Gianluca Caruso

Lavoro nel mondo della cybersecurity con un approccio pratico: sicurezza applicata a codice, infrastruttura, automazioni DevSecOps e processi reali, anche quando farla bene è la parte più ostica.

Versione senza tecnicismi? Cosa faccio

Esperienze lavorative

  1. ICT Security Specialist | DevSecOps Engineer | Full Stack Developer | AI Engineer @ Altrama Italia

    giu 2023 - presente

    Sicurezza ICT, hardening applicativo, sviluppo full-stack , automazione DevSecOps e supporto al percorso aziendale di certificazione ISO 27001.

Formazione

  1. CyberSecurity - formazione continua @ HackTheBox Academy, PortSwigger Academy e piattaforme specialistiche

    continuo

    Percorso pratico di offensive security (penetration testing, web application testing, vulnerability assessment, OSINT, bug bounty), blue team (hardening, WAF, IDS/IPS, EDR, XDR, SOAR) e governance (NIS2).

  2. Laurea triennale in Informatica @ Universita della Calabria

    2018 - 2023

    Percorso universitario in informatica, sviluppo software e basi di sicurezza.

  3. Diploma in Sistemi Informativi Aziendali @ ITAS ITC Rossano

    2013 - 2018

    Formazione tecnica su sistemi informativi, basi dati e processi aziendali.

Skills

Sviluppo full stack

Frontend, backend, API e basi dati per applicazioni web complete.

  • TS/JS
  • React
  • Next.js
  • Node.js
  • Spring Boot
  • Django
  • FastAPI
  • Go
  • PostgreSQL
  • MongoDB
  • Redis
  • MySQL
  • SQLite
  • REST
  • GraphQL
  • WebSocket
  • tRPC
  • Test e2e
  • HTML
  • CSS
  • TailwindCSS
  • Bootstrap

DevSecOps

Pipeline, container, infrastruttura e controlli automatici vicino al codice.

  • Docker
  • Kubernetes
  • Terraform
  • Ansible
  • GitHub Actions
  • Vault
  • Helm
  • Nginx
  • Caddy
  • Prometheus
  • Grafana
  • ELK

AI engineering

Agent, RAG e automazioni che trasformano contesto tecnico in workflow utili.

  • Python
  • LLM
  • RAG
  • AI Agents
  • LangChain
  • Prompt Engineering
  • Red Teaming AI
  • Automation

Security

Offensive security, difesa, hardening e analisi delle superfici esposte.

  • Penetration Testing
  • WPT
  • Vulnerability Assessment
  • Web Security
  • Bug Bounty
  • OSINT
  • Threat Intelligence
  • Hardening
  • WAF
  • IDS/IPS
  • EDR
  • XDR
  • SIEM
  • SOAR
  • Zero Trust
  • SAST
  • DAST
  • SCA
  • NIS2
  • ISO 27001

Certificazioni e obiettivi raggiunti

Clicca per vedere tutti i badge

HTB Certified Web Exploitation Specialist

Path completato

Hacking in the wild

Hacking WordPress

The eye that sees all

Network Enumeration with Nmap

Do things the traditional way

Introduction to Bash Scripting

Every road leads back to root

File Inclusion

Airborne delivery

File Transfers

DROP your weapon

SQL Injection Fundamentals

Your request is my demand

Web Requests

Combine the modules

Using the Metasploit Framework

Playing with the mess

JavaScript Deobfuscation

Stairway to Heaven

Linux Privilege Escalation

Fuzzing is power

Attacking Web Applications with Ffuf

Crude but effective

Login Brute Forcing

JOIN the adventure

SQLMap Essentials

Developer

Introduction to Web Applications

Your first battle

Getting Started

Just a small crack, and you're in

Broken Authentication

Start building your arsenal

Setting Up

Tactical

Penetration Testing Process

Included in every report

Cross-Site Scripting (XSS)

Light in the dark

Vulnerability Assessment

Inject with caution

Command Injections

Dive into requests

Using Web Proxies

You need to trace before you can hunt

Footprinting

Ghost in the shell

Shells & Payloads

Scan and execute

Attacking Common Services

Arachnoid

Web Attacks

Prepare your payload and up you go

File Upload Attacks

Information is not knowledge, or is it?

Information Gathering - Web Edition

Straight to the server

Server-side Attacks

Passwords are not the only way forward

Session Security

You shall not (by)pass

Web Service & API Attacks

Hunt the bug

Bug Bounty Hunting Process

Flaw finder

Intro to Whitebox Pentesting

Endpoint Explorer

API Attacks

Fuzzing guru

Web Fuzzing

Graph invader

Attacking GraphQL

Protocol Breaker

Attacking AI - Application and System

PenguinTracer

Introduction to Linux Forensics

Scrivimi!

Scrivi almeno due caratteri: la lavagna risponde subito.