Information Security Specialist

Riccardo
Vecchi

ISC²
CISSP
Certified Information
Systems Security
Professional
Profile

Security Leader
with a Strategic Edge

Information Security professional with 5+ years spanning GRC, security operations, and strategic advisory. Currently driving Allianz Italy's security governance framework and serving as AI Security Focal Point — translating complex risk landscapes into C-level decisions and board reporting.

My approach bridges technical depth with business acumen: ISO/IEC 27001 ownership, vulnerability programs at scale, DLP, and DevSecOps strategy across financial, government, and automotive sectors.

Italiano
Madrelingua
English
C1 Advanced
0
Years in InfoSec
0
IS KPIs Owned
0
Servers Managed
0
Workstreams Led
Career Path

Work Experience

Apr 2023 — Present
Allianz Italy
Information Security Specialist — Governance, Risk & Compliance
  • Governance and operational security role supporting the CISO office in strategy definition
  • Ownership of 4 IS KPIs with direct reporting to Local and Group board (C-Level)
  • Maintenance and evolution of the Information Security Governance framework (Policies and Procedures)
  • Responsible for ISO/IEC 27001 certification maintenance and audit coordination
  • AI Security Focal Point — driving secure AI adoption across the organization
  • Oversight of local Security Operations team (5 members) covering incident and vulnerability handling
  • DLP Responsible and coordinator of VAPT, Bug Bounty, Application Security testing and Exposure Management
May 2022 — Apr 2023
Oplium Italy
ICT and Cyber Risk Consultant
  • ISO 27001 Implementation and Certification for client engagements
  • Vulnerability Management program coordinator for a government agency (1500+ servers)
  • DevSecOps Strategy implementation for an automotive company
Jul 2021 — May 2022
Deloitte
Cyber Risk & Data Privacy Analyst
  • Project management of 19 workstreams within a cybersecurity masterplan for a banking group
  • Functional contribution to DLP solution implementation including data flow mapping
Aug 2020 — Jul 2021
Vcube S.r.l.
Security System Engineer
  • Security controls implementation and administration — EDR, AV, MFA, IDS/IPS, Windows, Linux
Competencies

Skills & Expertise

Technical Security
Cyber ResilienceVAPT Vulnerability ManagementDLP EDR / IDS / IPSAttack Surface Mgmt Bug BountyApp Security TestingDevSecOps
Governance & Compliance
ISO/IEC 27001DORA NIS2Risk Management Third Party ManagementProgram Management Security KPI ReportingAudit Coordination
Tools & Platforms
RSA ArcherOneTrust QualysJira ServiceNowPowerBI Microsoft O365Azure
Leadership
Strategic ThinkingStakeholder Management C-Level ReportingTeam Oversight MentoringProblem Solving
Proficiency
GRC & ISO 2700195%
Vulnerability Management90%
Security Operations85%
Risk Management92%
DevSecOps78%
AI Security82%
Credentials

Certifications

ISC²
CISSP
★ Gold Standard of Cybersecurity
CISSP
Certified Information Systems Security Professional · ISC²

The world's premier cybersecurity credential — held by fewer than 150,000 professionals globally. The CISSP validates expert-level mastery across all 8 security domains: Security & Risk Management, Asset Security, Security Architecture, Network Security, Identity & Access Management, Security Assessment, Security Operations, and Software Development Security. The definitive benchmark for senior GRC and security leadership roles.

AZ
Azure AZ-900
Microsoft Azure Fundamentals
ISO
ISO/IEC 27001
Lead Implementer & Auditor
Academic Background

Education

2020 — 2021
Postgraduate Certification
Cyber Academy — Security Analyst
University of Modena, Italy
2015 — 2019
Bachelor of Engineering
Civil and Environmental
University of Modena, Italy
Get in Touch

Contact

Email
rivecchi@ikmail.com
Phone
(+39) 334 181 6859
Location
Milan, Italy

Open to senior security leadership opportunities, board advisory roles, and speaking engagements on GRC, AI Security, and cyber resilience. Let's connect.

Send a Message