Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic

Francesco Strangis

Rende,CS

Summary

IT Consultant and Developer with expertise in identity and access management (IAM), web application security, and DevOps. Skilled in designing and evolving secure authentication architectures, integrating Microsoft Entra ID, Broadcom Siteminder, and modern authentication protocols such as SAML 2.0, OAuth 2.0, OpenID Connect, and FIDO2 Passwordless Passkeys.

Experienced in migrating and optimizing authentication systems, implementing SSO solutions via Microsoft Entra ID Application Proxy, and integrating Azure Authenticator for OTP-based authentication. Strong background in enterprise platform development and support, including Siebel AM CRM, ensuring stability, security, and seamless integration.

Proficient in cloud security and application protection, with experience in Azure DDoS Protection, Azure Web Application Firewall (WAF), and Azure Application Gateway to enhance security and performance.

Expertise in DevOps practices, including CI/CD pipeline automation on Google Cloud Platform, covering build, testing, and deployment. Adept at troubleshooting, incident resolution, and system optimization, delivering scalable and secure solutions for enterprise clients.

Overview

9
9
years of professional experience
1
1
Certification

Work History

Lead Cybersecurity Architect

Ntt Data Italia
05.2023 - Current

I am currently implementing a security solution to protect on-premises applications using Microsoft Azure technologies. The solution leverages Microsoft Entra ID Application Proxy to securely publish the applications via Azure Application Service, ensuring that access will only be possible through authentication in Microsoft Entra ID using Single Sign-On (SSO) mechanisms.

Authentication is being enforced using some security protocols, including SAML 2.0, OpenID Connect, and OAuth 2.0, providing a seamless and secure experience for users. The user base includes accounts from both an on-premises Active Directory (AD) and Microsoft Entra ID, requiring a hybrid identity approach.

To enhance security and user experience, I am integrating FIDO2 Passwordless Passkeys, allowing users to authenticate without traditional passwords, improving both security and usability. Additionally, I am managing the distinction between Microsoft Entra ID B2C, ensuring appropriate access control and user management strategies.

Lead Cybersecurity Architect

Ntt Data Italia
06.2016 - Current

In this project, I am responsible for the management, maintenance, evolution, and incident resolution of the customer's web protection platforms, including Strong, VAM, and WEBSSO, ensuring secure authentication and access management. Initially, the architecture was based on Broadcom Siteminder 12.0, where users accessed applications using biometric authentication and/or passwords, while internal employees authenticated through Kerberos and NTLM for seamless corporate access.

As part of a major architectural evolution, we designed the transition to Siteminder 12.8, enhancing security, scalability, and integration capabilities. This upgrade laid the foundation for further improvements in authentication mechanisms.

In the evolutionary phase, I have been heavily involved in the architectural design of advanced authentication features, ensuring seamless integration with the existing infrastructure. Specifically, I have contributed to the design and implementation of OTP authentication via Azure Authenticator and the adoption of SAML 2.0, providing more flexible and secure authentication methods while maintaining compatibility with the customer’s identity and access management framework.

As part of the incident management process, my duties include incident intake, analysis, troubleshooting, and resolution, working closely with both operations teams and the customer. I assess potential solutions and implement the most effective approach, ensuring minimal disruption and optimal security performance.

Lead Cybersecurity Architect

Ntt Data Italia
11.2023 - 02.2024

I contributed to the strengthening of the security posture of the existing platform by analyzing vulnerabilities, optimizing defenses, and implementing advanced protection strategies leveraging Azure technologies. The project focused on enhancing resilience against DDoS threats, integrating Azure DDoS Protection through a cost-benefit analysis to select the most effective plan.

To ensure proactive threat detection, I configured automated security breach alerts, enabling real-time monitoring and rapid response to potential incidents. Additionally, I implemented tailored security rules on Azure Application Gateway with Web Application Firewall (WAF) to provide layered protection for exposed services.

The effectiveness of these measures was rigorously validated through targeted testing across both development and production environments, ensuring a robust, well-integrated, and future-proof security framework.

System Engineer

Ntt Data Italia
07.2020 - 01.2021

In this project, I am responsible for designing and implementing a DevOps pipeline on Google Cloud Platform (GCP) to manage the entire test case project, covering both Front-End (FE) and Back-End (BE) processes. The pipeline automates the build process, executes unit tests, and manages the deployment to the TEST environment, ensuring a streamlined and efficient workflow.

Beyond development, my role also includes tasks related to technical analysis, documentation, and testing, guaranteeing that the pipeline integrates seamlessly with the existing infrastructure and supports continuous development.

Software Engineer

Ntt Data Italia
12.2017 - 11.2019

In this project, I was responsible for the development, maintenance, and support of the Siebel AM platform used by the customer for CRM in both Business and Customer areas. My role involved implementing new customer-requested features, contributing to the evolution of the platform, and maintaining both new and existing projects to ensure stability and performance.

Beyond development, I conducted unit testing on implemented solutions to guarantee reliability and compliance with business requirements. Additionally, I provided technical support and service management, assisting in troubleshooting and optimizing platform operations.

This project focused on enhancing the customer’s CRM infrastructure through continuous improvements, leveraging the Siebel AM platform to support evolving business needs and ensure a seamless customer experience.

Education

First Level Master - Cyber Security

Univesity of Calabria
Cosenza, Italy
05-2016

Master's Degree - Computer Engineering

University of Calabria
Cosenza, Italy
02-2016

Bachelor's Degree - Computer Engineering

University of Calabria
Cosenza, Italy
04-2010

Skills

  • Microsoft Azure Services & Platform
  • Identity and Access Management
  • Google Cloud Platform

Certification

Cisco CCNA Exploration 1: Network Fundamentals

Cisco CCNA Exploration 2: Routing Protocols and Concepts

Cisco CCNA Exploration 3: LAN Switching and Wireless

Cisco CCNA Exploration 4: Accessing the Wan

Microsoft Certified - Azure Solutions Architect Expert, consisting of:
- Azure AZ-300: Microsoft Azure Architect Technologies
- Azure AZ 304: Microsoft Azure Architect Design

Azure SC-900: Microsoft Security, Compliance, and Identity Fundamentals

Azure SC-300: Identity and Access Administrator Associate

TOGAF EA Foundation

Microsoft Certified - Cybersecurity Architect Expert, consisting of:
- Azure SC-100: Microsoft Cybersecurity Architect (close to achieving)

Languages

Italian
Bilingual or Proficient (C2)
English
Upper intermediate (B2)

Timeline

Lead Cybersecurity Architect

Ntt Data Italia
11.2023 - 02.2024

Lead Cybersecurity Architect

Ntt Data Italia
05.2023 - Current

System Engineer

Ntt Data Italia
07.2020 - 01.2021

Software Engineer

Ntt Data Italia
12.2017 - 11.2019

Lead Cybersecurity Architect

Ntt Data Italia
06.2016 - Current

First Level Master - Cyber Security

Univesity of Calabria

Master's Degree - Computer Engineering

University of Calabria

Bachelor's Degree - Computer Engineering

University of Calabria
Francesco Strangis