CV
Mattia Pini
Senior Defense Security Engineer
Senior Defense Security Engineer with 8+ years in cybersecurity. At Satispay I built the defensive security capability from the ground up: SIEM and detection engineering, cloud security on AWS and GCP, and security automation with AI agents. Previously focused on data protection and Microsoft cloud security in banking and consulting.
"Leave this world a little better than you found it"
Experience
Senior Defense Security Engineer
2026--Present
- Co-own the defensive security strategy with the CISO and run sprints for the four-engineer defensive team
- Interim line manager for two engineers; previously line-managed one engineer (2025--2026)
- Leading the migration of the security AI agents to Amazon Bedrock AgentCore
- Security architecture reviews (Keycloak CIAM, Spring Cloud Gateway), vendor risk assessments and audit support (CSSF)
Cloud Security Engineer
2023--2026
- First security engineer alongside the CISO: built the defensive security function from scratch, single-handedly for the first 18 months
- Led the SIEM selection and the Splunk rollout; defined log onboarding standards (CIM) for 20+ sources
- Designed risk-based alerting for customer account takeover
- Built AI agents that triage security alerts and, after analyst approval, handle remediation, stakeholder communication and incident reporting
- Moved AWS WAF to default-deny with self-service allowlisting through Terraform pull requests
- Led AWS and GCP security governance: SCP review, GCP hierarchy redesign, external configuration assessment and remediation
- Led the passkey rollout on Google Workspace
Security Lead Consultant
2022--2023
- Azure/M365/Infrastructure cloud security assessments for an international energy company
- Defined architecture for Microsoft Data Loss Prevention on macOS devices in a nationwide energy enterprise
- Developed a PowerShell module to automate Azure Multi-Factor Authentication management
- Implemented process workflows with Microsoft Power Automate for a global optical company
- Performed microservices security analysis (JWT vs mTLS)
Security Project Manager
2020--2022
- Managed enterprise Azure/O365 security projects (Hybrid AD, MIP, DLP, Sentinel)
- Defined security KPIs and toxic combination controls
- Supported internal and external security audits
- Developed data security governance policies and standards
Security and Technical Application Manager
2018--2020
- Defined data security requirements for new applications
- Designed application architectures with data security best practices
- Implemented enterprise data security policies and operating models
- Authored technical documentation for secure data flows
Certifications
- 2022 — Certified Kubernetes Administrator (CKA) (Linux Foundation)
Education
1st Level University Master Degree
2018--2020
Information Security Specialist
Master Degree
2014--2018
Computer Science and Engineering
Bachelor's Degree
2010--2014
Computer Science and Engineering
Skills
Technical
Architecture
4/5
Automation and AI
5/5
Cloud Security
5/5
Data Protection
5/5
Detection and SIEM
5/5
Identity
4/5
Incident Response
4/5
Kubernetes
4/5
Soft Skills
Adaptability
4/5
Communication
5/5
Critical Thinking
5/5
Problem-Solving
5/5
Stakeholder Management
4/5
Languages
Hobbies and Interests
- In my spare time, I run a self-hosted Kubernetes homelab (Talos, FluxCD GitOps, Cilium) for home-network services and home automation.
- Moreover, I play the Cajon in a band, performing live around Milan.
- I also like role-playing games like Pathfinder and D&D.
- Until some years ago, I was a scout group leader in an AGESCI scout group.