about.md
Cloud Security Engineer at Emeria UK, running internal security as the estate migrates from Azure, Sentinel and Defender to CrowdStrike, AWS and Proofpoint. Before that I was a Security Engineer at MVW Technology and a Sentinel Engineer for global enterprise customers. My focus is turning noisy telemetry into reliable detections, plus the automation, runbooks and playbooks that make them usable.
// a taste of the day job SigninLogs | where TimeGenerated > ago(1h) | where ResultType != "0" | summarize Failures = count(), Apps = dcount(AppDisplayName) by UserPrincipalName, IPAddress | where Failures > 20 and Apps > 3 | project UserPrincipalName, IPAddress, Failures, Apps
skills.json
SIEM / SOAR
XDR / Endpoint
Network & Email Security
Cloud
Identity & Data
Operations
Soft skills
Languages
experience.log
Cloud Security Engineer @ Emeria UKACTIVE
- Deliver internal cloud security engineering, protecting the organisation's environment across endpoint, network, email and identity.
- Contributed to the group-wide rollout of CrowdStrike and Proofpoint, and maintain in-depth, hands-on expertise with both platforms and Zscaler.
- Support the strategic migration from Azure, Sentinel and Defender to CrowdStrike, AWS and Proofpoint, while developing AWS expertise.
- Partnered with external penetration testers to remediate identified vulnerabilities, engineering new Microsoft Sentinel detections and resolving underlying issues.
- Introduced controls to detect and restrict unmonitored AI usage across the company, reducing data exposure risk.
- Enhance threat detection and response processes, tuning existing KQL analytics and developing new ones.
- Build dashboards in Azure Workbooks and automate security workflows with Azure Logic Apps.
Security Engineer @ MVW Technology
- Sole Security Engineer: end-to-end ownership of the security stack and the technical roadmap for cloud security operations.
- Architected and deployed Microsoft Sentinel for new enterprise clients, with custom data connectors and KQL analytics for immediate value.
- Built enhanced threat detection and response processes to optimise security operations.
- Designed dashboards in Azure Workbooks and automated workflows with Azure Logic Apps.
- Continuously tuned existing KQL queries and developed new analytics.
- Delivered tailored 1:1 KQL training for SOC analysts.
- Led monthly client service reviews and created sales materials to support business growth.
Sentinel Engineer @ LRQA Nettitude
- Improved security operations through process refinement and threat detection optimisation.
- Worked with customers to identify and implement tailored security use cases.
- Developed and maintained SOPs, runbooks, workbooks and playbooks.
- Guided SOC analysts and tailored Sentinel alerts to each environment.
- Architected use cases with global enterprise customers, directly strengthening their threat detection posture.
M365 Security Engineer @ Zenzero
- Configured and deployed Microsoft Endpoint Manager for Windows, iOS and Android.
- Ran incident response using PowerShell logs to identify and remediate breaches.
- Set up Conditional Access policies and monitored Microsoft 365 Defender and Azure Sentinel.
IT Support Engineer @ Modulo2
- 2nd/3rd line support for software and hardware issues.
- Deployed and managed devices with Jamf and Windows Autopilot.
- Monitored projects to keep IT infrastructure performing optimally.
certs_and_education
Certifications
Education
ILAS, Napoli2014
ITILS Francesco Giordani, Caserta2012
contact.sh
$ ./connect --target luca
[+] handshake complete. Open to security engineering opportunities.
email → lucadimauro@outlook.com
base → Kingston upon Thames, Surrey, UK