Security Engineer

Carlo Denaro
I find vulnerabilities.
Then I fix them.

10+ years in tech. 5+ in cybersecurity.
PCI DSS · GDPR · Secure Development · Team Leadership.
Based in Como, Italy — working across CH/IT.

Get in touch View experience
About

I'm a Security Engineer who came up through software development — which means I don't just audit systems, I understand how they're built and why they break.

My background spans hands-on PCI DSS and GDPR assessments, leading security teams, and years of frontend engineering on high-traffic platforms. I bridge the gap between development and security operations.

Most of my career has been inside the Lastminute.com Group — one of Europe's largest travel tech companies — where I've held roles from frontend developer to cyber security engineer.

10+
Years in tech
5+
Years in cybersecurity
8
Person security team led
Experience
2023 — Present
Lastminute.com Group
Senior Frontend Developer

Security-aware frontend development on a travel platform serving millions of users. Leading migration of legacy codebase to TypeScript, with focus on XSS prevention, input validation, and secure API patterns.

React TypeScript Secure Coding XSS Prevention
2020 — 2023
Mearete / Localpoint SA
Chief ICT Security Officer

Led a security team of 8. Designed and implemented security training programs, drove shift-left security adoption across the engineering organisation, and oversaw infrastructure and application security strategy.

Team Leadership Shift-Left Security Training Secure SDLC
2019 — 2020
Lastminute.com Group
Cyber Security Engineer

Hands-on PCI DSS and GDPR assessments. Vulnerability scanning and penetration testing using industry-standard tooling. Cross-team collaboration for remediation.

PCI DSS GDPR BurpSuite Tenable.io OWASP Zap Metasploit
2015 — 2019
Lastminute.com Group
Frontend Developer

Four years on high-traffic booking platform. Search results, advertising server, and progressive migration from BackboneJS to ReactJS.

React BackboneJS JavaScript
2012 — 2015
Yoox Group S.p.A.
Javascript Developer

Custom JavaScript framework on international e-commerce platform.

JavaScript jQuery
Skills
Security
PCI DSS GDPR Tenable.io Qualys BurpSuite OWASP Zap Metasploit Secure SDLC Shift-Left Security Vulnerability Assessment Penetration Testing
Frontend
React TypeScript JavaScript Node.js HTML5 / CSS3
Backend & Data
PHP Python MySQL PostgreSQL MongoDB Redis
DevOps / CI / Methodologies
GitLab CI Jenkins Snyk Git Agile / Scrum TDD BDD
Contact

Let's talk.

I'm open to new opportunities in security engineering, penetration testing, and secure development — particularly in tech companies operating at scale.

me@carlodenaro.com