mountain landscape

Information Security

Security is an outcome of thoughtful design,
not a product you install or a checklist you complete.

I am a computer engineer who specializes in the field of cybersecurity. After more than a decade working on the sector I got the experience to bypass different security obstacles, but more importantly to design and implement the solutions and processes to make your environment more secure.

A deep technical knowledge is really important. But also a big emphasis on communication and empathy is essential to reach the objectives.

Things I Can Do

Here is a short list of the main activities and services i deliver. They range from high level strategy and guidance to technical implementations and anything in between.

  • CISO as a Service — Ongoing security leadership and strategic guidance for organizations that need executive-level direction without the cost of a full-time CISO.
  • Security Audits — Independent assessment of your security posture against industry standards, with a clear, prioritized roadmap of what to fix first.
  • Detection & Incident Response — Design and tuning of detection capabilities, plus hands-on response when incidents happen, to minimize damage and downtime.
  • ISO Certification — End-to-end guidance through ISO 27001 certification, from gap analysis to audit-ready documentation and controls.
  • Penetration Testing — Real-world attack simulation to uncover exploitable vulnerabilities before an adversary does, with clear remediation guidance.
  • Awareness Training — Practical, engaging security training that turns your team into your first line of defense, not your weakest link.

A Few Accomplishments

Here is a summary of the experience and knowledge i collected over the years:

Experience

  • 2022–Now Senior Security Architect (Arco IT, Zurich)
  • 2021–2022 Customer Success Manager Architect (IBM)
  • 2016–2021 Senior Information Security Engineer (EUMETSAT/ESA/ESOC, Darmstadt)
  • 2013–2016 IT Security Consultant (GMV, Barcelona)

Main Certifications

  • Certified Information Security Manager (CISM)
  • Red Hat OpenShift Administration
  • IBM Cloud Pak for Security Administrator
  • CISCO CCNA Security
  • BSI ISO27001 Lead Implementer
  • Offensive Security OSCP/OSWP
  • IBM QRadar
  • EC-Council Incident Handler & Forensic Investigator
  • Imperva WAF & DB

Selected Work

A closer look at the kind of work behind the job titles above.

Cyber Defence Strategy, Arco IT (Switzerland)

As Senior Security Architect, I help Swiss companies across multiple sectors build their cyber defence strategy end-to-end — from CISO-as-a-Service and ISO 27001 preparation to detection & response, vulnerability management, penetration testing, and security architecture and threat modeling.

ISMS & Risk Management, European Space Agency (ESOC)

Designed and led the ISO 27001 ISMS implementation and certification process for ESA's Mission Operations Infrastructure, including a tailored risk assessment methodology, a Patch & Vulnerability Management service, and incident response coordination for a 24/7 mission-critical environment.

Security Architecture, EUMETSAT Ground Segment

Defined and evolved the security architecture for EUMETSAT's Ground Segment, running a cross-organisational ISMS and vulnerability lifecycle program, and deploying tools including CyberArk (PAM), Palo Alto Networks, Rapid7, and Qualys across a high-availability satellite operations environment.

Let's Talk

Looking for a security architect, CISO advisory, or a penetration test? Tell me a bit about what you need and I'll get back to you within a couple of business days.

Or reach me directly: info [at] martiberini.com  ·  LinkedIn