Partner & supplier profile

Emanuele Russo

Cyber Security Architect. Independent B2B contractor, available to consulting partners, systems integrators and staffing agencies. Europe-based, working across global time zones.

Open to new engagements Remote-first Europe-based · global hours B2B · EU VAT registered 18 yrs IT · 14 in security

Why partners call

Four situations, roughly. Each one is a requirement that needs covering this quarter — not a conversation about next year's roadmap.

Supplier record

Everything your onboarding process will ask for, in one place — so “can we use him” takes five minutes instead of five emails.

Legal entity
SlytherOps — sole practice, ItalyTrading name of Emanuele Russo
VAT number
IT 02959810819
Engagement model
B2B service contract — direct, or through a consulting partnerTime & materials, or fixed-scope statement of work
Delivery model
Remote-firstOccasional on-site visits considered by arrangement
Base
Italy — CET / CESTEU-based supplier: EU VAT, EU contract law, EU data residency
Working hours
Full overlap across EMEA and the Americas · APAC by arrangementOut-of-hours, weekend and overnight coverage available where the engagement requires it — maintenance windows, migration cutovers, incident response
Availability
Open to new engagementsStart date and scope agreed per engagement
Rate
Rate card on requestDay and hourly rates quoted by market and engagement length
Experience
18 years in IT — 14 in cyber securityHealthcare, financial services, critical infrastructure
Languages
Italian — native · English — C1 Business AdvancedGerman, French, Japanese — A2
Professional indemnity
€1,000,000 per claim — Willis Towers Watson

Held continuously and renewed annually. Certificate supplied on request, before contract signature. This is usually where an individual contractor stalls in vendor onboarding.

Delivery areas

Security architecture & Zero Trust

Target architectures, control baselines, segmentation and secure-by-design review across hybrid and cloud estates.

Zero Trust · defence-in-depth · security baseline design · threat modelling · IT/OT segregation · platform lifecycle · production readiness

Security platform governance

Ownership of EDR/XDR and SIEM platforms end to end: assessment, policy lifecycle, staged rollout, telemetry validation, stabilisation.

Trend Micro Vision One · Deep Security · Apex Central · Microsoft Defender · IBM QRadar · Sentinel · Splunk · Wazuh · detection engineering

Identity, access & privileged security

Identity architecture, authentication modernisation, access governance and privileged access controls.

Microsoft Entra ID · Active Directory · CyberArk PAM · Conditional Access · SAML / OAuth 2.0 / OIDC · RBAC · JIT access · access reviews

Vulnerability & exposure management

Asset visibility, risk-based prioritisation, remediation ownership and SLA reporting across infrastructure, cloud and endpoints.

Qualys VMDR · CSAM · Cloud Agent · Qualys EDR · PCI · Nessus · OpenVAS — all Qualys modules certified

Operational resilience & compliance

Gap analysis, control mapping, evidence preparation and audit support — producing artefacts an assessor will accept.

ISO/IEC 27001 · NIS2 · DORA · EU Cyber Resilience Act · IEC 62443 · NIST CSF · NIST SP 800-82 · GDPR · PCI DSS · DR & BC

Product & application security

Secure SDLC, threat modelling, dependency hygiene and software supply-chain considerations alongside development teams.

OWASP Top 10 · Secure SDLC · SAST / DAST / SCA · CVE triage · SBOM · CI/CD security · secrets management · Docker · Kubernetes

Secure AI automation

Locally hosted, isolated AI workloads for vulnerability triage, reporting and evidence preparation — with access control, logging and human validation.

Ollama · Hugging Face · containerised local models · no external APIs · data residency enforced · human-in-the-loop

Security service ownership

Roadmaps, change governance, KPI and SLA monitoring, vendor coordination and operational handover.

ITIL · Jira ITSM · incident, change and problem management · risk communication · stakeholder reporting

Technology

Hands-on and in production, in regulated environments. Listed in full so you can keyword-match against a requirement without having to email and ask.

Identity & PAM
Microsoft Entra ID · Active Directory · CyberArk PAM · Conditional Access · SAML · OAuth 2.0 · OpenID Connect · LDAP · RBAC · Just-in-Time access · credential rotation · session recording · access reviews
Endpoint & XDR
Trend Micro Vision One · Apex Central · Deep Security · Microsoft Defender · Trellix · behavioural detection · IOC/IOA analysis · YARA · containment · telemetry validation
SIEM & detection
IBM QRadar · Microsoft Sentinel · Splunk · Wazuh · AQL · KQL · SPL · DSMs · building blocks · reference sets · correlation rules · MITRE ATT&CK · threat hunting
Vulnerability & exposure
Qualys VMDR · Qualys CSAM · Qualys Cloud Agent · Qualys EDR · Qualys PCI Compliance · Nessus · OpenVAS · asset discovery · dynamic tagging · scan governance · patch management
Network & SASE
Fortinet FortiGate · Palo Alto Networks · Check Point · Cato Networks · NGFW · IPS/IDS · VPN · SD-WAN · TLS inspection · web filtering · segmentation · secure routing
Cloud & workplace
Microsoft Azure · AWS · Google Cloud Platform · Microsoft Intune · Microsoft 365 Defender · Microsoft Purview · Google Cloud Armor · security baselines · compliance policies · automated remediation
DevSecOps
Secure SDLC · threat modelling · SAST · DAST · SCA · CVE triage · SBOM · CycloneDX / SPDX · CI/CD security · secrets management · Docker · Kubernetes security
Platforms & OS
Windows Server · Linux · hardening baselines · IT/OT segregation · industrial cybersecurity principles · compensating controls
Automation & AI
Python · PowerShell · Bash · REST APIs · JSON / CSV / HTML reporting · Ollama · Hugging Face models · containerised local inference · prompt engineering · human-in-the-loop workflows
Frameworks & standards
ISO/IEC 27001 · NIS2 · DORA · EU Cyber Resilience Act · IEC 62443 · NIST CSF · NIST SP 800-82 · GDPR · OWASP Top 10 · PCI DSS · MITRE ATT&CK · ITIL · Jira ITSM

All product and company names are trademarks or registered trademarks of their respective owners. They appear here to describe working experience only, and imply no partnership, endorsement, reseller relationship or vendor certification beyond those listed under Certifications.

Sectors delivered in

2026 — now

Independent practice — regulated and critical environments

Concurrent B2B engagements across security architecture, identity, vulnerability and exposure management, endpoint/XDR platform governance, security operations and operational resilience. Sectors include critical infrastructure and regulated financial services — among them a target identity environment built from the ground up, with its own security guardrails and access-control baseline. Delivered directly and through consulting partners.

2025 — 2026

Banking & financial services

Enterprise security platform operations across EDR, SIEM, vulnerability management, IAM/PAM, SASE, network security and Microsoft security, inside a NIS2, DORA and ISO 27001 programme. Hardened local AI workloads with enforced data residency, network isolation and human-supervised outputs.

2018 — 2025

Healthcare

Built the security capability from zero over six years: SOC and detection, network security, identity, incident response, disaster recovery and business continuity. GDPR safeguards for clinical and medical-device data.

2008 — 2018

Transport, construction and IT services

Firewall, VPN, IDS/IPS and host-based monitoring for business-critical systems. Vulnerability assessment, security audits, patch management, backup and disaster recovery.

Certifications

ISC2 SSCP CompTIA A+ Cyber CompTIA A+ Network EC-Council — Attack & Defense Palo Alto Networks Cybersecurity Qualys VMDR Qualys EDR Qualys PCI Compliance Qualys CSAM Qualys Cloud Agent Google Project Management Google Data Analytics

Working boundaries

Supplied on request

Start a conversation

Send the requirement, the client sector and the expected duration. You get a yes or a no within one working day — including a no, with the reason. If you need to send a spec sheet or an attachment, message me on LinkedIn.