- Vertical specialist on Cloudflare Application Security (WAF, Anti-DDoS, Web Security) and Zero Trust (Access, Gateway, ZTNA).
- Lead an enterprise project protecting 50+ enterprise domains: onboarding, WAF security policy design, application integrations and continuous monitoring, working directly with web and mobile development teams.
- Lead a Zero Trust programme for 6,000 users: ZTNA architecture, identity integration, access/gateway policies and phased roll-out.
- Integrate Cloudflare with heterogeneous infrastructures (AWS, Azure, on-prem, Kubernetes) and keep managing ZTNA and WAF for the 50+ SeSa Group companies with Terraform/Ansible automation.
Security Engineer · WAF & Zero Trust Specialist
Hi, I'm Fabrizio
I'm
Security Engineer with fast career progression — from Cloud Engineer to leading enterprise security projects in under four years. Currently a Cloudflare specialist for Application Security and Zero Trust at Vargroup, leading a WAF/Anti-DDoS programme for 50+ enterprise domains and a Zero Trust roll-out for 6,000 users. Automation-first mindset: Terraform, Ansible, Python & Bash.
name: "Fabrizio Di Cesare"
role: "Security Engineer"
focus: ["WAF", "Anti-DDoS",
"Zero Trust"]
stack: ["Cloudflare", "Python",
"Ansible", "Terraform"]
location: "Italy"
status: ● protecting the internet
About me
Curious by nature, hands-on by choice.
My passion for cybersecurity started at the Ulisse Security Group at the University of Bologna. There I explored many areas of security — from web and network security to OSINT and reverse engineering — while taking part in dozens of Capture The Flag competitions. Those challenges gave me a hands-on mindset and a collaborative spirit that I still carry today.
After graduating I moved into the enterprise world at Vargroup and SeSa, growing from Cloud Engineer to IT Security Manager and securing the 50+ companies of the SeSa Group. Today I'm a vertical specialist on Cloudflare Application Security and Zero Trust: I design WAF policies, build ZTNA architectures and integrate Cloudflare with AWS, Azure, on-prem and Kubernetes platforms — automating everything I can along the way.
My goal is always the same: building practical, scalable security that protects businesses while keeping them agile.
Experience
From Cloud Engineer to enterprise security lead.
- Managed security for all companies of the SeSa Group, focusing on application security and protection of corporate web services.
- Vulnerability assessments with Qualys and penetration tests (OWASP Top 10) on critical web applications.
- Ran phishing simulation campaigns and security awareness initiatives; incident triage and first response.
- Designed and deployed a Qualys-based continuous vulnerability assessment programme and strengthened security policies.
- Oversaw datacenter security operations, managing EDR and SIEM systems and enforcing access controls.
- Expanded the SOC with continuous monitoring solutions for proactive threat detection.
- Directed WAF and Anti-DDoS solutions across enterprise web services.
- Evaluated and introduced new security products, leading PoCs and vendor negotiations.
- Took part in internal and external ISO 27001 audits, ensuring compliance with the standard.
- Hardened enterprise datacenter infrastructures: network segmentation, asset/patch management, monitoring, incident response.
- End-to-end vulnerability assessments with remediation support, plus automation for asset discovery and patch management (Python/Bash, Ansible/Terraform).
- Analysed and secured AWS cloud environments (identity, networking, logging, hardening).
Education
University of Bologna — Computer Engineering.
Master's Degree in Computer Engineering
Thesis: Ransomon and Hades: Analysis and Visualisation of Ransomware Attacks in Real Time.
Focus: data analysis, threat intelligence, real-time visualisation of ransomware attacks via WebGL and Unreal Engine.
Bachelor's Degree in Computer Engineering
University of Bologna & CINECA
Thesis: Unreal Engine and Oculus Rift for the Virtual Heritage.
Publication: Evaluating an immersive interactive VR experience: MUVI — Virtual Museum of Daily Life
Certifications
Verified expertise on the platforms I work with every day.
Cloudflare One Advanced (for Partners)
Cloudflare
Zero Trust / SASE specialisation.
Verify on CredlyApplication Security Advanced (for Partners)
Cloudflare
WAF, Anti-DDoS, bot and API protection specialisation.
Verify on Credly
AWS Certified Security — Specialty (SCS-C01)
Amazon Web Services
ID: 7a77ff35-d0a5-40d8-90ea-f72889e51dc2
Verify on CredlyTeaching & academic activities
Explaining complex topics clearly is part of the job.
Tutor, Master in Cybersecurity
Teaching tutor of the Master Cybersecurity: from design to operations — secure coding and SAST, OWASP web and mobile application security testing, threat modeling, malware analysis, incident response and digital forensics.
Lecturer & CTF Trainer
Lectures on Web Security and Cryptography, plus Capture The Flag (Attack/Defense) training. Active competitor with the Ulisse and CeSeNA_Ulisse teams.
Game Development Instructor
Instructor for game development courses using Unreal Engine and Blender.
Skills
The toolbox — from the edge to the kernel.
Security
Cloud & Identity
Infrastructure & DevOps
Programming
Graphics & Engines
Soft skills
- Teaching & public speaking — lecturer and tutor in cybersecurity and game development programmes.
- Teamwork — CTF and Attack/Defense competitions in diverse teams.
- Task & infrastructure management — product evaluation, deployment and coordination in professional settings.
Let's talk
Open to collaborations, security projects and a good coffee.