Francesco Palazzo

IT & Information Security Leader with 15+ years of experience spanning technical delivery and strategic oversight across multiple industries and international environments. Proven track record in defining and executing InfoSec strategy, building and leading multidisciplinary teams, and delivering measurable risk reduction and cost optimisation. Technically hands-on across IT, offensive security, vulnerability management, red and purple teaming, bug bounty programmes, cloud security, and enterprise infrastructure hardening.

  • Leadership & Strategy Team & Project Leadership | Mentoring & Talent Development | Security Strategy & Roadmaps | Vendor & Budget Management | Change Management | C-Level Stakeholder Engagement
  • Hands-on Technical Security IT Infrastructure | Penetration Testing | Red & Purple Teaming | Vulnerability Management | Multi-Cloud & Container Security | Server/Network/Endpoint/Wireless/Firewall Hardening | Bug Bounty
  • Compliance & Risk PCI DSS | ISO 27001 | NIST | CIS | Risk Assessment & Treatment | Policy Development & Auditing
Professional Experience
Feb 2020 – Nov 2025
Professional Experience
Group Information Security Manager @ Sainsbury's – Holborn, London, United Kingdom

J Sainsbury plc (LSE: SBRY), trading as Sainsbury's, is the second-largest retailer in the United Kingdom, with over 1,400 stores and 141,000 employees (2025).
It is listed on the London Stock Exchange and is a constituent of the FTSE 100 Index.

The group is split into three main divisions: Sainsbury's Supermarkets, Sainsbury's Bank and Argos.
Other subsidiaries are Habitat, Nectar and Tu.

I worked as the Group Information Security Manager at the group's head office in Holborn Circus, London.
I reported directly to the Group Head of Information Security, with a dotted-line reporting relationship to the Group CISO.

Key Responsibilities & Accomplishments:
● Led and inspired a multidisciplinary Team (Penetration Testing, Vulnerability Management, Red/Purple Teaming) of 8 Security Professionals across London, Coventry and Manchester.
● Reorganised the Team by defining clear roles and responsibilities aligned with individual skills, career aspirations and business needs.
● Reviewed and streamlined processes and workflows, removing inefficiencies and introducing improved methodologies.
● Developed the 12-month and 3-year Team strategy and roadmap.
● Set Team objectives and individual development plans for all members.
● Implemented Continuous Vulnerability Assessment, PCI ASV Attestation and DAST processes.
● Achieved a 42.5% increase in efficiency compared to penetration testing suppliers (Feb 2020 – Sep 2021).
● Saved over £1,348,000 by delivering penetration testing through the internal Team (Feb 2020 – Sep 2021).
● Increased vulnerability scanning coverage from 26% to 94% (Feb 2020 – Sep 2021).
● Recruited contractors and permanent staff to strengthen the Team and expand Security capabilities.
● Selected and managed security tools and third-party suppliers.
● Managed both OpEx and CapEx budgets.
● Implemented Cloud Security across AWS, Azure, GCP and OCI, as well as Container Security.
● Integrated the Cloud Security solution with the SOC SIEM.

Dec 2024 – Present
Professional Experience
Information Security Consultant @ AviaQuality – Kloten, Zurich, Switzerland

AviaQuality is a consulting firm headquartered in Kloten, Zurich, Switzerland, that offers safety and compliance solutions to the aviation sector, including airlines, maintenance organisations, and the aerospace industry.

The company provides customised training programmes and bespoke services aimed at driving long-term improvements in operational safety, regulatory compliance, efficiency, and performance within the aviation field.

In my role as Information Security Consultant, I am responsible for delivering specialised services to our customers, including:

● EASA Part-IS Training, as defined by the Commission Implementing Regulation (EU) 2023/203 and Commission Delegated Regulation (EU) 2022/1645.
● Information Security Consulting Services uniquely crafted to address the specific needs of the aviation and aerospace sectors.

Major clients I have been advising:

● German Aerospace Center (DLR - Deutsches Zentrum für Luft- und Raumfahrt e.V.)
● Edelweiss Air AG
● Neos S.p.A.
● 3PLEX GROUP

Oct 2015 – Jan 2020
Professional Experience
Group Senior Security Consultant @ Sky – Osterley, London, United Kingdom

Sky is a British-based pan-European satellite broadcasting, on-demand Internet streaming media, broadband and telephone services company headquartered in London, with operations in the United Kingdom, Ireland, Germany, Austria, Italy and Spain. It is Europe's biggest and leading media company and largest pay-TV broadcaster, with over 23 million subscribers and 31,000 employees (2019).
Sky is owned by Comcast Corporation (NASDAQ: CMCSA), an American global telecommunications conglomerate, which is the world's second-largest broadcasting and cable television company by revenue.

I worked at the company's headquarters in London in the Group Technology Office. Reporting directly to the Group Head of IS Assurance & Compliance, I supported him in protecting Sky's key information assets' confidentiality, integrity, and availability.
My responsibilities included performing various security assessments, educating Sky's business on the inherent risks, and providing meaningful hardening and mitigation strategies.
My job strongly focused on web-based and mobile application penetration tests, network and wireless penetration tests, logical security audits, hands-on technical security evaluations, and remediation advice.
I also supported Sky's Payment Card Industry Data Security Standard (PCI DSS) by analysing and assessing the risks and impacts of exploits and security vulnerabilities, initiating the remedial actions required to mitigate risks to Sky's platforms, services, and systems.

Key Responsibilities & Accomplishments:
● Delivered IS Assurance Technical Consultancy support across departments/programmes of work.
● Supported Compliance, PCI DSS, SOA, ISO 27001/2, NIST, policies, standards and controls.
● Supported the GSOC.
● Project & Change Management.
● Risk Assessment.
● Penetration Testing.
● Onsite Assessments for the subsidiaries.
● Mentored the apprentices, graduates and junior consultants.
● Delivered the Responsible Disclosure programme.
● Interviewed candidates.

Sep 2014 – Sep 2015
Professional Experience
Penetration Tester & Security Consultant @ SECFORCE Ltd – Canary Wharf, London, United Kingdom

SECFORCE is a leading penetration testing company working in partnership with its clients to protect their business infrastructure from internal and external attacks. As a vendor-independent firm, SECFORCE provides impartial security advice in line with business requirements to give a measurable return to its clients.

It is a dynamic company passionate about security, analysing the latest security trends and contributing to the industry with open source software, published research and giving security conference presentations.

SECFORCE engagements are governed by a strict code of professional ethics and follow a structured approach built on proven methodologies such as CREST, OWASP and OSSTMM. It is CREST certified and has achieved ISO9001:2008 in recognition of its quality management systems and ISO27001:2005 for its information security management.

I conducted black, white and grey box Infrastructure Penetration Tests, Application Penetration Tests and gave Consultancy for some of the largest financial, media, telecommunication, security software, IT, intergovernmental organisations and banking companies globally. I provided full written reports to the clients, reflecting the results of the tests. These reports included recommendations to improve the security measures and mitigate the security risks, offering both full technical and non-technical overviews.

Infrastructure Penetration Tests:
● Conducted External and Internal Penetration Testing.
● Performed Wireless, Firewall and VPN Assessments.
● Engaged in Social Engineering initiatives.
● Reviewed Host Configurations.

Application Penetration Tests:
● Executed Web and Mobile Application Penetration Testing.

Consultancy:
● Reviewed Security Policies to ensure they met best practice standards and regulatory requirements.
● Advised on Incident Response strategies to effectively address and recover from security breaches.
● Assisted in Risk Management, helping clients to identify, assess, and prioritise risks.

Jan 2012 – Aug 2014
Professional Experience
IT Consultant - Security Specialist @ Société Générale Securities Services S.p.A. – Milan, Italy

Société Générale (EPA: GLE and BIT: GLE) is a leading French bank and one of the largest financial services groups in the euro-zone.

I was the IT Consultant - Security Specialist at Société Générale Securities Services S.p.A.
SGSS S.p.A. is a bank incorporated under Italian law and 100% held by Société Générale Group. The main services provided are custody and settlement, fund accounting and depositary bank services, and transfer agency services.

My duties involved System Management, Networking, Security, Policies/Governance/Risk procedures and IT Security Auditing.

Systems & Security:
● IT GRC PMP, hardened Microsoft Windows Server 2003 R2 and 2008 R2, hardened DCs, Domain Policy, AD, and DHCP servers, protected DNS servers, implemented a security baseline, hardened file services, print services, designed GPO for security policies, implemented the security baseline for Windows clients, hardened Windows clients, configured and managed WSUS, Sophos Endpoint Security and Control, performed assessments for compliance, configured and managed SQL, Apache and IIS.
● Configured and managed Microsoft PKI.

Networking & Security:
● Checked and optimised the configuration of Cisco appliances in Milan and Turin; analysed, checked and resolved strange and abnormal network traffic in Milan and Turin using Wireshark and Check Point Tracker; managed, reviewed and optimised FW, NAT and IPS rules on Nokia IP390 Check Point firewall in Milan and Turin.
● Created complex VPN connections between multiple companies.

Exchange Servers & Mail Security

Web Security

Governance, Risk and Compliance:
● Analysed and compared the new Société Générale Group Instructions and IT Security Policies with Société Générale Securities Services S.p.A. internal regulations, identified the differences and compliance controls, recognised non-compliant policies and found the solutions.

Incident Response, Penetration Testing, Vulnerability Management, Vulnerability Assessment, and Mitigation.

Jan 2012 – Aug 2014
Professional Experience
ICT Officer @ Costa Crociere S.p.A. – United Arab Emirates and Europe

Costa Crociere S.p.A. is the largest Italian travel group and Europe's number-one cruise operator, with over 75 years of tradition in passenger shipping.
The Group is headquartered in Genoa (Italy) and comprises Costa Cruises, AIDA Cruises and Costa Asia brands.

Costa Crociere S.p.A. is part of Carnival Corporation & plc (NYSE: CCL and LSE: CCL), the world's largest cruise operator, and is a member of the exclusive World's Leading Cruise Lines. As of Forbes Global 2000 in 2010, Carnival Corporation & plc was ranked as the 238th leading company in the world.

The ships in the Costa Cruises fleet fly the Italian flag and sail to over 250 destinations worldwide, including the Mediterranean, Northern Europe, the Baltic Sea, the Caribbean, Central and South America, the United Arab Emirates, the Far East, the Indian Ocean, the Red Sea, and offer Round-the-World cruises.

I was the officer responsible for ensuring the continuity, stability, and efficiency of all IT systems, networks, satellite communications, and radio equipment on board, in cooperation with the IT Department ashore and Facility Management. Reporting directly to the Chief Communications Officer, my role encompassed a broad range of technical and managerial responsibilities, ensuring the seamless operation of the ship's IT infrastructure.

Key Responsibilities & Contributions:
● Led the integration of onboard IT systems with shore-based operations, enhancing real-time satellite communication and operational efficiency.
● Upgraded the ship's IT infrastructure, installing advanced servers, wireless networks, and satellite communication systems.
● Conducted regular drills and training sessions with the IT team and relevant crew members to ensure preparedness.
● Offered expert troubleshooting and technical support for all IT-related issues.
● Trained the crew on using onboard technology resources.

Apr 2008 – Dec 2010
Professional Experience
System & Network Administrator @ Meridiana Fly S.p.A. – Olbia and Milan, Italy

On February 28, 2010, Meridiana S.p.A. and Eurofly S.p.A. merged to create Italy's second-biggest airline, Meridiana Fly S.p.A. (BIT: MEF). I oversaw the critical and challenging integration of the two companies' systems, networks, and software.

These were the most significant projects carried out:
● Developed the new virtual infrastructure with VMware to improve the efficiency, availability, and cost-effectiveness of IT resources and applications.
● Installed and configured a new DC and AD with Microsoft Windows Server 2008 R2.
● Installed and configured Microsoft Exchange 2010, migrated all mailboxes and objects from Exchange 2003 to 2010 and from Windows Server 2003 to 2008 R2, and implemented new GPOs.
● Installed and configured BES v5 and migrated all users from BES v4.
● Reconfigured all routing and installed MPLS to link the airports to the headquarters, set up new VPNs, installed and configured CheckPoint Unified Threat Management appliances, Cisco ASA, Microsoft ISA, and Microsoft Forefront TMG.
● Installed and configured Symantec Endpoint Protection 11.0, implemented Symantec MessageLabs Hosted Email Security and WebSense for web filtering and security.
● Resolved the technical issues of Lufthansa Integrated Dispatch Operation, IBM WebSphere MQ 7.0, Airbus software, and Oracle 9.2.

I was the fulcrum of this IT merge, leveraging my knowledge of systems/networking, programming, and scripting languages. I also coordinated six Help Desk technicians, ensuring a seamless transition and minimal disruption to operations.

Apr 2008 – Feb 2010
Professional Experience
System & Network Administrator @ Eurofly S.p.A. – Varese and Milan, Italy

Eurofly S.p.A. (BIT: EEZ) was the Italian carrier leader in the "leisure" sector, ranking among the top five airlines in Italy according to the ENAC yearbook 2006.

During my tenure, I worked with a variety of technologies:
● Configured and managed physical blade servers, including Windows 2003 (32-bit and 64-bit Enterprise), IIS, AD, Exchange 2003, file servers, DFS, clustered servers, SQL, Sybase, Terminal Servers, backup servers, print servers, DNS, DHCP servers, DC, WSUS, GPO, and WINS.
● Installed, configured and maintained software solutions such as Airbus software, SITA software, AMOS by Swiss AviationSoftware, AIMS by AIMS Int’l Ltd., LIDO by Lufthansa Systems, and EHM by Pratt & Whitney.
● Installed, configured and managed network appliances, including Cisco Catalyst 3750 Gigabit and PoE, Catalyst 6500.
● Administered RIM BlackBerry Enterprise Server v4 and the IP telephony solution 3Com NBX V3000.

During this experience, I obtained the AMOS Basic certification from Swiss Aviation Software, enhancing my expertise in aviation software solutions. Additionally, I coordinated two Help Desk technicians, ensuring efficient IT support and system management.

This role allowed me to develop a comprehensive understanding of IT infrastructure in the aviation sector and contribute significantly to Eurofly S.p.A.'s IT operations before its eventual merge with Meridiana S.p.A.

Security Certifications

OSCP

Offensive Security Certified Professional

OSWP

Offensive Security Wireless Professional

CISSP

Certified Information Systems Security Professional

CISM

Certified Information Security Manager

Education
2015 - 2015
Education
Applied Cyber Security @ MIT – Massachusetts Institute of Technology

Cambridge, MA, USA

2012 - 2012
Education
Information System Risk Management @ SDA Bocconi School of Management

Milan, Italy

2007 - 2010
Education
Computing and IT @ The Open University

London, UK

2007 - 2008
Education
Computer Science @ University of Milan

Milan, Italy

Languages

  • Italian
    100%
  • English
    80%
  • Spanish
    50%