luca@sentinel: ~
luca@sentinel:~$ whoami

LUCA DI MAURO

Cloud Security Engineer at Emeria UK, with deep expertise in the Microsoft security ecosystem and hands-on experience with CrowdStrike, Zscaler and Proofpoint. I design end-to-end security operations, automate threat detection, and lead technical security deployments, bridging complex implementation and business-level outcomes.

0years in security & IT
SC-200certified SecOps analyst
KQLdetections, hunts, training
3languages spoken

about.md

Cloud Security Engineer at Emeria UK, running internal security as the estate migrates from Azure, Sentinel and Defender to CrowdStrike, AWS and Proofpoint. Before that I was a Security Engineer at MVW Technology and a Sentinel Engineer for global enterprise customers. My focus is turning noisy telemetry into reliable detections, plus the automation, runbooks and playbooks that make them usable.

// a taste of the day job
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != "0"
| summarize Failures = count(), Apps = dcount(AppDisplayName) by UserPrincipalName, IPAddress
| where Failures > 20 and Apps > 3
| project UserPrincipalName, IPAddress, Failures, Apps

skills.json

SIEM / SOAR

Microsoft SentinelKQLAzure Logic AppsAzure WorkbooksData Connectors

XDR / Endpoint

CrowdStrikeDefender for EndpointDefender for Cloud AppsMicrosoft 365 Defender XDR

Network & Email Security

ZscalerProofpoint

Cloud

AzureAWS (building experience)Terraform

Identity & Data

Microsoft Entra IDConditional AccessAzure Purview

Operations

Incident ResponseVulnerability ManagementTerraform / AutomationPowerShell

Soft skills

Time ManagementTeam CollaborationCritical ThinkingCommunication

Languages

Italian · Native
English · C2
French · C1

experience.log

[2026-02 → present]

Cloud Security Engineer @ Emeria UKACTIVE

London
  • Deliver internal cloud security engineering, protecting the organisation's environment across endpoint, network, email and identity.
  • Contributed to the group-wide rollout of CrowdStrike and Proofpoint, and maintain in-depth, hands-on expertise with both platforms and Zscaler.
  • Support the strategic migration from Azure, Sentinel and Defender to CrowdStrike, AWS and Proofpoint, while developing AWS expertise.
  • Partnered with external penetration testers to remediate identified vulnerabilities, engineering new Microsoft Sentinel detections and resolving underlying issues.
  • Introduced controls to detect and restrict unmonitored AI usage across the company, reducing data exposure risk.
  • Enhance threat detection and response processes, tuning existing KQL analytics and developing new ones.
  • Build dashboards in Azure Workbooks and automate security workflows with Azure Logic Apps.
[2024-04 → 2026-02]

Security Engineer @ MVW Technology

London
  • Sole Security Engineer: end-to-end ownership of the security stack and the technical roadmap for cloud security operations.
  • Architected and deployed Microsoft Sentinel for new enterprise clients, with custom data connectors and KQL analytics for immediate value.
  • Built enhanced threat detection and response processes to optimise security operations.
  • Designed dashboards in Azure Workbooks and automated workflows with Azure Logic Apps.
  • Continuously tuned existing KQL queries and developed new analytics.
  • Delivered tailored 1:1 KQL training for SOC analysts.
  • Led monthly client service reviews and created sales materials to support business growth.
[2022-09 → 2023-11]

Sentinel Engineer @ LRQA Nettitude

London
  • Improved security operations through process refinement and threat detection optimisation.
  • Worked with customers to identify and implement tailored security use cases.
  • Developed and maintained SOPs, runbooks, workbooks and playbooks.
  • Guided SOC analysts and tailored Sentinel alerts to each environment.
  • Architected use cases with global enterprise customers, directly strengthening their threat detection posture.
[2021-08 → 2022-09]

M365 Security Engineer @ Zenzero

London
  • Configured and deployed Microsoft Endpoint Manager for Windows, iOS and Android.
  • Ran incident response using PowerShell logs to identify and remediate breaches.
  • Set up Conditional Access policies and monitored Microsoft 365 Defender and Azure Sentinel.
[2020-11 → 2021-08]

IT Support Engineer @ Modulo2

London
  • 2nd/3rd line support for software and hardware issues.
  • Deployed and managed devices with Jamf and Windows Autopilot.
  • Monitored projects to keep IT infrastructure performing optimally.

certs_and_education

Certifications

[✓] Microsoft SC-200: Security Operations Analyst
[✓] Diploma in Advanced French
[✓] Web Development (ILAS, Napoli)

Education

Dip. HE, Web Development
ILAS, Napoli
2014
A-Levels, Science Studies
ITILS Francesco Giordani, Caserta
2012

contact.sh

secure channel

$ ./connect --target luca

[+] handshake complete. Open to security engineering opportunities.

email   → lucadimauro@outlook.com

base   → Kingston upon Thames, Surrey, UK