Building real-world, risk-aware systems for critical environments
I’m Emanuele, a Healthcare Assistant (OSS) transitioning into Cybersecurity Governance, Risk, and Compliance (GRC).
After years in high‑pressure clinical environments managing critical operational protocols and sensitive data (GDPR Art. 9), I’ve learned how crucial procedural discipline, risk management, resilience, and human‑centered systems are.
Today, I apply that operational mindset to cybersecurity auditing, framework compliance, and regulatory risk management.
My projects are not academic exercises: they are real-world systems and simulated enterprise environments, designed with risk-based thinking, auditability, and compliance-by-design in mind.
- 📜 ISC2 Certified in Cybersecurity (CC) & Google Cybersecurity Professional
- 🛡️ ISO/IEC 27001:2022 Lead Auditor Training Course (In progress — Exam scheduled Q3 2026)
- 🇪🇺 EU Regulatory Compliance: NIS2 Directive, EU AI Act (High-Risk AI Systems) & MDR UE 2017/745 (SaMD)
- 🎲 Risk Assessment & Methodology: ISO/IEC 27005:2022, ISO 31000 & ISO 19011:2018 Audit Execution
- 🏢 Sector Focus: Healthcare, Critical Infrastructure & High-Risk Regulated Environments
Full-scope simulated audit and gap analysis for a biopharmaceutical firm. Features a complete end-to-end ISO 19011 audit cycle and ISO 27005 risk management lifecycle:
-
Audit Execution: Audit Plan (
AUD-PLAN), Audit Trail (AUD-TR), and Findings Matrix (NC_OFI_Matrix). -
Risk Management: ISO 27005 Risk Register (
$P \times I$ scoring model) & Risk Treatment Plan (RTP) with Capex/Opex budgeting. - Executive Advisory: Maturity Dashboard (NIST CSF v1.1 Tier scoring), Strategic 3-6-12 Roadmap, and C-Level Board Presentation Deck.
Modular software in Python for emergency department triage, engineered with Compliance-by-Design principles:
- EU AI Act Assessment: High-Risk AI System compliance audit report (Articles 9–14: Risk Management, Data Governance, Logging, Transparency, Human-in-the-Loop).
- MDR UE 2017/745: SaMD Class IIa Regulatory Readiness Report (Rule 11).
- Cyber Security & Privacy: Non-repudiable audit logging, GDPR Art. 32 security controls, and ISO 27001 Annex A mapping.
Resilient mesh telemetry system designed for critical operational environments and IoT/OT monitoring:
- Security-by-Design & OT/IoT security mapping.
- Business Continuity Management (ISO 22301) & NIS2 sector alignment (Healthcare).
- Secure logging, threat modeling, and risk register.
- Frameworks: ISO/IEC 27001:2022 | NIST CSF v1.1/2.0 | ISO/IEC 27005 | ISO 19011 | NIS2 | GDPR
- Deliverables: Gap Analysis | Risk Registers | Risk Treatment Plans | Audit Plans | Board Decks | SoA Evaluations
- Tech & Scripting: Python | Git/GitHub | Markdown/LaTeX | Linux | Azure AD / IAM Basics
Healthcare taught me discipline, procedural compliance, risk awareness, and human-centered design.
Cybersecurity governance is the natural evolution of that mindset.
I build and audit systems that are:
- 🛡️ Resilient
- 📋 Auditable
- ⚖️ Compliant
- 👥 Human-first
📫 Connect with me: LinkedIn | GitHub Portfolio