Lead Cybersecurity Assessor

Alessandro
Candeloro

IMQ S.p.A. — EU Notified Body // Milan, IT

5+ years leading security assessments, regulatory compliance programs and cross-functional teams across financial, healthcare, automotive and IoT sectors. Subject matter expert for EU product cybersecurity regulations. Targeting a Cybersecurity Manager role as a step towards CISO leadership.

profile.sh
$ whoami
Alessandro Candeloro
$ cat role.txt
Lead Cybersecurity Assessor target: CISO
$ cat certs.txt
OSCP / OSWA / PSM II
$ cat compliance.txt
EN 18031 / CRA / ECE 155/156
$ status
[ OK ] 5+ yrs experience [ OK ] EU Notified Body delegate [ OK ] open to opportunities
$

[ 01 ]
Regulatory Compliance

EN 18031, Cyber Resilience Act, ECE 155/156, IEC 60335-1 Annex U — translating complex EU product cybersecurity regulations into actionable conformity programs.

[ 02 ]
Security Assessment

30+ penetration tests across web, infrastructure and mobile. Vulnerability assessment using OWASP and PTES methodologies, reducing exploitable attack surface by up to 30%.

[ 03 ]
Team & Client Leadership

Leading teams of 5+ assessors, owning end-to-end delivery cycles, C-suite reporting and executive client relationships. 98% client satisfaction across portfolio.

01
Mar 2025 — present
IMQ S.p.A.
EU Notified Body
Lead Cybersecurity Assessor

Service ownership and pre-sales for EU product cybersecurity regulations. Leading a team of 5 assessors across EN 18031, CRA, Automotive and IEC 60335-1 Annex U assessments.

Official delegate to REDCA cybersecurity working group; co-authored Technical Guidance Notes for EN 18031
Active member, Euro NCAP Cybersecurity Working Group
Leading development of IMQ's CRA conformity assessment methodology
98% client satisfaction — commercial proposals in C10k–C40k range
EN 18031 CRA ECE 155/156 team leadership pre-sales
Feb 2024 — Mar 2025
Aesys S.r.l.
Project Manager

Managed cross-functional teams of 5–10 in Scrum environments, delivering cybersecurity and compliance projects. Oversaw end-to-end development of a GDPR-compliant clinical record platform.

100% regulatory approval for GDPR-compliant clinical record platform
Improved delivery predictability by 20%; reduced compliance gaps by 30%
project management GDPR scrum GRC
Nov 2022 — Feb 2024
Aesys Cyber S.r.l.
Cybersecurity Consultant

Scoped and executed 30+ penetration tests across finance, healthcare and public sectors. Co-developed GRC advisory practice expanding the service portfolio beyond penetration testing.

Reduced exploitable attack surface by 30% via OWASP and PTES methodologies
C-suite risk reports accelerating remediation adoption by 40%
Increased client retention by 20% through new GRC advisory practice
pentest OWASP GRC risk reporting
May 2021 — Nov 2022
ITI — Innovazione
Tecnologica Italiana
Cybersecurity Specialist

Comprehensive vulnerability assessments using Burp Suite, Nessus, Metasploit and Nmap. Supported SOC teams in red and blue team incident response simulations.

Identified 200+ high-risk findings; reduced critical vulnerabilities by 40%
Improved SOC detection coverage by 25% through corrective playbooks
VA/PT Burp Suite Nessus SOC red team
02
PRJ-001 // IMQ S.p.A.
EN 18031 Compliance Roadmap

Designed and executed a strategic EN 18031 compliance roadmap for EU manufacturers. Built a scalable assessment framework for requirements 3.3(d/e/f), enabling presumption of conformity across multi-product portfolios.

EN 18031 RED DA conformity
PRJ-002 // IMQ S.p.A. — WIP
CRA Readiness Program

Co-leading design of IMQ's CRA conformity assessment methodology. Developing a gap analysis framework mapping CRA requirements against IEC 62443 controls, leveraging CEN/CENELEC draft standards.

CRA IEC 62443 gap analysis
+
coming soon
03
Offensive Security
OSCP — Offensive Security Certified Professional
Jan 2023
Offensive Security
OSWA — Offensive Security Web Assessor
Feb 2023
Scrum.org
PSM II — Professional Scrum Master
Oct 2024
04
City, University of London — UK
M.Sc. Cyber Security
Thesis: Keeping Privacy from Email Providers — PGP as WebAssembly Module
Feb 2022
City, University of London — UK
B.Sc. Computer Science
Thesis: Displacement Learning through Vision Sensors Using Machine Learning
Jul 2020