Available for opportunities

Carlo Grancini.

Network & Cybersecurity student

Milan, Italy

Who I Am

I am a computer science student passionate about networking, cybersecurity, and Linux environments. I am motivated, reliable, and highly oriented towards technical problem-solving.

I have solid experience in CTF competitions, including OliCyber and CyberChallenge.IT, where I trained and competed alongside the official cybersecurity team of the University of Milan (Università Statale di Milano).

I believe in hands-on learning, security hardening, and building robust, highly optimized systems. When I am not solving security challenges, I am designing home network infrastructures, configuring physical network nodes, or scripting automation tools.

What I Work With

Virtualization & Infra

Proxmox VE Clustering & HA KVM / LXC Docker & Compose Linux (Ubuntu/Debian)

Cybersecurity & Analysis

Burp Suite Ghidra / Binary Ninja Penetration Testing Nmap / Wireshark CTF (OliCyber/CyberChallenge)

Networking & Routing

OPNsense / pfSense VLAN Segmentation WireGuard VPN Hardware Switch Config Cisco IOS (CCNA)

Languages & Dev

Java C / C++ Rust Python & Bash HTML / CSS / JS (Astro)

What I've Done

PC Hardware & Retail Engineering Intern

Sep 2025

PC Maestro · Cork, Ireland

Performed hardware assembly, comprehensive troubleshooting, and detailed board-level repairs on enterprise laptops and consumer PCs. Handled technical sales and customer support, operating completely within a native English-speaking environment.

CyberChallenge.IT Competitor & Security Trainee

2023 — 2025

Università Statale di Milano & OliCyber

Selected for the highly competitive national CyberChallenge.IT program at the University of Milan (Statale di Milano) in May 2025. Trained and competed with the university's official cybersecurity team in advanced security challenges, specializing in Reverse Engineering, Cryptography, Binary Exploitation, and Web Security. Was also active in the OliCyber.IT competition from 2023 to 2025.

IT Infrastructure & Network Developer

Oct 2023 — May 2024

Ricoh · Milan, Italy

Assisted in planning, designing, and deploying robust IT and digitalization systems. Built secure, scaled network infrastructures optimized for educational institutions in partnership with Ricoh's engineering team.

Computer Science Student

2021 — Present

ITSOS Marie Curie · Cernusco sul Naviglio

Studying Computer Science and Telecommunications with a major focus on standard networking protocols, Cisco IOS routing, Linux system administration, database management, and structured software development.

What I've Built

System Administration & Infrastructure

Enterprise Homelab & Virtualization Cluster

A compact, resilient, and segmented home lab for hosting containerized services, automation scripts, and network security testing.

Compute Nodes 4x i5-12450H (32 Cores tot.) / 64GB RAM
Storage 4x 512GB NVMe SSDs
Enclosure Compact 10" 6U Rack Cabin
Power Backup 1200W UPS Battery System

Logical Architecture & Clustering

  • Proxmox VE Cluster (3 Nodes): Configured in High Availability (HA) for dynamic failover and orchestrating KVM virtual machines and LXC containers.
  • Windows Workstation (1 Node): Isolated environment optimized for high-performance development and active security testing.
  • VLAN Network Segmentation: Controlled routing and traffic isolation implemented via custom firewall policies, separating IoT devices, sandbox lab systems, and home LAN.

Physical Networking & Resilience

  • Layer 2 Managed Switching: High-speed local switching backbone to manage high-throughput inter-node clustering communication and bridge to the main gateway.
  • 1200W UPS Continuity: Complete power protection, preventing data corruption during outages and enabling graceful automated shutdown sequences.
  • Setup Status: Active & Segmented
Full-Stack Development & Security Hardening

Siregest.it — Zero-Trust Cloud Architecture

Visit Website

Full deployment, speed tuning, and strict security hardening for a real-world enterprise management platform.

Server Ubuntu VPS (Self-hosted/Hardened)
Frontend Astro SSR / Node.js & PM2
Backend / CMS Directus on Docker & PostgreSQL
Edge / Reverse Proxy Cloudflare Tunnel (Zero Exposed Ports)

VPS Hardening & Zero-Trust

  • Local Service Confinement: All backend processes and database layers bind strictly to local loopback interfaces, remaining entirely invisible to the public internet.
  • Cloudflare Tunnel Integration: Standard web ingress ports are locked at the system firewall. Web traffic enters securely via a local encrypted tunnel daemon.
  • OS-Level Protections: Hardened system firewall policies, Fail2Ban brute-force mitigation on SSH, unattended nightly security patches, and automated encrypted cron backups.

Edge Security & Threat Mitigation

  • BREACH Side-Channel Defense: Payload compression (Gzip/Brotli) is disabled on administrative control panels, neutralizing side-channel leaks of sensitive session cookies.
  • Edge Security Headers: Enforced strict HSTS policies, X-Frame anti-clickjacking protections, MIME-sniffing mitigations, and stripped tech identifiers to block fingerprinting.
  • WAF & Geo-Fencing: Configured Cloudflare Bot Fight Mode, custom challenges for irregular geographical regions, and static Edge caching for performance.
Troubleshooting Case Study: The 15-Minute Token Expiry Bug

The Bug: Initially, authenticated media assets expired every 15 minutes due to CDN edge caching holding onto temporary session-based authorization tokens generated by the server. When the token expired, the cached asset links broke, resulting in sporadic loading failures.
The Secure Resolution: Redesigned the asset routing to pull public-facing media directly from structured folders, bypassing the need for session tokens in URLs. Enforced server-side validation using static API keys confined strictly within the local environment. This achieved flawless caching efficiency while elevating asset access security.

Credentials & Training

Professional & Global Credentials

Independent Certified Courses

Let's Connect

Interested in collaborating or just want to chat about tech and cybersecurity? Feel free to reach out.