Skip to content
View ZGr3Y's full-sized avatar

Block or report ZGr3Y

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ZGr3Y/README.md

Hi, I'm Paolo Scarlata 👋

M.Sc. student in Computer Science at the University of Catania, specializing in Cloud Systems and Cybersecurity.

I build secure backend and distributed systems, with experience in Python automation, identity and access management, data workflows, and event-driven architectures.

Experience

I worked as a Backend Software Developer Intern at AITHO, contributing to an AI platform using Python, MLflow, Alembic, Azure Functions, and Microsoft Entra ID.

My work included idempotent automation, database migrations, JWT/JWKS validation, automated testing, and quota-aware API request handling.

Featured Projects

Event-driven security monitoring system built with Java 21, Spring Boot, RabbitMQ, PostgreSQL, and Docker.

  • Real-time log ingestion and analysis
  • Brute-force, denial-of-service, and malicious-payload detection
  • Idempotency, rate limiting, circuit breaking, and automated testing

Reproducible Capture the Flag environment developed for my bachelor’s thesis using Node.js, Express, Docker, and JWT.

Includes challenges involving IDOR and WAF bypass, JWT JWK injection, backup-file disclosure, and insecure password hashing.

Vulnerable and hardened web applications demonstrating broken access control, insecure JWT handling, IDOR exploitation, HTTPS enforcement, and secure session management.

Technical Stack

  • Languages: Python, Java, JavaScript, SQL, C, C++
  • Backend & Data: Spring Boot, Node.js, Express, MLflow, Alembic, PostgreSQL, RabbitMQ
  • Cloud & DevOps: Azure Functions, AWS, Docker, Kubernetes, GitHub Actions, Linux
  • Security: Microsoft Entra ID, OAuth 2.0, OpenID Connect, JWT/JWKS, RBAC, OWASP methodology

Current Interests

Cloud security, distributed systems, identity and access management, secure backend engineering, and security monitoring.

Contact

paolo.scarlata2001ct@gmail.com

Pinned Loading

  1. Broken-Access-Control Broken-Access-Control Public

    Internet Security Project

    JavaScript

  2. CTF CTF Public

    CTF project for bachelor degree

    JavaScript

  3. sentinel-distributed-siem sentinel-distributed-siem Public

    Java 1