Diego Zamboni

CISO • Organizational Leader • Security Expert • Computer Scientist

I am a senior computer scientist, computer security expert, IT architect, organization and team leader with 30 years of professional experience, and much longer of being fascinated and passionate about science, computing and education. I specialize in the areas of Computer Security, Cloud Computing, Self-healing Systems and Configuration Management.

I possess a strong combination of leadership, conceptual and technical skills that enable me to help organizations and teams reach their goals. I have excellent communication abilities, with ample experience in writing, teaching and public speaking. I can interact and work fluently at the strategic, tactical and technical levels. I have a Ph.D. in Computer Science and have extensive experience in both academic and business environments.

Professional Highlights

Management and leadership, IT security, cloud computing

  • Chief Information Security Officer for Governance at Avaloq, defining and managing Avaloq's global ISO27001-certified Information Security Management System

  • Managed security architecture at the Stellantis Virtual Engineering Workbench project. Worked with Stellantis CISO and business stakeholders to define governance, establish security best practices and drive risk analysis, threat modeling and mitigation.

  • Established scalable and durable mechanisms to enable partners to work securely in the Volkswagen Digital Production Platform (DPP) program.

  • Managed security architecture, risk management, data governance and compliance (ISO27001, ISAE3402/3000, etc.) for Swisscom's Cloud platforms.

  • Established and led the Swisscom IT Clouds security community of practice.

  • Established and led the Health and State Management team at Swisscom to design, implement and operate a framework for scalable monitoring, logging and alerting for Swisscom's Cloud platforms.

  • Established and led the first computer security organization at UNAM, which has grown into the university's Information Security Coordination (UNAM-CERT).

  • Managed IT security customer relationships at HP Enterprise Services, including overseeing the activities of operational and engineering teams, risk and compliance management, requirements discussion and reporting.

Research, architecture and design

  • Designed the Orchard monitoring framework for Swisscom's Application Cloud platform, and led the team that implemented it and brought it into production.

  • Designed and implemented the Billy Goat malware capture and analysis system at IBM.

Experience

CISO Governance

– Present 2 yrs 1 mo
Switzerland

I lead the global CISO Governance team, focusing on establishing robust security policies and monitoring compliance. I am in charge of defining and monitoring Avaloq's global Information Security Management System. My role involves defining requirements and ensuring effective oversight of first-line security functions, which is essential for maintaining a secure and compliant environment in the financial technology sector.

Amazon Web Services

2 yrs 3 mos
Senior Global Security Architect
1 yr 3 mos
Switzerland

I worked with customers and within AWS to increase security awareness, design and build secure solutions, mentor and develop colleagues and customers in security best practices. I was Lead Security Architect in the Stellantis Virtual Engineering Workbench (VEW) project.

  • Established the VEW security workstream to identify customer security requirements and policies, define and promote security best practices and drive activities related to risk analysis, threat modeling and mitigation definition, prioritization and implementation.

  • Established in VEW measurement mechanisms for status and metrics for security activities, which provide visibility to both technical and business stakeholders.

  • Established the VEW Security Champions program to promote and transfer security knowledge.

  • Defined and tracked implementation of security features in VEW to fulfill both customer business requirements and AWS best practices.

Global Security Architect
1 yr
Switzerland

Worked with AWS global customers to improve security posture and promote secure design and implementation practices. I was a member of the security team in the Volkswagen Digital Production Platform (DPP) project.

  • Established in DPP scalable and durable mechanisms to enable DPP partners to work securely in the DPP program.

  • Created and promoted security learning materials tailored for various roles within the DPP project.

  • Increased security awareness and knowledge by promoting a Security Guardians initiative across the DPP organization.

Swisscom

7 yrs 2 mos
Enterprise Architect and IT Clouds Solution Security Architect
2 yrs 6 mos
Switzerland

As an Enterprise Architect, I participated in the design of future products and solutions offered by Swisscom, in collaboration with architects from all other divisions of the company.

As Solution Security Architect for Swisscom's Cloud Platforms (including Enterprise Service Cloud, Enterprise Application Cloud, Dynamic Computing Services, Enterprise Cloud for SAP Applications and related services) I was responsible for the security, compliance and data governance of those services. I defined, prioritized and drove relevant product features and business goals. I also lead the IT Clouds Security Community of Practice and advised engineering teams on compliance, governance and operational activities.

  • Ensured cloud platform and service compliance with internal, contractual and regulatory standards, including ISO27001, ISAE3402/3000 and GDPR.

  • Established and led a community of around 30 /Security Champions/ from different teams, who drove security initiatives and promote the security culture within the Swisscom IT Clouds organization.

  • Coordinated threat modeling, audits, penetration tests and security compliance reporting.

  • Coordinated organization- and team-wide processes for risk and vulnerability management.

  • Development of the Swisscom Platforms vision for 2025.

Team Lead & Product Owner for Health & State Management
3 yrs
Switzerland

I built and led a team which evolved on par with Swisscom cloud platforms to provide their monitoring and logging capabilities. My responsibilities included people management (up to 16 people), definition and prioritization of requirements and roadmaps (in collaboration with Product Managers and other stakeholders), technical architecture, and managing the planning and execution of team activities.

  • Led the transition of the Enterprise Cloud LEMM (Logging, Event Management and Monitoring) and Access & Inventory frameworks into maintenance mode as the platform was retired.

  • Defined the scope and mission of the Health and State Management (HSM) team as part of the new Enterprise Service Cloud project, and later of other platforms as the IT Clouds scope expanded to Application Cloud, Enterprise Cloud for SAP Solutions and Dynamic Computing Services.

  • Defined the logging and monitoring architecture for the Enterprise Service Cloud platform based on VMware vRealize Operations and vRealize Log Insight.

  • Led the transition of the Application Cloud platform monitoring from the Orchard framework to a TICK-based framework.

  • Defined architecture and oversaw implementation of the Customer Log Forwarding service.

  • Managed business relationship and technical implementation of OpsGenie for alert management in IT Clouds.

  • Main technologies involved: VMware vSphere (ESX, vCenter, NSX), VMware vRealize Operations Manager and Log Insight, Ansible (configuration management), OpsGenie (alert management).

Cloud Architect and Orchard Project Lead
7 mos
Switzerland

Managed a team of three people and led the Orchard project through its implementation, production release and further improvements and development.

Cloud Lab Senior Platform Architect
11 mos
U.S.A. (remote)
  • Designed the architecture and implemented the initial prototype for the Orchard health-management and self-healing framework for Swisscom's Application Cloud Platform-as-a-Service service.

  • Main technologies involved: OpenStack (cloud computing infrastructure), Cloud Foundry (application platform), Consul (health management and service discovery), RabbitMQ (message bus), Riemann (event analysis).

CFEngine AS

3 yrs 7 mos
Product Manager
10 mos
Norway/U.S.A. (remote)
  • Managed the CFEngine language roadmap.

  • Created and led the CFEngine Design Center project, which was the foundation for the current CFEngine Build service.

  • Coordinated the work on CFEngine third-party integration (e.g. AWS EC2, VMware, Docker and OpenStack).

  • Developed code for both the Design Center core and its integrations.

Senior Security Advisor
2 yrs 8 mos
Norway/U.S.A. (remote)
  • CFEngine Advocate, with a special focus on security.

  • Wrote the book Learning CFEngine 3, published by O'Reilly Media, which became the de facto introductory text to CFEngine.

  • Gave talks, wrote articles and blog posts, taught classes, and in general spread the word about CFEngine.

  • Developed and implemented the strategy for CFEngine as a security component.

Cofounder, Head of Research and Training

Boundless Innovation and Technology
2 yrs
Mexico

I advised and coordinated teams working on teaching- and security-related products, consulting and services.

HP Enterprise Services

1 yr 11 mos
Account Security Officer
1 yr
Mexico
  • Acted as first point of contact for all security-related issues for five HP enterprise customers in Mexico.

  • Initiated, advised and managed security-related projects.

  • Handled communication and coordination between technical teams involved in security initiatives.

  • Involved in all security-related decisions at the sales, design, implementation, delivery and ongoing maintenance stages of IT Outsourcing projects.

IT Outsourcing Service Delivery Consultant
11 mos
Mexico
  • Helped multidisciplinary customer teams (software engineering, IT management, networking, sales and support) by solving complex problems in customer environments.

  • Performed analysis, design and implementation of solutions in multiple areas of expertise, including system automation, configuration management, system administration, system design, virtualization, performance and security.

Developer (Intern)

3 mos
U.S.A.
  • Developer for the Bruce host vulnerability scanner, later released as the Sun Enterprise Network Security Service (SENSS).

  • Designed and implemented the first version of the network-based components of Bruce, which allowed it to operate on several hosts in a network, controlled from a central location.

National Autonomous University of Mexico (UNAM)

4 yrs 9 mos
Founder and lead of Computer Security Area
1 yr
Mexico
  • Established UNAM's Computer Security Area, the University's first team dedicated to computer security, which has evolved into the Information Security Coordination (UNAM-CERT).

  • Managed up to nine people working on different projects related to computer security.

  • Managed security monitoring for a Cray supercomputer and 22 Unix workstations.

  • Provided security services to the whole University, including incident response, security information, auditing and teaching.

  • Established the celebration of the International Computer Security Day (sponsored by the Association for Computing Machinery) at UNAM. Acted as the main organizer of the event for two years (1994 and 1995). This event has grown and evolved into the Computer Security Day and the Computer Security Congress.

  • Designed and headed development of an audit-analysis tool for Unix systems (SAINT).

System Administrator
3 yrs 9 mos
Mexico
  • System administrator at UNAM's Supercomputing Center, managing a Cray Y-MP Supercomputer and related systems.

  • Managed the Network Queuing Subsystem (NQS),

  • Managed and provided support for 22 Unix workstations.

  • Monitored the security of the Cray supercomputer and related workstations.

  • Other responsibilities: user administration, operating system installation, resource management, security policies.

Education

Certifications

Research

Phantom

IBM Research
1 yr
  • Developed security solution for VMware virtual environments using virtual machine introspection

  • Implemented intrusion detection and prevention capabilities based on VMware VMsafe API

  • Publications: [13]

Billy Goat: Active worm detection and capture

IBM Research
6 yrs
  • Pioneered active worm-capture technology that became the foundation for modern honeypots and honeynets

  • Designed system to simulate thousands of vulnerable hosts to attract and capture propagating worms

  • Implemented automated analysis to extract signatures and update intrusion detection/prevention systems

  • Publications: [18], [25]

Router-based Billy Goat

IBM Research
2 yrs
  • Deployed active worm-capture at network boundary, coupled with border router infrastructure

  • Implemented automatic IP address spoofing to cover entire external address space

  • Enabled accurate detection of infected local machines and prevention of outbound worm propagation

  • Publications: [17]

SOC in a Box

IBM Research
2 yrs
  • Pioneered integrated security appliance concept, precursor to modern Unified Threat Management systems

  • Combined multiple security functions: intrusion detection, worm detection, vulnerability scanning, and network discovery

Exorcist

IBM Research
1 yr
  • Developed host-based intrusion detection system using behavior analysis

  • Implemented system call sequence monitoring for anomaly detection

Using autonomous agents for intrusion detection

Purdue University
2 yrs
  • Designed AAFID architecture for distributed monitoring and intrusion detection using autonomous agents

  • Implemented and published prototype as open source, contributing to distributed IDS research community

  • Explored novel research approaches in distributed intrusion detection

  • Publications: [21], [22], [28], [35], [33], [34]

Software

Pilatus

IBM Research (not publicly available)
2 yrs 11 mos

An automated system installer that allows arbitrary system installation and configurations, allowing for both proprietary and open source components to be installed in an automated fashion. Open source components can be downloaded directly from their original source to avoid distributing them.

Embedded Sensors Project

Purdue University
2 yrs 11 mos

A system of sensors for intrusion detection developed in OpenBSD through code instrumentation. Developed as part of my Ph.D. thesis work.

Honors & Awards

UPE Microsoft Scholarship Award

Awarded by UPE and Microsoft

Member of Phi Beta Delta

Awarded by Phi Beta Delta honor society

Fulbright Scholarship (for pursuing Ph.D. studies at Purdue University)

Awarded by Fulbright Program and CONACYT

Program Committees and Boards

Program co-chair

IBM Academy of Technology Security and Privacy Symposium (internal IBM event)
2 days

Program Chair

ZISC Workshop on Security in Virtualized Environments and Cloud Computing

Program Chair

Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA)
1 day

Advising

Daniele Sgandurra (University of Pisa, Italy)

Internship advisor at IBM Research
11 mos
  • Project: Design and implementation of process injection using virtual machine introspection.

Martin Carbone (Georgia Institute of Technology, U.S.A.)

Internship advisor at IBM Research
11 mos
  • Project: Implementation of a proof of concept Hyperjacking attack on Intel platform.

Teaching

CISSP training (30 hours)

iNetworks, Mexico (remote class)

CFEngine one-day training class (8 hours)

Multiple venues
2 yrs

Virtualization lecture (2 hours), Systems Security class, Computer Science Dept.

ETH Zürich
2 yrs

Intrusion detection: Basic concepts and current research at IBM class (3 hours), Information Technology Security Spring School

University of Lausanne

Introduction to Computer Security class (40 hours)

ITESM, Mexico

EE495 (Information Extraction, Retrieval and Security) course

Purdue University, U.S.A.
  • Co-designed eight security-related lectures and taught two of them

  • Co-designed the class project

SSH: Achieving secure communication over insecure channels class

CSI NetSec conference, U.S.A.

Protecting your computing system class

Schlumberger, U.S.A.

Supercomputing Internship Program Courses

UNAM, Mexico
5 yrs

Designed and taught multiple courses (10-40 hours long) on the following topics:

  • Introduction to Unix

  • Unix utilities

  • Unix security

  • Basic Unix administration

  • Advanced Unix administration

  • UNICOS system administration on Cray supercomputers

Other Professional Activities

Publications

Skills

Leadership

  • 32 years of multidisciplinary team and project leadership experience
  • IT Enterprise Architecture
  • Scaled Agile Framework (SAFe)

Communication

  • Excellent written and spoken communication skills
  • Extensive public speaking experience
  • Professional writing and teaching experience

Information and Cyber Security

  • Enterprise security governance
  • Enterprise security architecture
  • Virtualization and cloud computing security
  • Risk management and compliance
  • Intrusion detection and prevention
  • Software security and secure software development
  • ISO27001

Technology

  • Broad and deep IT expertise
  • Cloud computing
  • Computer security
  • Operating systems
  • Networking
  • Configuration management
  • Software & services development
  • Programming languages

Cloud Computing

  • AWS architecture
  • AWS security
  • AWS infrastructure and development
  • Held multiple AWS Professional- and Associate-level certifications (Security, Solutions Architect, Dev/Sysops) from 2022-2025

Research

  • Ph.D. in Computer Science
  • 9 years of experience at IBM Research

Programming Languages

  • Ruby
  • Python
  • C
  • Perl
  • Java
  • LISP family (Clojure, Racket)
  • Unix shells and tools

Systems & Development

  • Unix/Linux systems engineering and administration
  • System health management and monitoring
  • Cloud platforms
  • Software development
  • Configuration management (CFEngine, Puppet, Chef, Ansible)

Development Environments & Technologies

  • Unix/Linux
  • Cloud Foundry
  • Amazon EC2
  • macOS
  • VMware (ESX, vSphere)
  • OpenStack
  • Docker
  • REST APIs
  • XML and related technologies
  • Network programming
  • Database programming (SQL)
  • Kernel programming (OpenBSD and Linux)
  • HTML

Languages

Spanish

Native

English

Full proficiency

German

Intermediate proficiency (B2 level)

References

Available by request