Application security specialist and security code reviewer
Milan Area, Italy
Application security specialist and security code reviewer
Milan Area, Italy
Code reviewer and SSDLC designer. I help my customers in adding security into their SDLC (Software Development LiveCycle) using a "step by step" approach trying to be as gentle as possible with existing workflows.
Focused into reviewing source code with automatic both static than dynamic tools and with a manual code review process to better refine tools' results.
Active in research in the source static analysis, in paper writing and evangelism in various conferences about SSDLC, code review and safe coding.
Penetration tester in many ethical hacking activities for important realities such as banks, telcos, manufacture industries in the Italian market place.
code reviewing, SSDLC, safe coding, penetration testing, java, c, web application delopment, kernel hacking, linux, unix, osx
(Privately Held; 201-500 employees; Computer & Network Security industry)
December 2008 — Present (1 year )
The Source code flaws Top 10 project is a project with the ambitious goal to give a taxonomy for security flaws you can find in a security code review.
Providing such a taxonomy we can use it into Owasp Code Review guide and into Owasp Orizon project to gather security findings introducing source flaw categories.
Main project link: http://www.owasp.org/index.php/Project_Information:template_Source_Code_Flaws_Top_10_Project
(Non-Profit; Information Technology and Services industry)
October 2006 — Present (3 years 2 months)
Owasp Orizon is a framework to provide security tools code reviewing and SSDLC safe coding rules enforcement.
I'm project leader of Orizon and our mean goal is to provide to opensource community a good programming safe coding library and APIs to make source code assessment
(Computer & Network Security industry)
November 2004 — Present (5 years 1 month)
Code reviewing and SSDLC building
Penetration tester
Identity and Access Management solution design and implementation
Laurea , Computer Science, Security, Operating Systems, Networking , 1995 — 2001
Maturità tecnica , Computer Science, Software development , 1991 — 1995
Rollerblade, taekwon-do, playing guitar, drinking beer, photograph, writing, reading, listening music, coding
Owasp, sikurezza.org