Claudio Sasso
Director, Ethical Hacking Team @Oracle
Signup · Get unlimited contacts
WORK HISTORY
Director, Ethical Hacking Team @Oracle
London, GB
Responsible for a team of hardware hackers as well as developers working on automation and tooling.Responsible for identifying targets and manage the whole lifecycle of Security Assessment on Oracle products (hardware and software), interacting with developers and supply chain, taking active role in the design of fixes as well as architectural change, and finally presenting the results to Executives.Tech lead in software assessment; as much as possible, I am taking part to every assessment to maintain my technical skills and learn more. Still involved in scaling security, automate attacks and defense, coverage analysis, effective/advanced code analysis, threat modeling, vulnerability identification automation, fuzzing.
EDUCATION
Università degli studi Roma TRE
Hons in Computer Science [Software Engineering], Software Development, Telecommunications, Information Technologies
Università degli studi RomaTre
Bachelor Degree, Computer Science
SKILLS
ABOUT CLAUDIO SASSO
20 years of experience in the field of security across various domains: DevSecOps Strategy, Security Process / SDLC Design, Governance and Security Dashboards/Indicators, Red Team Assessments (SAST, DAST, IAST, and Reverse Engineering), Blue Team Secure Design/Bug Fixing, Standards & Compliance, Security Instructor.> As Cyber Security Director focused on identify key priorities, strategic initiatives, new security standards and technological advancements that form the foundation of our Security Program. Lead the adoption of cutting-edge defence technologies by leveraging insights gained from security assessments that employ state-of-the-art techniques to uncover and exploit vulnerabilities.> As Security Engineer, I have conducted numerous web, infrastructure, and product security assessments, involving in-depth review of extensive codebases. This work has primarily focused on Enterprise platforms, both Business-to-Business (B2B) and Business-to-Consumer (B2C), as well as Open Source Software (OSS). I have also served as an additional Security Architect/Engineer, actively contributing to hands-on issue resolution and the redesign of systems in response to high-severity vulnerabilities.> Cyber Security Trainer: Java Security, Secure Software Development and Penetration Testing classes, Penetration testing labs and CTF competitions, Exploit writing for demosKeywords: Net Analysis; Vulnerability identification; SQL injection; XSS; Session/Net Transfers hijacking; Java Security; Web Security; Web Application Development; Protocol Analysis; BGP; Root Cause Analysis; Internal AS Structure; EJB Security; ISO27001; ITIL; Target2; Regulations; Compliance; SDLC; SSDLC; SAP Pentesting; Cloud; Authorization Model; RBAC; DAC; ABAC; SSRF; CSRF; MITM; SSL vulnerabilities; Java Serialization
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.