Jackie Giancarlo Rizzi
Senior Security Researcher @Veracode
Signup · Get unlimited contacts
WORK HISTORY
Senior Security Researcher @Veracode
London, GB
Applied Research focused on developing new capabilities for Veracode\'s product line:• Dynamic Analysis of Web Applications and API (Veracode DAST)• Static Analysis Security Testing (SAST)• Software Composition Analysis (SCA)• Veracode Package Firewall (Malicious Packages)• Veracode Fix (Artificial Intelligence Security Flaw Remediation)• Veracode Risk Manager (Unified findings, Prioritized solutions, Best Next Actions, ASPM)Incubation Research at the edge of Offensive Security and Attack Surface Management:• rapidly prototyping capabilities in asset discovery, vulnerability identification, PoC development, and offensive automation tooling.Tools Development:• Development of tools for detection and exploitation• Focus on identifying, researching and automating interesting attack techniquesTechnologies and related frameworks:• Go Lang, Rust, Python, JavaScript, Java, C/C++, PHP, Ruby, Shell Script, Assembly x86/x86-64
SKILLS
ABOUT JACKIE GIANCARLO RIZZI
I am a Senior Security Researcher of the Applied Research team at Veracode, where I specialize in crafting new capabilities for Veracode\'s product line. My primary areas of responsibility include Dynamic Analysis of Web Applications and APIs (Veracode DAST), Software Composition Analysis (SCA), and Static Analysis Security Testing (SAST)With six years as a penetration tester at Veracode and a background as a software engineer, I leverage this dual expertise to drive research and innovation. Operating within a rapid prototyping cycle, I facilitate technology transfer from incubation to product and engineering teams.I have transitioned from commercial penetration testing to pursue full-time research while maintaining active engagement in Ethical Hacking and Bug Hunting through Vulnerability Disclosure Programs (VDP), Bug Bounties, and Open-Source Software analysis. My research focuses on novel attack techniques, asset discovery, vulnerability identification, developing Proof of Concepts (PoCs), and creating automation tools within Offensive Security.Driven by a desire to contribute to the open-source community, I actively seek opportunities for meaningful engagement and collaboration.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.