Rocco Calvi — Co-Founder
Rocco is a renowned cybersecurity researcher with deep expertise in source code review, coverage-guided fuzzing, and vulnerability assessment of web and binary applications. With over 13 years of experience, he has significantly advanced cybersecurity for government entities and private sector organizations worldwide, uncovering critical vulnerabilities, including high-impact remote code execution flaws in major products like Microsoft Office 2022 and widely deployed networking hardware. Currently, as Chief Vulnerability Researcher at TecSecurity Research, Rocco leads comprehensive security audits, identifying vulnerabilities through tailored assessments of software frameworks, web applications, and binary executables. His extensive background spans diverse technologies and sectors, earning recognition for his strategic approach and meticulous project management skills. Rocco has provided expert consultancy to prominent Global 1000 organizations such as Microsoft, Mayo Clinic, Nvidia, Meta, CrowdStrike, Amazon, Commonwealth Bank of Australia, and BAE Systems Applied Intelligence. He previously founded the Digital Security Research Centre at the Technology Innovation Institute in the UAE, driving efforts to automate source code auditing in collaboration with the University of Virginia's Cyber Grand Challenge team. His notable achievements include earning multiple first-place positions on Microsoft's Office Security Researcher Leaderboard (2022) and holding over 270 CVEs, primarily involving remote code execution vulnerabilities. Early in his career, Rocco secured first place at Panoply’s 2013 Security in Government Conference and second prize at Hackers for Charity’s international CTF competition. Committed to knowledge sharing, Rocco moderated Offensive Security’s Exploit-Database, led xen1thLabs’ Coordinated Disclosure Program, and contributed to Rapid7’s Metasploit Project, Corelan Team, and Trend Micro’s Zero Day Initiative. His responsible disclosure of critical vulnerabilities has been publicly acknowledged by Google, Microsoft, Adobe, IBM, NETGEAR, TP-LINK, AutoDesk, and VideoLAN.
Stackforce AI infers this person is a Cybersecurity Expert specializing in vulnerability research and software security.
Experience: 17 yrs
Skills
- Vulnerability Research
- Cybersecurity
- Research Management
- Software Security
- Project Management
- Vulnerability Disclosure
- Security Management
Career Highlights
- Over 270 CVEs related to remote code execution vulnerabilities.
- Led vulnerability research for major tech companies.
- Recognized for contributions to cybersecurity knowledge sharing.
Work Experience
TecSecurity
Founder and Vulnerability Researcher (4 yrs 4 mos)
Technology Innovation Institute
Founder and Acting Chief Researcher of Digital Security Research Centre (1 yr)
Digital14
Director of Software Lab (10 mos)
xen1thLabs
Director of Software Lab (1 yr 9 mos)
Lead Security Researcher (2 yrs)
IOActive, Inc.
Lead Security Consultant Contractor (1 yr 3 mos)
Securus Global
Senior Security Consultant (4 mos)
BAE Systems Applied Intelligence
Senior Security Consultant (3 yrs 10 mos)
Corelan Team
Security Researcher and Exploit Developer (2 yrs)
Education
Bachelor’s Degree at Swinburne University of Technology