Egidio Romano

Associate Consultant

Piazza Armerina, Sicily, Italy16 yrs 11 mos experience
Highly Stable

Key Highlights

  • Over 700 unique vulnerabilities reported.
  • Expert in web application security.
  • Extensive experience in penetration testing.
Stackforce AI infers this person is a Cybersecurity expert specializing in web application security and vulnerability management.

Contact

Skills

Core Skills

Penetration TestingVulnerability AssessmentVulnerability ManagementVulnerability IntelligenceSecurity ResearchSecurity Code Review

Other Skills

Security AssessmentsSecurity Vulnerability ValidationSecurity TestingCVE CollectionWeb Application SecurityVulnerability ResearchCode ReviewSoftware TestingSoftware EngineeringInformation Security ManagementSecurity AuditsISO 27001PCI DSSComputer SecurityApplication Security

About

I am a curious guy who enjoys exploring in order to understand how things are made and how they work. I am also known as "EgiX", which is the nickname I chose when I was fifteen. Following are some info and numbers about me: • Collecting CVEs since 2007 – so far 180 (https://karmainsecurity.com/research) • 200+ files on Packet Storm (https://packetstorm.news/files/author/5967) • 100+ penetration tests with the Cobalt Core (https://www.cobalt.io) • Exploit Database: https://www.exploit-db.com/?author=1024|6398 • Bugcrowd profile: https://bugcrowd.com/EgiX

Experience

Bugcrowd inc

Application Security Engineer

Apr 2017Jun 2018 · 1 yr 2 mos

  • I was part of the Application Security Engineer (ASE) team at Bugcrowd. This involved triaging and validation of incoming security vulnerability submissions for some of the company's managed bug bounty programs, which means taking incoming submission data and curate it for validity, accuracy, and severity, as well as communicate directly with Bugcrowd's clients or researchers when additional information was required.
Vulnerability ManagementSecurity Vulnerability Validation

Synack red team

Penetration Tester

Feb 2017Sep 2020 · 3 yrs 7 mos

  • I was part of the Synack Red Team (SRT), which gives to some cybersecurity researchers across the globe a platform to do what they love and get paid for it. As a member of the SRT, I participated in security assessments for various organizations worldwide, performing penetration testing activities remotely. This involved analyzing IT systems and applications for potential vulnerabilities and contributing to security research within the platform.
Penetration TestingSecurity Assessments

Cobalt.io

Penetration Tester

May 2016Jul 2025 · 9 yrs 2 mos

  • I was part of the Cobalt Core community, performing 100+ penetration testing engagements and reporting over 700 unique security vulnerabilities through the cobalt.io platform. Over these years, I conducted in-depth web, mobile, and infrastructure penetration tests for organizations across a wide range of industries, consistently delivering actionable findings that strengthened customers' IT security posture.
Penetration TestingVulnerability AssessmentSecurity Research

Karma(in)security

IT Security: Consultant & Researcher

Jan 2016Present · 10 yrs 2 mos

Minded security

Application Security Consultant

Nov 2014Dec 2015 · 1 yr 1 mo

  • I was part of the security consultancy team at Minded Security, where I performed several technical activities such as vulnerability assessment, security code review, and penetration testing of almost any kind of mobile and web application out there, mainly in the banking and financial industry. During the employment I also enjoyed doing some vulnerability research projects on certain open source software, discovering and reporting security issues in Concrete5, CakePHP, and MISP.
Vulnerability AssessmentSecurity Code Review

Secunia

Information Security Specialist

May 2013Apr 2014 · 11 mos

  • I was part of the research team providing the vulnerability intelligence information powering all Secunia products. This involved monitoring several sources of vulnerability information, and verifying the validity of security reports through technical testing and communication with software vendors. Specialized in testing and assessment of vulnerabilities in web applications and virtual appliances. I also performed a security code review of Secunia CSI 7.0 before its launch on September 2013.
Vulnerability IntelligenceSecurity Testing

Sugarcrm

Virtual Internship

Apr 2012Apr 2012 · 0 mo

  • I performed a security code review of SugarCRM Community Edition as part of my experimental thesis - which concerns web application security testing techniques - by using a customized white-box approach based on the OWASP testing methodology. As a result, I have identified around fifty security issues, which have been fixed in SugarCRM Community Edition versions 6.4.0, 6.4.3, and other commercial versions.
Security Code Review

Karma(in)security

Independent Security Researcher

Jul 2007Apr 2013 · 5 yrs 9 mos

  • During my graduation studies I tried to improve my technical knowledge in the computer security field, especially with regards to web application security. In my spare time I loved to hunt for security bugs in open source web applications. As a result, I've collected dozens of CVEs by discovering and reporting security issues in applications like Joomla, TikiWiki, WebCalendar, PmWiki, Zenphoto, phpMyFAQ, phpLDAPadmin, WeBid, Mantis Bug Tracker, phpScheduleIt, Coppermine, Docebo, CMS Made Simple and some others.
Security ResearchCVE Collection

Education

Università di Catania

BS in Computer Science

Stackforce found 100+ more professionals with Penetration Testing & Vulnerability Assessment

Explore similar profiles based on matching skills and experience