Career Profile

Domenico Gigante received the Bachelor degree in Computer Science and M.S. degree in Cybersecurity from the University of Bari “A. Moro”, Italy, in 2019 and 2021, respectively. He currently works at Ser&Practices Srl as Cybersecurity Engineer. His activities involve Web Application Penetration Testing, VAPT and Code Review. In November 2024, he has concluded his industrial PhD in Cybersecurity applied to AI-based systems at the Department of Computer Science, University of Bari “A. Moro”. He is the author and co-author of research articles in peer-reviewed national and international journals. His research interests include Trustworthy (Privacy- and Security-oriented) AI and Secure Software Engineering. In his free time, he loves playing CTFs, mostly on HTB, reading cybersecurity bullettins, and working out.

Experiences

Cyber Security Master Teacher

2021 - Present
Talent Garden Spa

Here he works as teacher for a Professional Master’s Programme (Master di 1° livello) on Ethical Hacking. The topics are:

  • Information Gathering
  • Footprinting & Scanning
  • Enumeration
  • Fundamental Host-based & Network-based Attacks
  • Exploitation
  • Priviledge Escalation
  • Metasploit Framework

Pentester | Cybersecurity Engineer | Backend Project Lead

2021 - Present
Ser&Practices Srl

Here he mainly works as Security Engineer. His activities involve:

  • Web Application Penetration Testing
  • Code Audit
  • VAPT
    More in detail, over a 3 years period here he addressed various application domains (Retails, Finance, Sport and Bidding, Furniture) and he:
  • Performed 30 black-box API penetration tests (Burp, Nmap, …)
  • Performed 5 black-box web application penetration tests (Burp, Nmap, …)
  • Performed 5 Vulnerability Assessment and Penetration Testing (VAPT) for web applications and API
  • Performed 20 code static and dynamic analyses (Fortify SAST and DAST, SonarQube)
  • Discovered and exploited more than 100 Critical and 300 High vulnerabilities
  • Reviewed the on-cloud system design for the entire product line of a proprietary service
  • Created 100+ automation scripts using Python and Bash
  • Discussed with 10+ company owners to provide recommendations for secure designs
  • Wrote 100+ security reports detailing the security vulnerabilities compliant with standards like OWASP and GDPR
  • Prepared 100+ executive reports and presentations
  • Created 10 cloud CI/CD pipelines to implement DevSecOps processes for companies
    He also works as Project Lead for the backend side of an internal product. Some of the activities are:
  • Interaction with customer to decide the system architecture optimization and evolution
  • Interaction with customer to validate bugs and plan change requests
  • Creation and maintenance of the cloud CI/CD pipeline
  • Creation and maintenance of the required cloud environments and assets (AWS, Azure)
  • Planning and execution of source code development tasks (PHP, .NET, Python, Bash)
  • Creation and maintenance of the application databases (MySQL, MongoDB)
  • Creation and maintenance of a cache system for the application (Redis)
  • Development of webviews rendered by a mobile application (HTML, CSS, Javascript)

Junior Software Developer

2019 - 2021
Auriga Spa

Here he worked as junior developer in the banking & finance domain. His activities involved:

  • Development of low-level libraries to interact with small and specialized hardware (C++)
  • Development of high-level libraries to simplify the interaction with low-level libraries (C#)
  • Development of frontend components for a proprietary console application (ASP.NET)
  • Hardening of Windows machines against physical attacks

Education

PhD in AI and Cybersecurity

2021 - 2024
University of Bari "A. Moro"

He conducted research in the fields of Trustworthy (Privacy- and Security-oriented) AI and Secure Software Engineering. He published various articles in peer-reviewed national and international journals and was a speaker at international conferences, e.g. International Conference on Evaluation and Assessment in Software Engineering (EASE) and International Conference on AI Engineering (CAIN). He is the main author of the POLARIS AI framework. More details in the dedicated paragraph below.

MSc in Cybersecurity

2019 - 2021
University of Bari "A. Moro"

He acquired basic knowledge regarding the main aspects of Cybersecurity. Among the most relevant topics, there are:

  • Web Application Penetration Testing
  • Network Security
  • Code Audit
  • Cryptography

BSc in Computer Science

2016 - 2019
University of Bari "A. Moro"

He acquired the fundamental notions of Computer Science. Among these, there are:

  • Object-Oriented Programming
  • Data Structures and Algorithms
  • Computer Networks
  • Operating Systems
  • Databases
  • Software Engineering

Diploma Liceo Scientifico Opzione Scienze Applicate

2011 - 2016
Liceo Scientifico OSA "Levi-Montalcini"

He acquired the fundamental notions of Mathematics, Physics, and Computer Science.

Certifications

INE eWPT

2025 (WIP)
INE Security

INE Security’s eWPT provides essential skills and knowledge required to plan and perform a thorough and professional web application penetration test and how to effectively identify, exploit, and mitigate vulnerabilities in modern web applications.

INE eJPT

2024
INE Security

INE Security’s eJPT is for Penetration testers and validates that the individual has the knowledge, skills, and abilities required to fulfill a role as a penetration tester. This certification exam covers Assessment Methodologies, Host and Network Auditing, Host and Network Penetration Testing, and Web Application Penetration Testing.

Microsoft Certified - Azure Fundamentals (AZ900)

2022
Microsoft

Earners of the Azure Fundamentals certification have demonstrated foundational level knowledge of cloud services and how those services are provided with Microsoft Azure.

Fortify SCA & SSC Certified Professional

2022
Micro Focus

This certification provides participants with demonstrations and hands-on activities using a practical, solutions-based approach to identify and mitigate today’s most common business security risks to applications.

FT120 - Fortify SAST and DAST for Developers

2022
Micro Focus

Fortify SAST and DAST for Developers is a two day training that explores how the Fortify product suite Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) scans for security vulnerabilities.

Cyber Challenge.IT

2020
Cybersecurity National Lab

CyberChallenge.IT is a training programme for young talent aged 16 to 24, is Italy’s leading initiative to identify, attract, recruit and place the next generation of cybersecurity professionals.

Publications

Here is the list of the currently published research papers.

  • Supporting Secure Agile Development: the VIS-PRISE Tool
  • Maria Teresa Baldassarre, Vita Santa Barletta, Giovanni Dimauro, Domenico Gigante, Alessandro Pagano, Antonio Piccinno
    Proceedings of the 2022 International Conference on Advanced Visual Interfaces
  • Resolving Security Issues via Quality-Oriented Refactoring: A User Study
  • Domenico Gigante, Fabiano Pecorelli, Vita Santa Barletta, Andrea Janes, Valentina Lenarduzzi, Davide Taibi, Maria Teresa Baldassarre
    2023 ACM/IEEE International Conference on Technical Debt (TechDebt)
  • From GDPR to privacy design patterns: The MATERIALIST framework
  • Vita Barletta, Giuseppe Desolda, Domenico Gigante, Rosa Lanzilotti, Marco Saltarella
    Proceedings of the 19th International Conference on Security and Cryptography-SECRYPT
  • A Rapid Review of Responsible AI frameworks: How to guide the development of ethical AI
  • Vita Santa Barletta, Danilo Caivano, Domenico Gigante, Azzurra Ragone
    Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering (EASE 2023)
  • POLARIS: A framework to guide the development of Trustworthy AI systems
  • Maria Teresa Baldassarre, Domenico Gigante, Marcos Kalinowski, Azzurra Ragone
    Conference on AI Engineering Software Engineering for AI (CAIN 2024)
  • The Social Impact of Generative AI: An Analysis on ChatGPT
  • Maria Teresa Baldassarre, Danilo Caivano, Berenice Fernandez Nieto, Domenico Gigante, Azzurra Ragone
    GoodIT '23: ACM International Conference on Information Technology for Social Good
  • Fostering Human Rights in Responsible AI: A Systematic Review for Best Practices in Industry
  • Maria Teresa Baldassarre, Danilo Caivano, Berenice Fernandez Nieto, Domenico Gigante, Azzurra Ragone
    IEEE Transactions on Artificial Intelligence
  • Trustworthy AI in practice: an analysis of practitioners' needs and challenges
  • Maria Teresa Baldassarre, Domenico Gigante, Marcos Kalinowski, Azzurra Ragone, Sara Tibido'
    28th International Conference on Evaluation and Assessment in Software Engineering (EASE 2024)
  • Ensuring Child Rights in the Age of AI: A Multidimensional Analysis of Existing Frameworks
  • Danilo Caivano, Berenice Fernandez Nieto, Domenico Gigante, Azzurra Ragone, Sara Tibido'
    GoodIT '24: ACM International Conference on Information Technology for Social Good

    Skills & Proficiency

    Code Audit

    Web Application Penetration Testing

    Vulnerability Assessment and Penetration Testing

    Cloud Configuration

    CI/CD pipeline

    Databases

    Python Scripting

    Technical & Executive Report Writing

    PHP

    .NET

    Javascript & jQuery