Cyber security specialist · Rome, IT

Davide
Di Matteo.

Protecting critical infrastructure.
Investigating how systems break.

Vulnerability management, penetration testing and independent security research. Currently at Aeroporti di Roma.

Latest researchFIELD NOTES / 001
Coordinated disclosure

CVE-2026-20516

A privileged service.
An untrusted request.

MediaTek · Android TV
Security in practice. Curiosity by default.Scroll to explore

From assurance
to critical infrastructure.

Aeroporti di RomaLeonardoSipal
1credited
CVE

01 / Independent research

Follow the evidence.

Original research, reproducible findings
and a clearly defined scope.

02 / Professional experience

Security, in the real world.

Download my CV
Mar 2026 — Present Current

Aeroporti di Roma

Cyber Security Specialist

  • Coordinate a dedicated team across the vulnerability management lifecycle for airport systems.
  • Manage VAPT activities within the Italian National Cybersecurity Perimeter (PSNC), from vendor engagement to remediation tracking and retesting.
  • Support incident response with the CSOC and collaborate with Cyber Threat Intelligence teams.
Vulnerability managementPSNCIncident response
Nov 2024 — Feb 2026

Leonardo

Cyber Security Assurance & Red Team

  • Performed vulnerability assessments and penetration tests on INFOSEC systems and critical applications.
  • Supported Common Criteria certification through technical documentation, remediation plans and collaboration with the Security Evaluation Lab.
VAPTCommon CriteriaSecurity evaluation
Dec 2022 — Nov 2024

Sipal

Cybersecurity Analyst · Ce.Va. Operator

  • Analyzed security requirements and tested products against Common Criteria requirements.
  • Used SAST, DAST and vulnerability scanners, working with developers on remediation and evaluation evidence.
SAST / DASTPenetration testingProduct security

03 / Selected projects

Built to understand.

Research and academic work exploring
how systems behave, and how to secure them.

Bachelor's thesis

Linux malware
evasion research

Seven Linux antivirus products, three evasion techniques and a documented comparison of how representation changes detection.

CPythonMalware analysis
Read the full case study ↗
Explore the project

The question

How does detection change when known shellcode is encoded, packaged or executed inside a process?

My contribution

Compared seven Linux antivirus products using C and Python test programs. Documented shellcode execution, process injection and self-injection in an experimental thesis completed in October 2022.

The result

All seven products removed the unencoded baseline. Outcomes changed with encoding and packaging; the full case study reproduces the historical tables and explains their limits.

Academic project

Secure e-commerce
platform

A full-stack storefront with security controls built into authentication, inputs and data access.

PHPMySQLApplication security
Explore the project

The challenge

Build a functioning e-commerce portal while accounting for common application vulnerabilities.

My contribution

Implemented authentication, password hashing, session management and order processing. Used prepared statements, input validation and output sanitization for SQL injection and XSS prevention.

Project output

A full-stack PHP and MySQL web application developed as an academic project.

Academic project

Music platform
database design

Modeling a music streaming service across relational and document-based databases.

MySQLMongoDBData modeling
Explore the project

The challenge

Design the data layer for a SoundCloud-style platform with users, playlists and music metadata.

My contribution

Designed the entity-relationship model, implemented relational data in MySQL and unstructured data in MongoDB, and worked on query and index optimization.

Project output

An ER schema and relational / NoSQL database implementations developed for a database management course.

04 / Foundations

A technical foundation.

Certified Ethical Hacker

EC-Council

Earned · Nov 2025

CompTIA Security+

CompTIA

Earned · Oct 2017

Computer Science

University of Rome “Tor Vergata”

Bachelor's degree · 2016–2022

Tools I work with

Nessus / Burp Suite / Nmap / Wireshark / C / Python / Bash / Linux

05 / Always learning

Off duty. In the lab.

Hack The Box profile

@Dingooo / Hands-on practice across Linux and Windows targets, security challenges and defensive investigations.

Loading latest activity…

Current rank
User owns
System owns
Global rank

Rooted machines

Recent Linux & Windows targets

Loading machine activity…

Challenges & Sherlocks

Offensive skills. Defensive thinking.

Loading challenge activity…

Progress over time

The practice log

Loading recorded snapshots…

A daily record of profile statistics.

Start a conversation

Good security starts
with good questions.

Research, technical conversations or professional opportunities.

davidedimatteo97@gmail.com
Based in

Rome, Italy
Italian · English

Connect on LinkedIn ↗Download CV ↓