Luigi Iacuaniello

Cybersecurity Software Engineer · Naples, Italy

I am a software engineer specializing in cybersecurity.
I write code, develop services and often analyze codebases for vulnerabilities and design flaws.

Skills

Languages
Go · Java · Spring Boot · Python · TypeScript · SQL
Security engineering
Threat modeling - STRIDE, Threagile · Secure code and architecture review · Secure SDLC design · OWASP ASVS · WSTG · MITRE ATT&CK mapping
Offensive
Web, API and mobile testing · Broken authorization and business logic · Burp Suite · SQLMap · Nuclei · Cloud attack-path analysis
Cloud and platform
AWS - IAM, policy evaluation · Kubernetes · Istio · mTLS · HashiCorp Vault · Docker · Helm
Identity
OAuth 2 · OIDC + PKCE · JWT · Keycloak · Service-to-service authorization
Supply chain
SBOM - SPDX · cosign · Sigstore · SLSA provenance · Dependency and container scanning
Data and messaging
PostgreSQL · Apache AGE · Kafka · NATS · GraphQL · REST

Projects

PerspectiveGraph - an attack-path engine, in the open

2026

Open source - my own work · Security tooling

An open-source engine that asks one question of every pull request: does this change open a path from the internet, through too much privilege, to something worth stealing? Each hop gets a probability instead of a severity label, and where the engine isn't sure, it says so rather than rounding up. I also built a red-team oracle that checks its conclusions against the live AWS policy-evaluation API - and it caught my own engine treating an IAM permission boundary as a grant, when a boundary only ever caps. That false positive is a regression test now.

  • Apache 2.0, public repository, CI running on every commit
  • Container images signed with cosign, with SBOM and SLSA build provenance
  • Graded in CI against four CloudGoat-shaped scenarios, including two that must produce no finding
  • Privilege hops validated against the live AWS policy-evaluation API
The Attack paths view of the public demo: routes ranked by priority on the left, and on the right the selected route from an internet-facing load balancer to an AdministratorAccess role - its exploit probability, then a kill chain listing each hop with its probability, the evidence that probability came from, and the mapped ATT&CK technique.
Routes ranked by what to fix first - and every hop with its probability, where that probability came from, and the mapped ATT&CK technique.

GoPostgreSQL + Apache AGETypeScriptKubernetesAWS IAMNATSGraphQL

Live demo ↗Source on GitHub ↗

About

I am an Italian software engineer based in Naples, with about eight years of experience in the industry - specifically within the banking and financial sectors. I continue to write code out of passion and a desire for professional growth, which is why I am working on PerspectiveGraph.

In my spare time, I enjoy listening to classical music, particularly 18th-century opera.

Based
Naples, Italy · CET / CEST
Languages
Italian, English, French, and Spanish
Work
Remote across Europe

Contact

Email is the reliable way to reach me - I'll reply within two working days.

luigi@a3thinker.it

Please don't send credentials, tokens or production data in a first email.