Giacomo Zanatta
Software Engineer — Java, Distributed Systems & Security
Treviso, Italy · Italian citizen (EU), relocating to the Netherlands · Available from November 2026 · PhD defense expected Q1 2027
professional summary
Software Engineer and Technical Leader with 5 years of industrial software delivery and 3+ years of formal security research. At Alpenite, I integrated Adyen payment processing into production e-commerce platforms for Pinko and Monnalisa, and architected a Go middleware connecting e-commerce, ERP, OMS, and CRM systems. In two Applied Scientist roles at AWS (Amazon Web Services), I built automated taint analysis pipelines to detect vulnerabilities in large, safety-critical Java codebases. Primary developer of JLiSA, a Java static analyser ranked 3rd in the Java track at SV-COMP 2026 (International Competition on Software Verification).
experience
- Led a cross-organisational security project bridging two independent AWS security teams (Austin and New York), integrating a proprietary Java data-flow engine into Strata, AWS's open-source Lean-based verification platform, toward a unified vulnerability detection pipeline.
- Conducted the feasibility and scoping assessment, defined functional and non-functional requirements, and designed the pipeline and integration architecture.
- Owned the full output quality pipeline: pre-analysis path pruning to maximize signal, and post-analysis SMT solver exploitability reasoning to suppress non-actionable findings.
- Owned end-to-end delivery of a 12-week security analysis research project, defining scope through customer-driven requirements, managing week-to-week milestones, and aligning stakeholders on technical direction.
- Developed a precision classification methodology that quantified the trustworthiness of ~75% of vulnerability traces across regression and acceptance test suites, identifying 5 critical sources of over-approximation and producing per-finding confidence scores to separate exploitable findings from non-actionable noise.
- Designed and implemented taint analysis techniques to automatically detect security vulnerabilities in large, safety-critical Java codebases, ensuring privacy and compliance at scale.
- Performance led to a direct invitation for a second internship in an expanded cross-team role (AWS Austin, 2026).
- Promoted from junior developer to Technical Leader in 2 years, leading a team of 3–4 developers across 3 concurrent luxury e-commerce projects (Pinko, Monnalisa, Jil Sander) and owning delivery end-to-end.
- Integrated Adyen payment processing into Salesforce Commerce Cloud: server-side REST API flows and webhook notification handling, following the provider's PCI DSS integration guidance.
- Served as primary technical interface between clients, external vendors (ERP, CRM providers), and the project manager, translating business requirements into actionable technical specifications and managing delivery timelines.
- Architected and deployed a middleware integration layer (in Go) connecting e-commerce, ERP, OMS, and CRM systems, implementing JWT-based authentication and access control for secure inter-system communication, with a PostgreSQL persistence layer.
- Added Google Pay and Apple Pay integrations, and automated order export pipelines, ensuring data integrity and service continuity.
- Introduced structured documentation standards, systematic code review practices, and quality gates, reducing defect rates and onboarding time.
- Developed and integrated backend web services within Salesforce Commerce Cloud (SFRA/Node.js) for high-traffic luxury e-commerce platforms, ensuring fault tolerance and maintainability.
- Contributed to architecture design and production deployment of distributed systems.
education
- Primary developer of JLiSA, a Java static analyser ranked 3rd in the Java track at SV-COMP 2026 (International Competition on Software Verification), with CI pipeline and automated test suite.
- Developing PyLiSA, a Python static analyser written in Java, from grammar-level parsing to semantic analysis.
- Developing a real-time network security firewall for the ROS2 middleware: live traffic introspection, anomalous behaviour detection, compromised-node identification, and dynamic policy enforcement. Addresses OWASP A02:2025 by generating minimal, least-privilege communication policies.
- Research on automated security analysis and static architecture reconstruction of distributed microservices, enabling automatic detection of policy violations, sensitive data flows, and security misconfigurations.
- Visiting Researcher at INRIA Antique Lab, ENS Paris (Sep–Dec 2024).
- Teaching & mentoring: supported courses for up to 150 students.
- Core coursework: Security (system, network and web security, OWASP, hands-on labs with Metasploit, Nmap, and Wireshark), Cryptography (AES, RSA, Diffie-Hellman), Software Correctness & Reliability (data-flow analysis, abstract interpretation, vulnerability scanning), Formal Methods for System Verification.
- Thesis: LiSA and ROS — Static Analysis for Robotics.
skills
Programming
- Java
- Python
- Go
- SQL (PostgreSQL, MySQL)
- C/C++
- TypeScript
- Node.js
- Bash
- Lean
Security & Verification
- Static Analysis
- Taint Analysis
- Formal Methods
- Abstract Interpretation
- Policy Verification
- Network Security Monitoring
- OWASP
Frameworks & Tools
- Spring
- FastAPI
- Gin
- Docker
- Kubernetes
- CI/CD
- Git
- ROS2
- Linux (system administration, networking, containerisation)
Domains
- E-Commerce & Payments
- Cyber-Physical Systems
- Formal Verification
- ROS2 Robotics
- Microservices
- Cloud Security (AWS)
- Safety-Critical Software
- Access Control & Policy Enforcement
Standards & Compliance
- PCI DSS (payment integrations)
- SOC 2 / ISO 27001 (working knowledge)
- EU cybersecurity regulation: CRA, NIS2
- OWASP Top 10
- SBOM / VEX (working knowledge)
Emerging Technologies
- Large Language Models (LLMs)
- Agentic AI workflows
- AI-assisted software development tools (Claude Code, GitHub Copilot)
academic publications
- Automating ROS2 security policies extraction through static analysis — 2024 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS).
- Sound static analysis for microservices: utopia? A preliminary experience with LiSA — 2024 Proceedings of the 26th ACM International Workshop on Formal Techniques for Java-like Programs (FTfJP).
- Inference of access policies through static analysis — 2025 International Journal on Software Tools for Technology Transfer (STTT).
- JLiSA: The Java frontend of the library for static analysis (competition contribution) — 2026 International Conference on Tools and Algorithms for the Construction and Analysis of Systems (TACAS).
continuing education
- European Patent Office Innovation & IP course (75h, 2025).
- Summer Schools: Abstract Interpretation (Lipari 2024), Software Security (Marktoberdorf 2024).
languages
- English (fluent)
- Italian (native)