Portrait photograph of Liam Giannini, an OSCP-certified penetration tester from Ticino, Switzerland.

Liam Giannini

OSCP Penetration Tester · Full-Stack Developer · BSc Informatics Student

Zürich, Switzerland

Liam Giannini is an OSCP-certified security researcher and full-stack engineer whose work resists the disciplinary boundaries that ordinarily contain a career. To characterize him by any single vocation — penetration tester, product engineer, company founder — is to describe a facet and mistake it for the whole. What unifies these pursuits is a temperament rather than a subject: a persistent, almost adversarial refusal to accept that any system — computational or organizational — is sound merely because it is assumed to be.

His formation is instructive, and it began early. A self-taught tinkerer from his mid-teens — insatiably curious about how computer systems work and, more to the point, how they fail — Liam Giannini put that curiosity to constructive use from the start. As a teenager in Ticino, he uncovered security weaknesses across the systems of numerous local municipalities and disclosed each of them responsibly to the authorities concerned, explaining in every case how the flaw could be fixed. That was roughly a decade ago; the issues were remediated, and the episode set the pattern for everything since — the instinct to find the flaw, inseparable from the discipline to report it and help close it. The same consent-first ethic defines his professional practice today. He began his working life as a full-stack developer, acquiring an intimate, constructive command of systems before subjecting that command to the discipline of formal study. It is worth stating plainly what much of that mastery predates: his OSCP — earned through Offensive Security's notorious twenty-four-hour, hands-on-keyboard examination — and a top 1% all-time standing on Stack Overflow were both won the hard way, in the era before large language models existed to lean on. They are artifacts of unassisted skill, accumulated across nearly a decade of answering hard questions and breaking hard targets by hand.

In his primary discipline, offensive security, that skill is fully evident. Over roughly four years with Secure Network (BV TECH) in Milan and now through his own studio, Liam Giannini has delivered on the order of forty red-team and penetration-test engagements to major banks, multinational corporations, and Swiss public infrastructure — testing web, network, mobile, cloud, and Active Directory environments, leading small teams on complex assessments, and translating critical findings into executive risk. His work has been recognized with bug-bounty awards on Swiss federal infrastructure. Tools — Burp Suite, ZAP, Nmap, Metasploit, Nessus, Mimikatz, Volatility — are incidental; what is exceptional is the adversarial imagination that isolates, among thousands of unremarkable interactions, the single consequential flaw.

As co-founder of Webcracy SNC, the studio he launched in 2023, he owns security audits, full-stack product delivery across web and mobile apps, SaaS, ERP and CRM systems and even embedded firmware, and infrastructure end-to-end — a wholly custom, Swiss-hosted stack he architects and runs himself, from network and firewalls to servers, virtualization, and backups, distributed across multiple locations on the company's own private network — alongside client relationships and technical pre-sales. The studio ships products end to end, among them Lawkeeper, an AI legal-research assistant grounded in Swiss law; and its name predates the agency itself — it began in 2020 as Liam Giannini's from-scratch layer-1 blockchain for digital voting, where he built the chain and its consensus, not merely the smart contracts running on top. A substantial strand of his work is quietly academic: he supports researchers and students directly — building data-collection and analysis pipelines, custom research tooling, and the software behind master's theses at the University of Zurich's Department of Psychology, and maintaining Polytrick, the student-run academic-resource platform for ETH Zurich. Liam Giannini is himself completing a BSc in Informatics at ZHAW, with a focus on ICT, AI, and cybersecurity.

Highlights

Selected Security Research

Findings responsibly disclosed through official programs and coordinated disclosure; bug-bounty work verifiable on Intigriti. Technical details withheld.

Experience

Co-Founder · Webcracy SNC, LocarnoNov 2023 – Present
  • Co-founded a Swiss digital solutions company delivering cybersecurity, web and mobile apps, SaaS platforms, ERP and CRM systems, embedded firmware, hosting, AI, and blockchain solutions.
  • Lead security audits and penetration tests end-to-end: scoping, exploitation, reporting, remediation, executive readout.
  • Own and operate the company's entire infrastructure end-to-end — fully custom, Swiss-hosted, and distributed across multiple sites on a private network: networking, firewalls, servers, virtualization, and backups.
  • Build and deploy full-stack products on that self-hosted Linux stack.
  • Own client relationships, technical pre-sales, and delivery across multiple service lines.
Penetration Tester · Secure Network / BV TECH, MilanApr 2022 – Dec 2025
  • Delivered 40 red-team and penetration-test assessments for major banks and multinational corporations.
  • Tested web, network, mobile, cloud, and Active Directory environments; identified critical vulnerabilities.
  • Led small teams on complex engagements and translated technical findings into client risk and priorities.
  • Produced technical and executive reports; supported kick-offs, final readouts, and remediation discussions.
Web Developer · University of Zurich, Dept. of PsychologyNov 2024 – Present
  • Develop secure, responsive websites and custom research tools for master's studies.
  • Build data-collection and analysis workflows using Python, Next.js, and project-specific tooling.
Full-Stack Developer · Piramide Informatica Sagl, LosoneJan 2019 – Jan 2022
  • Built tailored frontend/backend systems, APIs, automations, chatbots, and home-automation solutions.
  • Managed Linux servers: setup, maintenance, optimization, hardening, monitoring, and self-hosted services.
  • Contributed to image-analysis algorithms and a blockchain/Web3-based digital voting system.

Education

BSc Informatics · ZHAW, ZürichSep 2024 – 2027 (expected)
  • Focus on ICT, AI, and cybersecurity.
Computer Science · Politecnico di Milano2020 – unfinished
  • Left the degree to pursue a job offer as a security engineer.
High School Diploma · Collegio Papio, Ascona2015 – 2020
  • Physics and mathematics focus. Award for best results in scientific subjects.

Skills

Offensive Security & Red Teaming

Penetration testingNetwork penetration testing Web application securityAPI testing Mobile / Android securityCloud security (AWS) Red teamingEthical hacking Active Directory exploitationPrivilege escalation Post-exploitationExploit development Buffer overflow exploitationReverse engineering Vulnerability assessmentSecurity audits Manual & automated testing

Security Tooling

Burp SuiteOWASP ZAPNmapMetasploit NessusSQLmapSSLscanMimikatzVolatility

Engineering & Web

PythonJavaScriptTypeScriptNode.js Next.jsReact.jsHTMLCSSBash Full-stack developmentFront-end developmentAPIs Scripting & automationDatabasesData analysis

Blockchain & Applied AI

Custom blockchain / consensusSmart contracts (Solidity) DApps / Web3FoundryRust RAG / LLM applications

Infrastructure

Linux administrationServer managementServer hardening Self-hosted servicesSovereign Swiss hostingMulti-site private network VirtualizationFirewallsBackupsMonitoring

Methods, Standards & Communication

OWASPCVEsCVSSInformation security Cyber-security riskCryptography fundamentals Technical documentationReport writing Executive summariesTeamworkMicrosoft 365

Languages

Italian — nativeEnglish — professionalGerman — conversational

Certifications & CTF

Research

Stack Exchange

Top 1% all-time on Stack Overflow — active across the network since 2015.

Profiles

Work & Projects

Press

Registries