Leadership 01

Vincenzo Iozzo

Vincenzo Iozzo Co-founder & CEO, SlashID

// About

Vincenzo Iozzo is the co-founder and CEO of SlashID, an identity security platform that detects and prevents identity-based attacks across human, non-human and AI identities. He writes about identity security, AI and vulnerability research on the SlashID blog and on his personal site, vincenzoiozzo.com.

Before SlashID he founded IperLane, a mobile security company acquired by CrowdStrike. As Senior Director at CrowdStrike he shipped Falcon for Mobile, sourced and executed the acquisition of Preempt Security (now Falcon Identity Protection) and managed the Falcon Fund.

// Research background

His earlier career was in offensive security research. He is a two-time Pwn2Own winner (iPhone and BlackBerry), co-author of the iOS Hacker’s Handbook (Wiley), a Black Hat speaker and former Review Board member, and a former Associate Researcher at the MIT Media Lab. He holds a BS in Computer Engineering from Politecnico di Milano. His academic work is indexed on Google Scholar.

Career 02

Background & roles.

SlashID

Co-founder & CEO

Leads SlashID, an identity security platform that detects and prevents identity-based attacks by ingesting logs from identity providers, cloud platforms and SaaS applications.

CrowdStrike

Senior Director

Shipped Falcon for Mobile (formerly IperLane), sourced and executed the acquisition of Preempt Security (now Falcon Identity Protection), and managed the Falcon Fund cybersecurity venture fund with Accel.

IperLane

Founder & CEO

Founded a mobile threat defense company, acquired by CrowdStrike.

Trail of Bits

Director of Security Engineering

Led security research and engineering at the security research and consulting firm.

MIT Media Lab

Associate Researcher

Research at the intersection of technology and society.

Independent, Zynamics, Secure Network

Security Researcher

Offensive security research on Mac OS X, iOS and mobile platforms, published at Black Hat, CanSecWest, ACM CCS and Microsoft BlueHat.

Writing 05

Articles on the SlashID blog.

31 articles
29 Sep, 2026

Test-driving Jev on a security task: identity resolution

→
1 Jun, 2026

Analysis of the 2026 Stryker Breach: Weaponizing Cloud Endpoint Management

→
20 Apr, 2026

Vercel April 2026 Security Incident: How a Compromised OAuth App Led to a Major Breach

→
30 Mar, 2026

Deepfake Impersonation Attacks (Part 2): Defending with SlashID Mutual TOTP

→
16 Mar, 2026

Deepfake Impersonation Attacks (Part 1): Anatomy of Modern Deepfakes

→
5 May, 2025

Achieving Least Privilege: Unused Entitlement Removal

→
8 Jan, 2025

Protecting against malicious OAuth 2.0 applications

→
30 Sep, 2024

Identity Security: The problem(s) with federation

→
16 Sep, 2024

Non-Human Identities Security: Breaking down the problem

→
22 Aug, 2024

A deep dive in the AWS credential leaks reported by Palo Alto Networks

→
15 Jul, 2024

Protecting against Snowflake breaches

→
10 Jun, 2024

Credential Tokenization: Protecting third-party API credentials

→
3 Jun, 2024

Secure API and M2M Access with OAuth2 Client Credentials and SlashID's sidecar

→
14 May, 2024

Introducing Organization Attributes

→
24 Apr, 2024

Introducing Anonymous Users: Balancing First-Party Data Collection and User Experience

→
2 Apr, 2024

SlashID SDK for PHP and Laravel authentication

→
6 Mar, 2024

Adding custom claims to identity tokens

→
19 Feb, 2024

SlashID: Building a globally distributed Identity Platform

→
31 Jan, 2024

Passkeys Adoption Trends: Survey from Large Deployments

→
8 Jan, 2024

Single Sign-On implementation: Security Issues and Best Practices

→
10 Oct, 2023

Context-aware authentication: fight identity fraud and qualify your users

→
28 Sep, 2023

Backend Authentication and Authorization Patterns: Benefits and Pitfalls of Each

→
21 Sep, 2023

JWT Implementation Pitfalls, Security Threats, and Our Approach to Mitigate Them

→
18 Sep, 2023

No-code anti-phishing protection of internal apps with Passkeys

→
14 Sep, 2023

Firewalling OpenAI APIs: Data loss prevention and identity access control

→
5 Sep, 2023

Protecting Exposed APIs: Avoid Data Leaks with SlashID Gate and OPA

→
16 Jan, 2023

Fetching Google Groups with SlashID SSO

→
18 Dec, 2022

In-browser HSM-backed Encryption with Tink and Wasm

→
23 Sep, 2022

The good, the bad and the ugly of Apple Passkeys

→
14 Sep, 2022

The Security and Regulatory Compliance Benefits of WebAuthn

→
12 Sep, 2022

Phishing Attacks – WebAuthn to the rescue

→

Explore the blog →