Application Security Engineer

TXT Group

Italia

On-site

EUR 26,500 - 31,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Permanent contract under CCNL Commerc.
Training opportunities

Job summary

HSPI S.p.A., part of TXT Group, is seeking an Application Security Engineer to join the Rome team in the Cinecittà area. The role focuses on vulnerability assessments, penetration testing, threat modeling, and secure code review across web apps, cloud platforms, and containerized environments.

The candidate will produce detailed reports, classify findings with CVSS v4.0 and MITRE ATT&CK, and verify remediation via retesting.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field.
  • Experience with vulnerability assessments, penetration testing, and secure code review is expected.
  • Familiarity with cloud and container security (Kubernetes) is a plus.

Responsibilities

  • Perform vulnerability assessments and penetration tests on web apps, IT infra, cloud, and containers.
  • Prepare technical reports and classify findings using CVSS, MITRE ATT&CK, and OWASP.
  • Support threat modeling and risk assessment for application architectures.
  • Conduct secure code reviews with SAST tools and manual analysis.

Skills

Vulnerability assessment
Penetration testing
Threat modeling
Secure code review
SAST tooling

Education

Bachelor's degree in CS/CE

Tools

Burp Suite
OWASP ZAP
Nessus
Kubernetes security tools
Prowler
Trivy
Kube-bench

Job description

HSPI S.p.A., part of TXT Group, is looking for a Application Security Engineer to join its team at the Rome office (Cinecittà area).

Key Responsibilities
  • Vulnerability Assessment & Penetration Testing Provide operational support in performing Vulnerability Assessments and Penetration Tests on web applications, IT infrastructures, cloud environments, and containerized platforms (Kubernetes/AKS).
  • Reporting & Compliance Support the preparation of detailed technical reports (Technical Deep Dive Reports), classify vulnerabilities according to internationally recognized frameworks (CVSS v4.0, MITRE ATT&CK, OWASP), and verify the effectiveness of implemented security controls through remediation retesting activities.
  • Threat Modeling Support the analysis of application architectures using methodologies such as STRIDE (Microsoft Threat Modeling Tool), identifying threats, assessing risks, and producing Threat Modeling and Risk Assessment documentation.
  • Secure Code Review Analyze source code using Static Application Security Testing (SAST) tools and manual code review techniques to identify logical vulnerabilities, programming flaws, and security weaknesses.
Required Technical Skills
  • Practical knowledge of the main categories of application vulnerabilities (OWASP, CWE).
  • Familiarity with leading security tools such as Burp Suite, OWASP ZAP, Nessus, Nmap, and container/cloud security auditing tools including Trivy, Kube-bench, and Prowler.
  • Basic programming and scripting skills (Python, Bash, Go, or knowledge of major web and object-oriented programming languages) to support secure code review activities.
  • Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field.
Preferred Qualifications
  • Previous experience, including academic or internship experience, with cloud architectures (Azure/AWS) and Docker/Kubernetes environments.
  • Active participation in cybersecurity training platforms such as Hack The Box, PortSwigger Web Security Academy, or TryHackMe, or involvement in Capture The Flag (CTF) competitions.
  • Entry-level cybersecurity certifications (e.g., eJPT, OSCP, GPEN) and/or foundational Cloud or Kubernetes certifications.
Why Join HSPI?
  • Tailored training and development plans, including internationally recognized certifications and continuous learning on industry best practices.
  • Opportunity to work alongside leading clients on strategic cybersecurity projects.
  • Early autonomy and responsibility from the very beginning.
  • Direct interaction with company management and end clients.
  • Hybrid working model.

The successful candidate will be offered a permanent employment contract under the Italian CCNL Commercio with a RAL ranging from €26.500 to €31.000, depending on experience.

This position is open to all qualified candidates regardless of gender, in accordance with Italian Legislative Decree 198/2006. HSPI is committed to equal opportunities and values diversity and inclusion in all its forms.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

TXT GROUP • Roma

Hybrid
EUR 27,000 - 31,000
Hybrid working model
Offensive Security Consultant
Offensive Security Consultant

TXT Group • Italy

On-site
EUR 26,500 - 31,000
Hybrid work mode
Application Security Engineer — Hybrid Role & Growth
Application Security Engineer — Hybrid Role & Growth

TXT GROUP • Roma

Hybrid
EUR 27,000 - 31,000
Hybrid working model
Application Security Engineer – Hybrid, Training & Growth
Application Security Engineer – Hybrid, Training & Growth

TXT Group • Italy

Hybrid
EUR 26,500 - 31,000
Hybrid work model
Permanent contract under CCNL Commerc.
Training opportunities
Offensive Security Engineer: Pen Testing & Code Review
Offensive Security Engineer: Pen Testing & Code Review

TXT Group • Italy

Hybrid
EUR 26,500 - 31,000
Hybrid work mode
Cybersecurity - Penetration Tester - Senior Associate - Roma [OTS]
Cybersecurity - Penetration Tester - Senior Associate - Roma [OTS]

PwC Italy • Roma

On-site
EUR 40,000 - 60,000
Formazione continua
Interazione con una rete globale di esperti
Recent graduates in Engineering - Economics- Computer Science
Recent graduates in Engineering - Economics- Computer Science

HSPI S.p.A. • Roma

On-site
EUR 7,600 - 10,000
Hybrid work mode
On-the-job training
Certified training programs
Penetration Tester
Penetration Tester

NEVERHACK Italy • Campania

On-site
EUR 35,000 - 38,000
Formazione continua
Ambiente di lavoro stimolante
Senior Consultant- Assistenza Tecnica
Senior Consultant- Assistenza Tecnica

HSPI S.p.A. • Roma

Hybrid
EUR 30,000 - 37,000
Training paths
Strategic projects
Autonomy
+2
Senior Web Application Penetration Tester
Senior Web Application Penetration Tester

7Layers • Italy

On-site
EUR 68,000 - 90,000
Smart Working
Ticket restaurant
Formazione continua
+3