Application Security Engineer

TXT Group

Italia

In loco

EUR 26.500 - 31.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Vantaggi offerti da questo lavoro

Hybrid work model
Permanent contract under CCNL Commerc.
Training opportunities

Descrizione del lavoro

HSPI S.p.A., part of TXT Group, is seeking an Application Security Engineer to join the Rome team in the Cinecittà area. The role focuses on vulnerability assessments, penetration testing, threat modeling, and secure code review across web apps, cloud platforms, and containerized environments.

The candidate will produce detailed reports, classify findings with CVSS v4.0 and MITRE ATT&CK, and verify remediation via retesting.

Competenze

  • Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field.
  • Experience with vulnerability assessments, penetration testing, and secure code review is expected.
  • Familiarity with cloud and container security (Kubernetes) is a plus.

Mansioni

  • Perform vulnerability assessments and penetration tests on web apps, IT infra, cloud, and containers.
  • Prepare technical reports and classify findings using CVSS, MITRE ATT&CK, and OWASP.
  • Support threat modeling and risk assessment for application architectures.
  • Conduct secure code reviews with SAST tools and manual analysis.

Conoscenze

Vulnerability assessment
Penetration testing
Threat modeling
Secure code review
SAST tooling

Formazione

Bachelor's degree in CS/CE

Strumenti

Burp Suite
OWASP ZAP
Nessus
Kubernetes security tools
Prowler
Trivy
Kube-bench

Descrizione del lavoro

HSPI S.p.A., part of TXT Group, is looking for a Application Security Engineer to join its team at the Rome office (Cinecittà area).

Key Responsibilities
  • Vulnerability Assessment & Penetration Testing Provide operational support in performing Vulnerability Assessments and Penetration Tests on web applications, IT infrastructures, cloud environments, and containerized platforms (Kubernetes/AKS).
  • Reporting & Compliance Support the preparation of detailed technical reports (Technical Deep Dive Reports), classify vulnerabilities according to internationally recognized frameworks (CVSS v4.0, MITRE ATT&CK, OWASP), and verify the effectiveness of implemented security controls through remediation retesting activities.
  • Threat Modeling Support the analysis of application architectures using methodologies such as STRIDE (Microsoft Threat Modeling Tool), identifying threats, assessing risks, and producing Threat Modeling and Risk Assessment documentation.
  • Secure Code Review Analyze source code using Static Application Security Testing (SAST) tools and manual code review techniques to identify logical vulnerabilities, programming flaws, and security weaknesses.
Required Technical Skills
  • Practical knowledge of the main categories of application vulnerabilities (OWASP, CWE).
  • Familiarity with leading security tools such as Burp Suite, OWASP ZAP, Nessus, Nmap, and container/cloud security auditing tools including Trivy, Kube-bench, and Prowler.
  • Basic programming and scripting skills (Python, Bash, Go, or knowledge of major web and object-oriented programming languages) to support secure code review activities.
  • Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field.
Preferred Qualifications
  • Previous experience, including academic or internship experience, with cloud architectures (Azure/AWS) and Docker/Kubernetes environments.
  • Active participation in cybersecurity training platforms such as Hack The Box, PortSwigger Web Security Academy, or TryHackMe, or involvement in Capture The Flag (CTF) competitions.
  • Entry-level cybersecurity certifications (e.g., eJPT, OSCP, GPEN) and/or foundational Cloud or Kubernetes certifications.
Why Join HSPI?
  • Tailored training and development plans, including internationally recognized certifications and continuous learning on industry best practices.
  • Opportunity to work alongside leading clients on strategic cybersecurity projects.
  • Early autonomy and responsibility from the very beginning.
  • Direct interaction with company management and end clients.
  • Hybrid working model.

The successful candidate will be offered a permanent employment contract under the Italian CCNL Commercio with a RAL ranging from €26.500 to €31.000, depending on experience.

This position is open to all qualified candidates regardless of gender, in accordance with Italian Legislative Decree 198/2006. HSPI is committed to equal opportunities and values diversity and inclusion in all its forms.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Application Security Engineer
Application Security Engineer

TXT GROUP • Roma

Ibrido
EUR 26.000 - 31.000
Hybrid working model
Offensive Security Consultant
Offensive Security Consultant

TXT Group • Italia

Ibrido
EUR 26.000 - 31.000
Hybrid work mode
Application Security Engineer – Hybrid, Training & Growth
Application Security Engineer – Hybrid, Training & Growth

TXT Group • Italia

Ibrido
EUR 26.000 - 31.000
Hybrid work model
Permanent contract under CCNL Commerc.
Training opportunities
Hybrid Security Engineer – VAPT & Secure Code Review (Rome)
Hybrid Security Engineer – VAPT & Secure Code Review (Rome)

TXT GROUP • Roma

Ibrido
EUR 26.000 - 31.000
Hybrid working model
Offensive Security Engineer: Pen Testing & Code Review
Offensive Security Engineer: Pen Testing & Code Review

TXT Group • Italia

Ibrido
EUR 26.000 - 31.000
Hybrid work mode
Junior IT Project Manager
Junior IT Project Manager

HSPI S.p.A. • Bologna

Ibrido
EUR 25.000 - 29.000
Hybrid working model
Cybersecurity - Penetration Tester - Senior Associate - Roma [OTS]
Cybersecurity - Penetration Tester - Senior Associate - Roma [OTS]

PwC Italy • Roma

In loco
EUR 40.000 - 60.000
Formazione continua
Interazione con una rete globale di esperti
Project Manager - IT Governance & Digital Transformation
Project Manager - IT Governance & Digital Transformation

TXT GROUP • Roma

Ibrido
EUR 39.000 - 47.000
Hybrid working model
Expert Penetration Tester
Expert Penetration Tester

Intesa Sanpaolo Group • Napoli

In loco
EUR 40.000 - 60.000
Senior Web Application Penetration Tester
Senior Web Application Penetration Tester

7Layers • Italia

Ibrido
EUR 68.000 - 90.000
Smart Working
Ticket restaurant
Formazione continua
+3