Application Security Engineer

24 ore fa

roma, Italia TXT e solutions Tempo pieno
Overview

In this role you will strengthen the security of web apps, cloud environments, and containerized platforms in a client-facing setting. You will work within cross-functional teams to perform vulnerability assessments, penetration testing, and threat modeling, shaping risk-informed security improvements. You’ll contribute to secure development through code reviews and security testing, and you’ll communicate findings through technical reports. The position offers growth through hands-on experiences, certifications, and direct client interaction in a hybrid work setup.

Retribuzione / Benefits
  • Hybrid working model
  • training and certifications
  • permanent contract
  • career development opportunities
  • interaction with management and clients
Responsabilità
  • Perform vulnerability assessments and penetration testing on web applications, IT infrastructures, cloud environments, and Kubernetes/AKS containers
  • Support reporting and compliance via Technical Deep Dive Reports and vulnerability classification using CVSS v4.0, MITRE ATT&CK, and OWASP; verify remediation effectiveness
  • Contribute to threat modeling using STRIDE and produce risk assessment documentation
  • Analyze source code with SAST tools and manual review to identify defects and security weaknesses
Requisiti fondamentali
  • Practical knowledge of OWASP and CWE vulnerability categories
  • Familiarity with Burp Suite, OWASP ZAP, Nessus, Nmap; Trivy, Kube-bench, Prowler for container/cloud security auditing
  • Basic programming/scripting skills (Python, Bash, Go) or knowledge of major web/object-oriented languages
  • Bachelor in Computer Science
  • Master in Computer Science or Computer Engineering is acceptable as alternative
  • Burp Suite
  • OWASP ZAP
  • Nessus
  • Nmap
  • Trivy
  • Kube-bench