Penetration Tester

24 ore fa

roma, Italia Particle Measuring Systems Tempo pieno
Overview

In this Penetration Tester role, you verify software security through vulnerability assessments, penetration testing, threat modeling, and SAST/DAST analysis. You document findings and help ensure compliance with cybersecurity requirements. You will design testing plans, identify defects, and report results to support secure software delivery. Join a mission-driven team delivering advanced monitoring tech to major industries, with a strong emphasis on innovation and accountability.

Retribuzione / Benefits
  • competitive salary package (40,000–50,000 gross annual)
  • permanent contract
  • range of benefits supporting well-being
  • inclusive work environment
Responsabilità
  • Perform vulnerability assessments and verify security risks in software
  • Conduct manual and automated penetration testing
  • Carry out threat modeling to identify threats and mitigation strategies
  • Analyze SAST/DAST findings with developers and security teams
  • Validate vulnerabilities and prepare security reports for compliance
  • Plan and implement comprehensive testing strategies for software security
  • Identify and document malfunctions to facilitate resolution
  • Execute tests (manual and automated) and prepare detailed test reports
Requisiti fondamentali
  • Experience identifying, validating, and documenting software vulnerabilities and security risks
  • Ability to perform security assessments using manual methods and standard tools
  • Experience with SAST/DAST across the SDLC
  • Knowledge of CVSS and risk prioritization
  • Understanding of security integration within Agile, DevSecOps and CI/CD environments
  • Ability to produce clear technical security reports with remediation guidance
  • Penetration testing (manual and tool-based)
  • SAST/DAST
  • Vulnerability risk assessment using CVSS
  • Secure development lifecycle in Agile/DevSecOps/CI/CD
  • Security reporting with remediation recommendations
  • Public security advisories, CVE databases, and vulnerability disclosure processes (nice to have)