Penetration Tester

2 giorni fa

Milano, Lombardia, Italia Sky Italia Srl Tempo pieno 36.000 € - 44.000 € Contratto

Sky is the tech media company that makes entertainment and connectivity a personal, simple, and seamless experience.

Our mottois We Believe in Better: we believe people deserve the best, and every day we innovate to create value and make our customers’ lives easier.

We are part of Sky Group and the Comcast family, operating within an international environment focused on continuous innovation and powered by world-class technology that enables us to reach millions of people every day.

With an IP-first approach, we design cutting-edge technology platforms such as Sky Stream, Sky Q, Sky Glass, and NOW, bringing together premium content, trusted and always-on news coverage, and major sporting events within a simple and intuitive ecosystem.

We connect with audiences across the entire country through our free-to-air channels – TV8, Cielo, and Sky TG24 – and go beyond entertainment with Sky Wifi and Sky Mobile, delivering ultra-fast connectivity both at home and on the go.

This is how we bring the joy of a better experience, guided by our values:

  • Creative. We are ambitious and innovative, embracing new technologies and leveraging insights to stay ahead of the curve, continuously raising the bar for our customers.
  • Welcoming. We are inclusive, collaborative, and respectful, fostering a strong sense of belonging.
  • Simplifying. We focus on what truly matters, set clear priorities, bring clarity, and remove complexity.
  • Do the Right Thing. We build a culture founded on clarity, fairness, and trust through transparent processes and decisions that people can rely on.

As a Penetration Tester, you will be responsible for identifying, assessing, and validating security vulnerabilities in Sky Italy applications, systems, networks, and cloud environments. You will also play an active role in supporting the remediation process, working alongside relevant teams to ensure vulnerabilities are properly understood, prioritised, and fixed. This role requires solid technical expertise, strong analytical thinking, and the ability to collaborate effectively with both technical and non-technical stakeholders within region and at Group level, translating complex security findings into clear, actionable insights for audiences at different levels of the organisation.

What you’ll do:

  • Plan, prepare and execute penetration testing activities on Sky Italy applications, systems, networks, and cloud environments.
  • Identify, verify, and validate vulnerabilities using both manual techniques and automated tools.
  • Simulate real-world attack scenarios to assess the effectiveness of existing security controls.
  • Document findings clearly, including technical details, potential impact, and risk severity.
  • Produce detailed reports and present results to both technical and non-technical stakeholders.
  • Support the remediation process to ensure vulnerabilities are properly understood, prioritised, and fixed.
  • Proactively stay up to date with emerging threats, vulnerabilities, and attack techniques.
  • Contribute to the continuous improvement of internal security testing methodologies and best practices.
  • Support security incident management.
  • Support application security management.
  • Work closely with Group in defining offensive strategy to be implemented locally in the region.

What we’re looking for:

  • Master’s degree in Computer Science or Computer Engineering, or equivalent experience.
  • Proven experience as a Penetration Tester and/or Red Teamer in complex environments.
  • Solid understanding of common vulnerabilities and attack techniques.
  • Hands‑on experience with standard penetration testing tools (e.g. Nmap, Burp Suite, Metasploit, Kali Linux).
  • Experience with Active Directory configuration review.
  • Solid knowledge of networking, operating systems, web/cloud architectures, and security fundamentals.
  • Strong analytical and problem‑solving skills, with a methodical approach to identifying and validating vulnerabilities.
  • English: B2 level or above, both written and spoken.
  • Proactivity and a strong problem‑solving mindset.
  • Excellent communication skills for interacting with both technical and non‑technical stakeholders.

Preferred Qualifications:

  • Cyber security certifications (e.g. OSCP, OSWE, or equivalent).
  • Familiarity with DevSecOps practices and integrating security into CI/CD pipelines.
  • Contributions to the security community (e.g. CTF participation, blog posts, open-source tools, conference talks).

What we offer:

Under the Private Radio and Television Industry Collective Labour Agreement