Application Security Engineer – Hybrid, Training & Growth
Posted Updated
HSPI S.p.A., part of TXT Group, is seeking an Application Security Engineer to join the Rome team in the Cinecittà area. The role focuses on vulnerability assessments, penetration testing, threat modeling, and secure code review across web apps, cloud platforms, and containerized environments.
The candidate will produce detailed reports, classify findings with CVSS v4.0 and MITRE ATT&CK, and verify remediation via retesting.
Perform vulnerability assessments and penetration tests on web apps, IT infra, cloud, and containers. Prepare technical reports and classify findings using CVSS, MITRE ATT&CK, and OWASP. Support threat modeling and risk assessment for application architectures. Conduct secure code reviews with SAST tools and manual analysis. Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field. Experience with vulnerability assessments, penetration testing, and secure code review is expected. Familiarity with cloud and container security (Kubernetes) is a plus. Hybrid work model Permanent contract under CCNL Commerc. Training opportunities