Skip to main content

Offensive Security & Attack Surface Specialist

4 × 9hr days€50kHybrid · Milano or Torino

.

Overview

You will join the Offensive Security & Attack Surface team and be responsible for evolving the traditional Offensive Security model toward an AI-augmented and industrialized paradigm, increasing the scale, speed, and coverage of activities. You will combine deep offensive expertise with the ability to design, configure, and govern agentic workflows to automate and make typically manual tasks continuous, while facilitating and managing internal training and supporting the evolution of the Red Team/Pen Test team.

What your activities will be

  • Conduct advanced Red Team and Penetration Testing activities
  • Integrate frontier LLMs to support reconnaissance, social engineering, and vulnerability discovery
  • Configure and use AI agents to increase productivity and the depth of offensive activities
  • Design workflows for the continuous repetition of testing activities
  • Build continuous offensive validation pipelines
  • Develop toolchains and harnesses to orchestrate LLMs and offensive security tools
  • Collaborate with the SOC and other functions to validate attack scenarios
  • Act as an internal trainer
  • Document methodologies and contribute to the company knowledge base

Who we are looking for

If you have the following characteristics, we are waiting for you:

  • At least 5 years of experience in Red Teaming and Penetration Testing
  • Advanced knowledge of attack techniques and Threat Modeling (MITRE ATT&CK)
  • Experience with LLMs, AI agents, and prompt engineering
  • Scripting skills (e.g., Python)
  • Experience in building automated pipelines
  • Ability to industrialize offensive activities
  • Strong communication and training skills
  • Excellent knowledge of the English language

What we offer

  • Gross annual salary starting from 50.000 €

  • The Group provides a variable remuneration component as regulated by the Remuneration Policies available on the Group website

  • Complementary elements regulated by the National Collective Labor Agreement for the Credit Sector and second-level company agreements

  • Professional development initiatives to support the growth of our people

  • Extensive training offer through the Corporate Academy dedicated to the continuous development of professional, managerial, and transversal skills at all levels

  • Possibility to join flexible work arrangements and the 4x9 short week

  • Modern and integrated corporate welfare system ( link)

  • Health coverage and supplementary pension starting from the date of hiring

  • Advantages on the Group's banking products and services

Who we are

We are leaders in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.

People are at the center; we take care of them by committing to creating an inclusive culture within the Group where everyone feels like a protagonist and valued.

The Chief Security Officer Governance Area oversees the physical security, cybersecurity, and operational continuity of the Group in an integrated manner, leveraging specialized skills and advanced technological solutions with the goal of ensuring high international security standards.

The Area includes the Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management structures, ensuring a coordinated and transversal approach to protecting the Group.

Join our international reality. The future is not waited for, it is chosen!

#sharingfuture

We guarantee an inclusive and equal opportunity environment. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with Legislative Decrees 198/2006, 215/03, and 216/03.

For the evaluation of applications, the data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to read the dedicated Privacy Policy.