Skip to main content
100 years and 84 days since the five-day weekRead the story

Penetration Tester

4 × 9hr days100% payHybrid · Napoli, Italy

Overview

Within the Cybersecurity Prevention & Response structure, you will work in a team of highly qualified professionals in an international, dynamic, and continuously expanding environment. Your main task will be to conduct Penetration Testing activities, simulating attacks aimed at identifying logical and application vulnerabilities, both known and unknown. Vulnerabilities will be identified in company assets, software, processes, and procedures in order to ensure complete mitigation of identified risks and the definition of corrective action plans to be undertaken.

What will your activities be

  • Perform Penetration Testing activities in an international context
  • Perform post-patching re-testing activities
  • Keep track of actions and procedures conducted during Penetration Testing activities in order to produce clear and complete reports
  • Define remedial actions following the results of activities and provide recommendations aimed at mitigating/resolving identified vulnerabilities
  • Maintain confidentiality during activities, following ethical standards and legal regulations
  • Use advanced tools and methodologies to carry out activities in compliance with industry standards and best practices
  • Collaborate with development and security teams to implement mitigation solutions and ensure resolution of identified vulnerabilities
  • Contribute to the continuous improvement of security processes by identifying and proposing new methodologies

Who we are looking for

If you have the following characteristics, we are waiting for you:

  • 3-5 years of experience in Penetration Testing
  • STEM degree (Computer Engineering, Computer Science, Cyber Security) and/or technical diploma accompanied by significant experience in the sector
  • Good knowledge of the English language (written and oral)
  • In-depth and up-to-date knowledge of the current cyber threat landscape, specifically in the Web domain, used by attackers
  • Knowledge of programming, scripting, and markup languages, including JavaScript, SQL, PHP, ASP, Python, Java, Bash, etc.
  • Knowledge of security system evasion methods such as WAF and PROXY
  • Knowledge of specific bypass methods divided by classes of application vulnerabilities
  • Experience in Penetration Testing on web applications, mobile, APIs, etc.
  • Knowledge of the main frameworks and methodologies in security testing (e.g. CVSS, PTES, MITRE ATT&CK Framework)
  • Basic knowledge of cyber regulations (e.g. GDPR, National Security Perimeter)
  • Knowledge of key principles of information security (availability, integrity, and confidentiality)
  • Knowledge of cyber risk management

The following knowledge represents a preferential qualification:

  • OSCP, OSWE, eWPT, GWAPT, CPENT certifications
  • Proven CVE publication

What we offer you

  • Gross annual salary starting from €45.000
  • The Group provides a variable component of remuneration as regulated by the Remuneration Policies available on the Group website
  • Complementary elements governed by the National Collective Labor Agreement for Credit and second-level company agreements
  • Professional development initiatives to support the growth of our people
  • Extensive training offering through the Corporate Academy dedicated to continuous development of professional, managerial, and transversal skills at all levels
  • Possibility to participate in flexible work and a 4x9 short week
  • Modern and integrated company welfare system (link)
  • Health coverage and supplementary pension from the date of hire
  • Advantages on products and services of the Group's banks

Who we are

We are a leader in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.

People are at the center, we take care of them by committing to creating an inclusive culture within the Group in which everyone feels like a protagonist and valued.

The Chief Security Officer Governance Area oversees in an integrated manner the physical security, information security, and operational continuity of the Group, leveraging specialized expertise and advanced technological solutions, with the objective of ensuring high security standards at an international level.

The Area includes the structures of Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management, ensuring a coordinated and cross-functional approach to protecting the Group.

Join our international reality. The future doesn't wait, you choose it!

#sharingfuture

We guarantee an inclusive environment and equal opportunities. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with D.lgs. 198/2006, 215/03, and 216/03.

For the evaluation of applications, data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to review the dedicated Privacy Notice.