.
Overview
Within the Cybersecurity Prevention & Response structure, you will work in a team of highly qualified professionals in an international, dynamic, and continuously expanding environment. Your main task will be to conduct Penetration Testing activities, emulating attacks aimed at identifying known and unknown logical and application vulnerabilities. Vulnerabilities will be identified in corporate assets, software, processes, and procedures in order to ensure the complete mitigation of emerging risks and the definition of corrective action plans to be undertaken.
What your activities will be
- Perform Penetration Testing activities in an international context
- Perform post-application patching re-test activities
- Keep track of actions and procedures conducted during Penetration Testing activities in order to produce clear and complete reports
- Define the necessary remediation actions following the results of the activities and provide recommendations aimed at mitigating/remediating the identified vulnerabilities
- Maintain confidentiality during activities, following ethical standards and legal regulations
- Use advanced tools and methodologies to perform activities in compliance with industry standards and best practices
- Collaborate with development and security teams to implement mitigation solutions and ensure the resolution of identified vulnerabilities
- Contribute to the continuous improvement of security processes by identifying and proposing new methodologies
Who we are looking for
If you have the following characteristics, we are waiting for you:
- 3-5 years of experience in Penetration Testing
- STEM degree (Computer Engineering, Computer Science, Cyber Security) and/or technical diploma accompanied by significant experience in the sector
- Good knowledge of the English language (written and oral)
- In-depth and up-to-date knowledge of the current cyber threat landscape, specifically in the Web domain, used by attackers
- Knowledge of programming, scripting, and markup languages, including JavaScript, SQL, PHP, ASP, Python, Java, Bash, etc.
- Knowledge of evasion methods for security systems such as WAF and PROXY
- Knowledge of specific bypass methods divided by application vulnerability classes
- Experience in Penetration Testing on web applications, mobile, API, etc.
- Knowledge of the main frameworks and methodologies in security testing (e.g., CVSS, PTES, MITRE ATT&CK Framework)
- Basic knowledge of cyber regulations (e.g., GDPR, National Cyber Security Perimeter)
- Knowledge of the key principles of information security (availability, integrity, and confidentiality)
- Knowledge of cyber risk management
The following knowledge is considered a preferential qualification:
- OSCP, OSWE, eWPT, GWAPT, CPENT certifications
- Proven publication of CVEs
What we offer you
-
Gross annual salary starting from €45.000
-
The Group provides for a variable component of remuneration as regulated by the Remuneration Policies available on the Group's website
-
Complementary elements regulated by the National Collective Labor Agreement for the Credit Sector and second-level company agreements
-
Professional development initiatives to support the growth of our people
-
Wide range of training offered through the Corporate Academy dedicated to the continuous development of professional, managerial, and transversal skills at all levels
-
Possibility to join flexible work and the 4x9 short week
-
Modern and integrated corporate welfare system ( link)
-
Health coverage and supplementary pension starting from hiring
-
Advantages on the Group's banking products and services
About us
We are leaders in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.
People are at the center; we take care of them by committing to creating an inclusive culture within the Group where everyone feels like a protagonist and valued.
The Chief Security Officer Governance Area oversees the physical security, cybersecurity, and operational continuity of the Group in an integrated way, leveraging specialized skills and advanced technological solutions, with the goal of ensuring high security standards at an international level.
The Area includes the Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management structures, ensuring a coordinated and transversal approach to the protection of the Group.
Join our international reality. The future is not waited for, it is chosen!
#sharingfuture
We guarantee an inclusive and equal opportunity environment. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with Legislative Decrees 198/2006, 215/03, and 216/03.
For the evaluation of applications, the data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to read the dedicated Privacy Notice.
