25 days ago
Milan, ItalyEntry Level
Responsibilities
- Perform penetration testing on iOS, Android, and web applications using tools such as Frida.
- Review source code for logic flaws, collaborate on secure design patterns, and assist with cloud infrastructure reviews.
- Develop scripts, proof-of-concept exploits, and tooling to automate testing and parse results.
- Test monitoring capabilities, participate in attack simulations, and help improve detection strategies.
- Write technical reports and document remediation steps for development teams.
Requirements
- Knowledge of information security fundamentals, networking, web application architecture, and vulnerabilities such as SQL injection, XSS, IDOR, and race conditions.
- 0–2 years of experience through internships, university projects, CTF participation, bug bounties, or personal research.
- Ability to read and write at least one scripting language, such as Python, for automation and proof-of-concept development.
- Strong interest in Android and iOS security, with exposure to Frida or Objection considered beneficial.
- Clear communication, eagerness to learn, curiosity, ownership, and collaborative teamwork skills.
- Preferred qualifications include open-source security contributions, published CVEs, cybersecurity certifications such as eJPT, OSCP, or PortSwigger, and familiarity with AWS, Burp Suite, or Nmap.
Benefits
- Private insurance for the employee and family, psychological support through Serenis, and mental health workshops.
- Stock Option Plan, meal vouchers, and relocation support for employees moving countries.
- Professional development programs, internal mobility, and language courses through Preply.
- Unlimited PTO, flexible working hours, and a hybrid policy with three days per week in-office: Tuesday, Thursday, and one additional chosen day, with the option to request extra remote time.
- Enhanced parental leave and additional leave for child sickness.
