Application Security Engineer — Hybrid Role & Growth
TXT GROUP · Roma, Lazio ·
- Work mode
- Hybrid
- Employment
- Contract
- Category
- Security
HSPI S.p.A., part of TXT Group, seeks an Application Security Engineer to join our Rome team in Cinecittà. You will perform vulnerability assessments, penetration testing, and secure code reviews across web apps, cloud environments, and Kubernetes platforms.
Responsibilities include reporting, threat modeling, and ensuring remediation effectiveness, with a hybrid work setup and a permanent contract under CCNL Commercio. Welcome involvement in certification paths and continuous security learning.
Perform vulnerability assessments and penetration testing on web apps, IT infra, cloud environments, and Kubernetes/AKS clusters. Support technical reporting with detailed Deep Dive Reports and CVSS/MITRE/OWASP mapping. Conduct threat modeling using STRIDE and produce risk assessment documentation. Review source code using SAST tools and manual techniques to find vulnerabilities. Must have practical knowledge of OWASP top vulnerabilities and CWE. Experience with vulnerability assessments, pen testing, and security tooling. Familiarity with reporting standards and remediation verification. Hybrid working model