We are currently looking for a Application Security Consultant - Penetration Testing Consultant in Ispra, Italy.
Candidates need to be fluent in English. This position is also open for freelancers. Workpermit is required. This position needs to be performed on-site. Remote work is not possible.
Tasks and responsibilities:
- Perform application assessments (source code analysis, dynamic security testing);
- Perform regular vulnerability scans using automatic or manual scanners (TripWire, Nessus, Acunetix);
- Perform pentests against infrastructure components (servers, network) or applications;
- Perform technical compliance checks against reference configurations (windowns, Linux/ Unix);
- Evaluate toolkits available on the market (including realisation of prototypes), build and maintain an ethical hacking and application security testing lab;
- Support in producing documentation and reports (installation, configuration guidance, assessment reports);
- Define functional specifications for solutions;
- Develop system software (e.g. scripts for automated configuration, system analysis, alerting);
- Design, prepare and perform technical demos and workshops for user awareness or seminars;
Profile:
- Bachelor or University degree;
- Minimum 5 years of experience in the cyber-security domain, exercising Security Testing, with experience in frameworks like HP Fortify or ideally IBM AppSCan;
- Minimum 2 years of experience in the audit/ pen-test field;
- Previous working experience in web application development (Java, .NET, Agile methodologies), is essential;
- Extensive professional experience in security assurance aspects such as vulnerability assessment, pen-test, technical compliance check and application security testing is required;
- Excellent knowledge of configuration and operation of Security software and hacking tools is required;
- Relevant certifications such as GPEN, CEH, OSCP or similar would be considered a strong asset;
- Fluent in English;
Interested: