The Security Testing Specialist will support the Quality Control & Assurance (QCA) unit in conducting advanced application and infrastructure security assessments. The role requires a strong Ethical Hacking background (white hat) hands-on penetration
testing expertise and solid secure coding and development experience to enable source code reviews and provide actionable technical guidance. This position is part of the cybersecurity assurance activities within the
client location.
Responsibilities
The Security Testing Specialist will be responsible for:
Plan and perform ethical hacking engagements and full-scope penetration tests
(web API infrastructure cloud when applicable)
Conduct and automate vulnerability scans analyse results prioritise risks
Perform source code reviews identify insecure coding patterns and recommend
remediation
Support the Secure SDLC identifying weaknesses early in the lifecycle
Produce detailed security assessment reports test plans and scripts
Analyse root causes of security defects and propose corrective actions
Contribute to security architecture evaluations and compliance testing
Collaborate with developers architects and stakeholders to ensure secure design
and implementation
Technical Skills and Tools
Ethical Hacking & Development (Newly Mandatory per Client Feedback)
CEH (Certified Ethical Hacker) or equivalent certification
Strong development experience (e.g. Python Java C# or similar)
Proven experience in secure coding and source code review
Solid understanding of application architectures and common coding
vulnerabilities
Penetration Testing & Security Tools
Hands-on experience with:
Burp Suite OWASP ZAP Metasploit
Nessus Qualys OpenVAS
Scripting languages: Python Bash PowerShell
OS expertise: Linux and Windows
Web & API security: REST SOAP JSON XML
Strong knowledge of:
OWASP Top 10
Secure SDLC
DevSecOps practices
Desirable:
Knowledge of cloud security controls (Azure AWS GCP)
Experience with SIEMs and log analysis
Familiarity with compliance frameworks: ISO 27001 NIST CIS
Qualifications and Experience
Minimum 5 years of experience in cybersecurity testing
University degree in IT engineering or equivalent experience
CEH certification is required
Certifications such as OSCP GIAC CISSP are advantageous
Strong reporting and documentation skills in English
Experience in European Institutions or large public-sector IT
Deliverables
Security testing strategy and test cases
Periodic penetration testing reports
Security gap analysis and remediation guidance
Scripts for test automation and log analysis
Documentation of findings and evidence in line with EU IT standards environments is a plus
30 employees
Welcome to Sansaone, a dynamic force in the realm of ICT talent acquisition. Born out of a passion for excellence and a vision for connecting outstanding professionals with forward-thinking organizations, we stand as a beacon for strategic recruitment solutions in the Information and ... View more