
Junior Offensive Security Engineer
Job description
About the role
You will be the dedicated support for the security team in protecting Satispay's cloud infrastructure, mobile applications, and web platforms through hands-on offensive work. This role is centered on performing penetration tests and security assessments under the guidance of senior engineers to ensure our systems remain resilient against real-world threats. You will own the execution of security testing for both mobile and web channels, using advanced tools and creative techniques to evaluate the strength of our defenses. Your work will directly influence the security roadmap by exposing logic flaws, implementation bugs, and architectural weaknesses before they can be exploited. You will translate technical findings into clear documentation and remediation guidance so that development teams can quickly and effectively address issues. Through constant collaboration with developers and security colleagues, you will help foster a culture where secure design and robust implementation are standard practice across all products.
Key facts
What you'll do
Conduct penetration testing against mobile applications for iOS and Android, analyzing runtime behavior and bypassing security controls with tools such as Frida.
Review application source code to identify logic flaws, authentication bypasses, and insecure design patterns while collaborating closely with developers on secure implementations.
Perform architectural reviews of cloud infrastructure components to validate that security controls are correctly applied and aligned with best practices.
Automate repetitive testing activities by developing scripts in languages such as Python, and build proof-of-concept exploits to validate complex vulnerability chains.
Parse and analyze output from security tools to refine testing methodologies, reduce noise, and highlight high-risk findings efficiently.
Work alongside the Security team to test monitoring rules, participate in attack simulations such as red teaming or breach and attack simulation exercises, and contribute to detection improvements.
Document every phase of security assessments, producing clear technical reports that detail findings, risk ratings, and actionable remediation steps for engineering teams.
Support the continuous improvement of the security testing process by suggesting new techniques, tools, and scenarios that keep pace with evolving threats and the expanding Satispay product landscape.
Act as an ambassador for secure engineering practices, sharing knowledge through informal discussions, code walkthroughs, and guidance that helps raise the overall security awareness of the team.
Maintain a structured and transparent workflow for testing activities, ensuring that scope, timelines, and results are clearly communicated to stakeholders throughout the engagement.
Requirements
You possess a strong foundation in information security fundamentals, including networking protocols, common web application architectures, and the mechanics of prevalent web vulnerabilities such as SQL injection, cross-site scripting, insecure direct object references, and race conditions.
You bring 0 to 2 years of practical experience gained through internships, university projects, active participation in Capture The Flag events, responsible disclosure and bug bounty programs, or focused personal research in security topics.
You have a naturally curious mindset and a problem-solving attitude, driven to understand not only how a vulnerability can be triggered but also why business logic controls can be bypassed and what design choices enable those weaknesses.
You are comfortable reading and writing code in at least one scripting language, with Python being a common example, to automate tasks, create proof-of-concept exploits, and process tool output for analysis.
You demonstrate a strong interest in mobile security, including familiarity with the Android and iOS platforms and hands-on experience with dynamic analysis tools such as Frida or Objection.
You communicate clearly in English, both in writing and verbally, and you are comfortable collaborating in a fast-paced, cross-functional team environment where feedback is frequent and expectations are high.
You are eligible to work legally in Italy without restrictions, ensuring that your profile aligns with the requirements for full-time employment in this role.
You are comfortable working in an agile environment, adapting quickly to shifting priorities and evolving requirements while maintaining attention to detail and a high standard of work.
You are intrinsically motivated, proactive in seeking out responsibilities, and capable of managing your time effectively to meet testing schedules and reporting deadlines.
Nice to have
Prior contributions to open-source security tools that are widely used by the community or the publication of valid CVEs in publicly tracked databases.
Possession of cybersecurity certifications such as eJPT, OSCP, or similar credentials that validate practical penetration testing skills.
Hands-on experience with cloud environments like AWS, including knowledge of common services and security best practices for infrastructure deployment.
Familiarity with standard penetration testing toolkits and frameworks, including Burp Suite, Nmap, and related utilities for network and web application testing.
Practical notes
This role is based in Milan, Italy, with a hybrid working arrangement that includes three days per week in the office on Tuesdays and Thursdays, plus one additional day of your choice.
You may request extra remote working time subject to team approval and operational needs.
The expected working hours align with standard full-time schedules, and travel is generally not required as part of this position.
This position is open to candidates who are eligible to work in Italy without visa requirements; relocation support is available for international moves as described in the CareAbout section.
Applications will be reviewed on an ongoing basis until the position is filled, encouraging early submission if you believe your profile matches the core requirements.