Junior Offensive Security Engineer
Satispay · Milan, Italy
Skills in this posting
Extracted from the posting text by the instrument — the demand side, read literally.
The posting
Junior Offensive Security Engineer
About Satispay
Satispay began by rethinking the simple act of a payment to remove the friction from our daily routines. But we didn’t stop there. Today, we are building a complete financial platform designed to empower people and concretely improve their lives. By giving our 6 million users a clear, open path to pay, save, and invest, we are evolving into the definitive destination for every financial need.
What you'll be doing
As our Junior Offensive Security Engineer, you’ll be the person who supports our security team in securing our cloud infrastructure, mobile, and web applications. Here's what your day-to-day will look like:
Penetration Testing – Perform penetration testing on mobile (iOS & Android) and web applications. Under the guidance of a senior engineer, use tools like Frida to bypass security controls and analyze app behavior at runtime.
Code and Architectural Review – Review source code for logic flaws, collaborate with developers to implement secure design patterns, and assist in reviewing cloud infrastructure for full security coverage.
Scripting & Automation – Develop scripts to automate repetitive testing tasks, create proof-of-concept exploits, and parse tool results to optimize testing workflows.
Collaborate on Defense – Work closely with the rest of the Security team to test monitoring capabilities, participate in attack simulations, and improve overall detection strategies.
Documentation and Reporting – Write technical reports of findings and document remediation steps for development teams.
Who we're looking for
We need a problem-solver who loves teamwork and gets things done. If you're curious and ready for real ownership, you'll fit in!
Does this sound like you?
Strong Foundations – Good knowledge of information security basics, networking, web application architecture, and familiarity with common web vulnerabilities (e.g., SQL injection, XSS, IDOR, race conditions).
Hands-on Experience – 0–2 years of experience from internships, university projects, active CTF participation, bug bounties, or personal research.
Curious Mindset – Driven to figure out how business logic can be bypassed and understand the "why" behind each vulnerability.
Scripting Skills – Ability to read and write code in at least one scripting language (e.g., Python) for task automation and creating simple proof-of-concepts.
Interest in Mobile Security – Strong interest in securing Android and iOS apps, with exposure to Frida or Objection as a great starting point.
Soft Skills – Clear communication, eagerness to learn, and proven capability of working collaboratively in a team environment.
Bonus Points – Previous contributions to open-source security tools or published CVEs, cybersecurity certifications (e.g., eJPT, OSCP, PortSwigger), familiarity with AWS/cloud environments, or standard penetration testing tools (Burp Suite, Nmap).
CareAbout: how we support your impact
We move fast, and evolution never stops. It’s a fun ride, but it can be challenging. To make sure our people truly thrive, we’re committed to making their lives easier, both in the office and out in the world. That’s why we created CareAbout:
❤️ Health (Private insurance for you and your family, psychological support with Serenis, mental health workshops)
💰 Financial resources (Stock Option Plan, Meal vouchers, Relocation support if you’re moving countries)
⚙️ Growth and development (Professional development programs, Internal mobility, Language courses with Preply)
🌱 Flexibility (Unlimited PTO, Hybrid working policy*, Flexible working hours)
👨👩👧 Family (Enhanced parental leave, Additional leave for child sickness)
*We embrace three days per week in-office (Tuesday and Thursday + 1 of your choice), with the option to request extra remote time.
Salary: €38,000 - €54,000 gross per annum
This range is set using objective, gender-neutral criteria for the role's core requirements. However, we do not believe in putting a ceiling on talent. The final compensation package is tailored according to your unique experience and expertise. If your skills go beyond the standard profile, apply anyway so we can discuss a package that reflects your true value.
Equal opportunity employer
At Satispay, we're proud to be an equal opportunity employer. We celebrate diversity and inclusion, welcoming individuals of all backgrounds. This opportunity is open to everyone, regardless - for instance - of race, colour, religion, sex, gender identity, sexual orientation, and national origin.
Join us in a workplace where everyone belongs!
Learn more about us
Our values and pillars aren’t just fancy words on a page - they really shape everything we do.
Explore them here .
#LI-VR1
By submitting this application, I acknowledge that I have read and understood the content of the Privacy Policy
Excerpt from the original listing. The full, current text lives at the source. Read and apply there →
The PivotHop read
- What a penetration tester actually earnsmedian, seniority, by country
- What penetration testers do insteadevery measured route out
- Security Engineer → Penetration Tester69% readiness
- All open penetration tester rolesthe full board
Where these skills also reach
Adjacent occupations measured from the same postings — readiness is what a penetration tester’s profile already covers.
- 349 open security engineer roles48% readiness from penetration tester
- 66 open network engineer roles33% readiness from penetration tester
- 532 open it support specialist roles25% readiness from penetration tester
- 564 open solutions architect roles24% readiness from penetration tester
More penetration tester roles
- Penetration Tester (Only for GR Residents)AI2CYBER · Greece
- Offensive Security EngineerPalantir · Washington, D.C.
- Offensive Security EngineerSporty Group · Europe
- Penetration Tester (Florida)Packetlabs Ltd. · United States
- AI Security Research & Red Team EngineerCloudflare · Hybrid
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.