Welcome to Herzum | now part of Catworkx!
We are much more than an IT consulting company: we are innovators, pioneers, and partners in excellence. Today, we begin a new chapter as part of the catworkx group — one of the world’s leading Atlassian Platinum Partners, with a strong presence across Europe.
Founded in Chicago in 2000, Herzum has grown into an international organization with offices in Italy, the United States, India, Switzerland, Ecuador, and the United Kingdom. Together with catworkx, we combine expertise, culture, and vision to deliver solutions that bring innovation, efficiency, and collaboration to companies around the world. We specialize in Agile, DevOps, and team collaboration technologies, helping organizations work better, faster, and more seamlessly.
Application Security Specialist:
We are seeking a technically strong Application Security Specialist to support security testing activities, analyze vulnerabilities, and provide remediation guidance to development and infrastructure teams. The role will be instrumental in improving the security posture of applications and supporting the remediation lifecycle.
Key Responsibilities
Configure, execute, and maintain application security scans
Analyze findings from security scanning tools and assess risk levels
Provide technical guidance to development teams and suppliers on remediation activities
Support root cause analysis of identified vulnerabilities
Monitor remediation progress and ensure timely closure of findings
Collaborate with application owners, DevOps teams, and security stakeholders
Contribute to security standards, best practices, and secure development initiatives
Produce technical reports and management summaries
Tools & Technologies
Experience with one or more of the following tools is highly desirable:
Polaris (SAST & SCA)
Invicti (DAST)
Entro (Secrets Management)
Aqua Security (Container Security)
Required Skills & Experience
Experience in Application Security, Security Engineering, or Vulnerability Management
Strong understanding of:
Secure Software Development Lifecycle (SSDLC)
SAST, DAST and SCA methodologies
OWASP Top 10
Container Security
Secrets Management
Ability to interpret technical findings and recommend remediation actions
Experience working with developers and DevOps teams
Fluent English
Preferred Qualifications
Security certifications such as OSCP, GWAPT, CSSLP, CEH, or similar
Experience with Cloud Security environments (AWS, Azure, GCP)
Familiarity with CI/CD security integration
Work Location: Full Remote.
We are looking for VAT-registered professionals (Partita IVA) available to collaborate, with a daily rate between € 300 and € 330.
Join Us! Become part of a team driven by innovation, belief in talent, and a commitment to excellence. Your next career step starts here.
This announcement is addressed to both sexes, in accordance with Laws 903/77 and 125/91, and to people of all ages and nationalities, in accordance with Legislative Decrees 215/03 and 216/03.