Vulnerability Governance Analyst, Italy

31 lug - Milano
Ion

ph3About us: /h3 pWe are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide. /p pFor the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as bVulnerability Governance Analyst /b. This position is targeted at candidates with b2–5 years of relevant experience /b in Cybersecurity, Vulnerability Management, or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organization’s vulnerability governance framework and security posture. /p pLearn more at /p h3Your role /h3 h3Your key duties and responsibilities /h3 ul liSupport the governance and continuous improvement of the enterprise Vulnerability Management program. /li liMonitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments, ensuring compliance with established remediation targets and governance requirements. /li liPerform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence. /li liCorrelate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services, impacted customers,



remediation owners and urgency of action. /li liPrioritize vulnerabilities using a risk-based model that goes beyond technical severity, considering exploitability, evidence of active exploitation, CISA KEV/EPSS, Internet exposure, asset criticality, client impact and multi-tenant blast radius /li liCoordinate remediation plans and follow-up activities with Infrastructure, Cloud, Development, Application Security, and Risk teams. /li liManage remediation exceptions, compensating controls, and risk acceptance processes. /li liDevelop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports. /li liSupport the escalation and governance of critical vulnerabilities and high-risk exposure scenarios. /li liContribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes. /li liSupport audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management. /li /ul h3Other duties /h3 pWe might ask you to perform other tasks and duties as your role expands. /p h3Your skills, experience, and qualifications required /h3 ul liMaster's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors) /li liAt least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.



/li liUnderstanding of vulnerability lifecycle management, remediation processes, and exposure management practices. /li liFamiliarity with vulnerability assessment platforms and reporting solutions. /li liKnowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds. /li liFamiliarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments. /li liKnowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management. /li liAbility to communicate technical findings through clear risk-based reporting and executive-level summaries. /li liStrong analytical, organizational, and stakeholder management skills. /li liExcellent knowledge of Italian and English. /li liRelevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus. /li /ul h3What we offer: /h3 ul liPermanent employment contract /li liItalian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico) /liliGross Annual Salary (RAL) ranging from b€40,000 to €50,000 /b, depending on experience, skills, and qualifications /li liJob grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level /li liOpportunity to join a leading international technology group operating in the financial services industry /li liExposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment /li /ul h3Location: /h3 pMilan. /p h3Important notes: /h3 pAccording to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority. /p /p #J-18808-Ljbffr

Operai imbianchini/verniciatori

07 ago - Ambivere
MD Consulting srls

Cintabile amministrativo

07 ago - Ottaviano
planeta

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per vulnerability governance analyst, italy / milano

Aiutante pizzaiolo

07 ago - Catania
Pizzeria fratelli pomodoro di Riccardo Patti

Autista di autoarticolati-ravenna (ra)-#25109

07 ago - Ravenna
Lavora con noi italia srls