Vulnerability Governance Analyst, Italy

07 ago - Roma
Altro

Vulnerability Governance Analyst, Italy at Ion.

Si candidi (facendo clic sul pulsante apposito) dopo aver controllato tutte le informazioni di lavoro riportate di seguito.
Key facts

Location: Milan, Italy
Engagement: Full-time (hybrid)
Team: Chief Information Security Office (CISO)
What you'll do

Contribute to the continuous enhancement of the enterprise Vulnerability Management program to ensure its effectiveness and efficiency.
Supervise the remediation of vulnerabilities across diverse environments, including infrastructure, cloud services, and applications, while ensuring adherence to established compliance targets.
Perform risk-based vulnerability assessments that take into account factors such as exploitability, asset significance, and potential business impact.
Integrate vulnerability data with configuration management, business impact analysis, and software bill of materials (SBOM) to accurately identify affected services and determine the urgency of remediation efforts.
Utilize a risk model to prioritize vulnerabilities, factoring in elements like active exploitation, CISA Known Exploited Vulnerabilities (KEV), and exposure on the internet.
Coordinate and manage remediation plans, maintaining communication and follow-up with various technical teams and risk management stakeholders.
Handle exceptions, implement compensating controls, and oversee risk acceptance processes related to identified vulnerabilities.
Develop and maintain dashboards, key performance indicators (KPIs), and comprehensive reports for effective vulnerability management.




Assist in the escalation and governance processes for critical vulnerabilities and high-risk scenarios.
Collaborate in defining and refining policies, standards, and governance processes related to vulnerability management.
Support audit activities, regulatory assessments, and compliance initiatives concerning cyber risk and vulnerability management.
Requirements

A Master's degree (with honors) in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a closely related discipline.
Between 2 to 5 years of experience in areas such as Vulnerability Management, Security Operations, Cyber Risk, or Security Governance.
A solid understanding of the vulnerability lifecycle, including management, remediation, and exposure assessment.
Familiarity with various vulnerability assessment platforms and reporting tools is essential.
Knowledge of vulnerability prioritization techniques and industry standards, including CVSS, EPSS, and CISA KEV.
Understanding of software supply chain security concepts, including SBOMs, Software Composition Analysis (SCA), and DevSecOps practices.
Awareness of frameworks and standards such as ISO 27001,



NIST Cybersecurity Framework (CSF), CIS Controls, DORA, and NIS2, particularly in the context of vulnerability and ICT risk management.
Strong communication skills to convey technical findings through clear, risk-focused reports and executive summaries.
Excellent analytical, organizational, and stakeholder management skills.
Proficiency in both Italian and English is required.
Nice to have

Possession of relevant certifications such as Security+, CySA+, CISSP, or ISO 27001 would be advantageous.
Skills & tools

Proficient in using Vulnerability Management platforms
Familiarity with reporting solutions
Experience with Configuration Management Database (CMDB)
Knowledge of Business Impact Analysis (BIA)
Understanding of SBOM/SCA methodologies
Familiarity with CVSS, EPSS, and CISA KEV standards
Experience with exploit intelligence and threat intelligence feeds
Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 frameworks
Practical notes

This position offers a permanent employment contract governed by the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
The Gross Annual Salary (RAL) is competitive, ranging from €40,000 to €50,000, depending on the candidate's experience and qualifications.
The job grade will be established between B2 and B3 levels following the selection process. xlwpduy
Candidates belonging to protected categories, as defined by Italian Law (L.68/99), will be given priority during the hiring process.

#J-18808-Ljbffr

Main Crane Operator 250

08 ago - Italia
Altro

Disegnatore Meccanico Su Solidworks

08 ago - Italia
WAICO

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per vulnerability governance analyst, italy / roma

ADDETTO UFFICIO ACQUISTI COMMERCIALE FRESCHI

08 ago - Italia
Altro

Oil & Gas Sector Growth Strategist - National Sales

08 ago - Italia
Altro