Vulnerability Governance Analyst, Italy

07 ago - Italia
Ion

ppVulnerability Governance Analyst, Italy at Ion. /ph3Key facts /h3ulliLocation: Milan, Italy /liliEngagement: Full-time (hybrid) /liliTeam: Chief Information Security Office (CISO) /li /ulh3What you'll do /h3ulliContribute to the continuous enhancement of the enterprise Vulnerability Management program to ensure its effectiveness and efficiency. /liliSupervise the remediation of vulnerabilities across diverse environments, including infrastructure, cloud services, and applications, while ensuring adherence to established compliance targets. /liliPerform risk-based vulnerability assessments that take into account factors such as exploitability, asset significance, and potential business impact. /liliIntegrate vulnerability data with configuration management, business impact analysis, and software bill of materials (SBOM) to accurately identify affected services and determine the urgency of remediation efforts. /liliUtilize a risk model to prioritize vulnerabilities, factoring in elements like active exploitation, CISA Known Exploited Vulnerabilities (KEV), and exposure on the internet. /liliCoordinate and manage remediation plans, maintaining communication and follow-up with various technical teams and risk management stakeholders. /liliHandle exceptions, implement compensating controls, and oversee risk acceptance processes related to identified vulnerabilities. /liliDevelop and maintain dashboards, key performance indicators (KPIs), and comprehensive reports for effective vulnerability management. /liliAssist in the escalation and governance processes for critical vulnerabilities and high-risk scenarios.



/liliCollaborate in defining and refining policies, standards, and governance processes related to vulnerability management. /liliSupport audit activities, regulatory assessments, and compliance initiatives concerning cyber risk and vulnerability management. /li /ulh3Requirements /h3ulliA Master's degree (with honors) in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a closely related discipline. /liliBetween 2 to 5 years of experience in areas such as Vulnerability Management, Security Operations, Cyber Risk, or Security Governance. /liliA solid understanding of the vulnerability lifecycle, including management, remediation, and exposure assessment. /liliFamiliarity with various vulnerability assessment platforms and reporting tools is essential. /liliKnowledge of vulnerability prioritization techniques and industry standards, including CVSS, EPSS, and CISA KEV. /liliUnderstanding of software supply chain security concepts, including SBOMs, Software Composition Analysis (SCA), and DevSecOps practices. /liliAwareness of frameworks and standards such as ISO 27001, NIST Cybersecurity Framework (CSF), CIS Controls, DORA, and NIS2,



particularly in the context of vulnerability and ICT risk management. /liliStrong communication skills to convey technical findings through clear, risk-focused reports and executive summaries. /liliExcellent analytical, organizational, and stakeholder management skills. /liliProficiency in both Italian and English is required. /li /ulh3Nice to have /h3ulliPossession of relevant certifications such as Security+, CySA+, CISSP, or ISO 27001 would be advantageous. /li /ulh3Skills tools /h3ulliProficient in using Vulnerability Management platforms /liliFamiliarity with reporting solutions /liliExperience with Configuration Management Database (CMDB) /liliKnowledge of Business Impact Analysis (BIA) /liliUnderstanding of SBOM/SCA methodologies /liliFamiliarity with CVSS, EPSS, and CISA KEV standards /liliExperience with exploit intelligence and threat intelligence feeds /liliKnowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 frameworks /li /ulh3Practical notes /h3ulliThis position offers a permanent employment contract governed by the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico). /liliThe Gross Annual Salary (RAL) is competitive, ranging from €40,000 to €50,000, depending on the candidate's experience and qualifications. /liliThe job grade will be established between B2 and B3 levels following the selection process. /li /ulpCandidates belonging to protected categories, as defined by Italian Law (L.68/99), will be given priority during the hiring process. /p /p #J-18808-Ljbffr

Aiuti per donna disabile

08 ago - Carini
Mary

Tirocinio retribuito

08 ago - Melegnano
Sicurezza e Gestioni

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per vulnerability governance analyst, italy / italia

Personal trainer

08 ago - Napoli
Ilaria

LAVORO a MILANO (Zona Bocconi):

08 ago - Milano
dalia2