Cyber Security Specialist

22 set - Milano
Avvale

ppBorn in 2004 as Techedge, we have almost 20 years of expertise that enabled us to become what we are today: Avvale! /p pThis path led us to be able to count on over 4,000 employees, present in 13 countries around the world. /p h3What We Do /h3 pWe help public and private companies to re-design their business models through the development of innovative and sustainable solutions, which have a positive impact not only on our customers but also on the world we live in! /p pThrough circular economy models, made possible thanks to technological innovation. /p h3What you will find /h3 pIn Avvale we value our talents and your path with us will be full of: /p ul libTraining development /b as you can participate to training on the job, certifications, foreign languages classes and you will have a yearly budget to buy training courses; /li libGender equality inclusion /b, the obtaining of Pdr 125 is a proof of Avvale commitment to an inclusive and fair work environment! /li libCompensation Benefits: /b In line with our commitment to transparency and people development, the gross annual salary (RAL) for this position ranges between €39,000,00 and €50,000,00 commensurate with experience and skills. The position is covered by the 'CCNL Commercio e Terziario' (National Collective Labor Agreement for Commerce and Service Sector), alongside a benefits package that includes meal vouchers, wellbeing initiatives (including Wellhub), and growth opportunities. /li /ul h3Role and responsibilities /h3 pWe are looking for a mid-level bCyber Security Specialist /b to join our Security team. Reporting directly to the Security Manager, this role will be pivotal in governing the company's defence infrastructure and overseeing compliance and data protection processes. /p pThe ideal candidate has a solid technical foundation and a pragmatic approach to supporting Governance, Risk Compliance (GRC) processes. They will act as the operational liaison between the company,



the external Security Service Providers and internal IT stakeholders, balancing technical operations with document and regulatory management. /p ul liOversee and monitor key corporate security controls (XDR/EDR, Email Security Gateway, MDM, DNS Protection, DLP) and manage Level 2 activities through ITSM/Ticketing systems. /li liSupport the Security Manager in defining, implementing, and monitoring security policies, standards, and procedures, ensuring compliance with frameworks and regulations such as ISO 27001, NIST, and GDPR. /li liCoordinate operational activities with MSSPs and internal stakeholders, manage escalated alerts, and support Incident Response activities, including remediation tracking. /li liSupport Vulnerability Management activities by analysing scan results, prioritizing risks, and monitoring patching and remediation activities following Penetration Tests or Threat Hunting exercises. /liliContribute to GRC and Third-Party Risk Management activities, including reviewing Security Policies and SOPs, assessing vendors, and monitoring supply chain security posture. /li liSupport internal/external audits and assist in collecting the required documentation for compliance assessments and customer security reviews. /li liPromote cybersecurity awareness across the organization through training initiatives, phishing simulation campaigns, and tracking employee and contractor participation. /li liSupport the Security Manager in drafting, reviewing, and continuously updating Security Policies and SOPs in line with major regulatory frameworks.



/li liMonitor the organization’s supply chain security posture through Cyber Threat Intelligence and Security Rating platforms, supporting Vendor Assessments through supplier questionnaire analysis and initial Gap Analysis activities. /li liSupport the completion of customer compliance questionnaires and assist in collecting evidence and documentation for internal and external audits. /li liContribute to promoting a cybersecurity-aware culture across the organization through training initiatives and awareness programs. /li li3-5 years of experience in similar roles such as Security Analyst, SecOps Specialist, or GRC Analyst, with a solid technical background. /li liPractical experience with SOC operations, Incident Management processes, and the Vulnerability Management lifecycle. /li liGood architectural understanding of modern security defenses for Endpoints, Email, Networks, and DLP technologies. /li liStrong familiarity with major security and privacy standards/frameworks, including GDPR, PCI-DSS, HIPAA (or equivalent), ISO 27001, and NIST. /li liKnowledge of IT Service Management (ITSM) processes. /li liExcellent communication skills, with the ability to effectively interact with external vendors and internal IT teams without direct hierarchical authority. /li liStrong analytical mindset, organizational autonomy, and accuracy in documentation and process management. /li liFluent knowledge of the English language /li /ul pbThe role requires working from our headquarters 2-3 days per week. /b /p pbCome with us /b /p pYou will have the opportunity to work and get in touch with international players who will allow you to increase your know-how in view of future challenges! /p pWe do not consider applications without CV. /p pAvvale promotes equal opportunity. We enhance diversity and are committed to creating an inclusive environment in compliance with applicable non-discrimination and data protection laws. /p /p #J-18808-Ljbffr

Luxury Travel Consultant

23 set - Roma
Meet and Greet Italy

Macchinista di Linea

23 set - Montone
Openjobmetis

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per cyber security specialist / milano

M Associate

23 set - Milano
MindMatch

Magazziniere - €1.700 al mese

23 set - Vigevano
Adecco Italia