Vulnerability Governance Analyst, Italy

ION Group

Milano

In loco

EUR 40.000 - 50.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Vantaggi offerti da questo lavoro

CCNL Metalmeccanico

Descrizione del lavoro

ION Group is seeking a Vulnerability Governance Analyst in Italy to strengthen the CISO function and mature vulnerability management across enterprise and cloud environments. You will drive risk-based remediation, coordinate with Infrastructure, Development and Security teams, and deliver executive dashboards.

The role requires 2–5 years in cyber risk or governance, solid knowledge of vulnerability lifecycle and ISO/NIST references, plus fluency in Italian and English.

Competenze

  • Master's degree in cybersecurity or related field.
  • 2–5 years of experience in Vulnerability Management or related areas.
  • Understanding of vulnerability lifecycle management and remediation processes.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, NIS2 in relation to vulnerability and ICT risk management.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be a plus.

Mansioni

  • Support governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor remediation activities across infrastructure, cloud, endpoint, and application environments.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services and urgency of action.
  • Prioritize vulnerabilities using a risk-based model considering exploitability, active exploitation, and external threat intel.
  • Coordinate remediation plans with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, and executive reports.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.
  • Contribute to policy and governance process improvements.

Conoscenze

Vulnerability Management
Security Operations
Cyber Risk
Security Governance
Threat Intelligence
Executive reporting

Formazione

Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)

Strumenti

SBOM/SCA tools

Descrizione del lavoro

Home » Jobs » Vulnerability Governance Analyst, Italy

Vulnerability Governance Analyst, Italy

We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as Vulnerability Governance Analyst. This position is targeted at candidates with 2–5 years of relevant experience in Cybersecurity, Vulnerability Management, or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organization’s vulnerability governance framework and security posture.

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments, ensuring compliance with established remediation targets and governance requirements.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services, impacted customers, remediation owners and urgency of action.
  • Prioritize vulnerabilities using a risk-based model that goes beyond technical severity, considering exploitability, evidence of active exploitation, CISA KEV/EPSS, Internet exposure, asset criticality, client impact and multi-tenant blast radius
  • Coordinate remediation plans and follow-up activities with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports.
  • Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
  • Contribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.
Other duties

We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required
  • Master\'s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)
  • At least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds.
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
  • Strong analytical, organizational, and stakeholder management skills.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus.
What we offer:
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
  • Gross Annual Salary (RAL) ranging from €40,000 to €50,000, depending on experience, skills, and qualifications
  • Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level
  • Opportunity to join a leading international technology group operating in the financial services industry
  • Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment
Location:

According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Security Governance Analyst, Italy
Security Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Vulnerability Governance Analyst, Italy — Elevate Cyber Risk
Vulnerability Governance Analyst, Italy — Elevate Cyber Risk

ION Group • Milano

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
Security Risk & Vulnerability Governance Analyst – Italy
Security Risk & Vulnerability Governance Analyst – Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Information Security Governance Analyst
Information Security Governance Analyst

CRIF • Bologna

In loco
EUR 34.000 - 42.000
Cyber Security Analyst
Cyber Security Analyst

Nethive SPA • Limena

Ibrido
EUR 28.000 - 34.000
Buoni Pasto 8 euro
Piano Welfare 1500 €/anno
Smart Working 1 giorno
Cyber Security Compliance Consultant
Cyber Security Compliance Consultant

Arsenalia • Venezia

In loco
EUR 35.000 - 50.000
Welfare Package
Worklife Kit
Career Path development program
+1
Cyber Security Compliance Consultant
Cyber Security Compliance Consultant

Arsenalia • Mestre

In loco
EUR 35.000 - 50.000
Welfare Package
Worklife Kit
Career Path development program
Cyber Security Analyst Senior
Cyber Security Analyst Senior

CRIF • Bologna

In loco
EUR 45.000 - 55.000
CYS_Cyber Resilince Advisor_GCSC
CYS_Cyber Resilince Advisor_GCSC

leonardocompany • Roma

Ibrido
EUR 42.000 - 55.000
Mensa aziendale
Buoni Welfare 250€ annui
Premialità legata ai risultati
+1