Vulnerability Governance Specialist

ION Group

Milano

In loco

EUR 40.000 - 50.000

Tempo pieno

14 giorni+
Generatore di candidature

Non inviare un curriculum generico — genera un curriculum e una lettera di presentazione personalizzati per questo specifico impiego.

Supera i filtri ATS

Vantaggi offerti da questo lavoro

Permanent employment contract
CCNL Metalmeccanico

Descrizione del lavoro

ION Group, Milan, is seeking a Vulnerability Governance Analyst to strengthen its vulnerability governance framework. You will work across Infrastructure, Cloud, Development, and Security to govern remediation efforts and provide data-driven risk reporting.

Ideal candidates have 2–5 years in cybersecurity governance, with strong knowledge of vulnerability lifecycle, SBOMs/SCAs, and industry standards. The role offers a permanent contract and a competitive gross salary in Italy.

Competenze

  • Master’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors).
  • At least 2–5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds.
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
  • Strong analytical, organizational, and stakeholder management skills.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus.

Mansioni

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor remediation activities across infrastructure, cloud, endpoint, and application environments.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services and urgency of action.
  • Prioritize vulnerabilities using a risk-based model considering exploitability, evidence of active exploitation, and external references.
  • Coordinate remediation plans with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports.
  • Support escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
  • Contribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.

Conoscenze

Risk reporting
Stakeholder management
Analytical skills
Italian-English proficiency

Formazione

Master’s degree in Cybersecurity/CS/Engineering/IT

Strumenti

Vulnerability assessment platforms
SBOM/SCA tooling
DevSecOps practices

Descrizione del lavoro

ION Group, Milan, is seeking a Vulnerability Governance Analyst to strengthen its vulnerability governance framework. You will work across Infrastructure, Cloud, Development, and Security to govern remediation efforts and provide data-driven risk reporting.

Ideal candidates have 2–5 years in cybersecurity governance, with strong knowledge of vulnerability lifecycle, SBOMs/SCAs, and industry standards. The role offers a permanent contract and a competitive gross salary in Italy.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Security Risk & Vulnerability Governance Analyst – Italy
Security Risk & Vulnerability Governance Analyst – Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Milano

In loco
EUR 40.000 - 50.000
Permanent employment contract
CCNL Metalmeccanico
Security Governance Analyst in Milan — Risk & Compliance
Security Governance Analyst in Milan — Risk & Compliance

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Security Governance Analyst, Italy
Security Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Security Threat Assessment & Analysis Senior Professional
Security Threat Assessment & Analysis Senior Professional

Source Technology Limited • Milano

Ibrido
EUR 70.000 - 110.000
Security Threat Assessment & Analysis Senior Professional
Security Threat Assessment & Analysis Senior Professional

SGI • Milano

Ibrido
EUR 60.000 - 90.000
Vulnerability Program Lead - Cybersecurity & Delivery
Vulnerability Program Lead - Cybersecurity & Delivery

Mynameis • Bardi

In loco
EUR 50.000 - 61.000
IAM/IGA Cybersecurity Specialist — Rome, Hybrid
IAM/IGA Cybersecurity Specialist — Rome, Hybrid

Numia S.p.A. • Roma

Ibrido
EUR 43.000 - 53.000
Buoni pasto
Valore di Produttività Aziendale
Welfare aziendale
+2
Senior GRC Security Risk & Compliance Analyst
Senior GRC Security Risk & Compliance Analyst

SGI • Milano

Ibrido
EUR 60.000 - 90.000