Global Cybersecurity Specialist (Milano)

Global Cybersecurity Specialist (Milano)

03 ago
|
Amplifon
|
Milano

03 ago

Amplifon

Milano

ppbAmplifon /b is an Italian multinational company and the global leader in hearing care solutions and services, built on retail expertise, customization and consumer care. More than b20,000 professionals /b every day, in a network of 10,000 points of sale across b25 countries /b, give back the joy of hearing, feeling and living to thousands of people across the world. /p pIn Amplifon we believe people are the most important component of our success. Thanks to our best‑in‑class Hearing Care Professionals and front‑and back‑office teams, we are able to put the everyday taps, pops and splashes back into the lives of our customers. We believe that it is only through strong investment in talent engagement, continuous professional development, support and recognition that our people can exceed every limit and build a fulfilling career. /p h3Role Overview /h3 pAt Amplifon we are evolving our technological infrastructure and elevating our security posture, integrating cutting‑edge innovations into our operational cybersecurity framework. As we prioritize innovative services for delivering hearing healthcare, robust cybersecurity is critical to ensure the security and integrity of these systems. In parallel, we are modernizing our internal asset management processes, leveraging digital tools for comprehensive, end‑to‑end life‑cycle management. /p pWe are looking for a talented Global Cybersecurity Specialist to join our Global IT — Cyber Security team. Reporting to the Global Cyber Security Associate Director, you will work hands‑on across penetration testing, infrastructure and application security assessment, vulnerability management and security‑platform operations. You will also take an active part in security monitoring and incident response, and contribute to our information security governance program (ISO/IEC 27001, NIS2). /p pThis is a high‑impact, cross‑country role in a fast‑moving environment, where your work directly protects customer data and business‑critical services and helps shape our asset management strategy. /p h3Key Responsibilities /h3 pbOffensive Security Assessments /b /p pbPenetration testing assessment — /b plan and perform penetration tests and security assessments on web and mobile applications, internal systems and internet‑facing infrastructure, identifying vulnerabilities, misconfigurations and exposure (e.g. unmanaged accounts, weak authentication, unnecessary services, exposed personal data). /p pbRemediation ownership — /b produce clear, risk‑based reports and drive remediation with system, application and infrastructure owners through to closure, then re‑test to confirm fixes are effective. /p pbControlled validation — /b support authorized, red‑team‑style validation activities (e.g. credential/dump validation, lateral‑movement checks) to confirm real‑world exploitability.



/p pbVulnerability Management /b /p pbLifecycle management — /b run and continuously mature the vulnerability management lifecycle: discovery, triage, prioritization, remediation tracking and verification. /p pbStrategy — /b collaborate in the development and execution of robust vulnerability management strategies across the global estate. /p pbSecurity Platforms Infrastructure /b /p pbPlatform operations — /b operate, configure and tune security consoles and platforms across endpoint, network and identity — for example EDR (e.g. SentinelOne), endpoint and patch management (e.g. Ivanti) and network security / firewalls (e.g. Cisco ASA) — ensuring compliance with company policies and industry best practice. /p pbAccess credential hygiene — /b strengthen access and credential hygiene on shared and critical systems (account reviews, deprovisioning of stale users, credential rotation, reduction of data exposure). /p pbSecurity Monitoring Incident Response /b /p pbDetection response — /b contribute to security monitoring and to the detection, analysis, containment and recovery phases of security incidents, working alongside the SOC and specialized external partners (e.g. threat‑intelligence and incident‑response providers). /p pbPost‑incident hardening — /b support lessons‑learned and hardening activities to reduce the likelihood and impact of recurrence. /p pbISMS regulation — /b contribute to the Information Security Management System (ISO/IEC 27001), information security risk assessments and regulatory alignment (e.g. NIS2), keeping security practices consistent with company policies. /p pbAsset lifecycle KPIs — /b support asset life‑cycle management and endpoint standardization initiatives using digital tools, and identify and track KPIs relevant to a secure, well‑governed asset and vulnerability portfolio. /p pbSupplier management — /b oversee the engagement and management of external suppliers and partners (penetration testing, vulnerability and security services), managing scope, quality and delivery against organizational expectations. /p h3Requirements /h3 h3Must have /h3 ul liBachelor's degree in a STEM field with a focus on cybersecurity or a related discipline — or equivalent hands‑on experience. /li liSolid understanding of penetration testing tools and methodologies (network and web/mobile application testing; familiarity with frameworks such as OWASP). /li liWorking knowledge of vulnerability management, security assessment techniques and common attack techniques (e.g. authentication weaknesses, credential attacks such as pass‑the‑hash, lateral movement). /li liExperience with security platforms across endpoint,



network and identity (e.g. EDR, endpoint/patch management, firewalls). /li liAwareness of information security frameworks and regulations (e.g. ISO/IEC 27001, NIS2, GDPR / personal‑data protection). /li liProactive mindset, dedicated to continuous improvement and adept at navigating transformational initiatives. /li liStrong problem‑solving skills with a meticulous, process‑oriented approach. /li liAbility to thrive in a dynamic, fast‑paced, multi‑country environment while managing multiple priorities concurrently. /li liExceptional communication skills and a collaborative, team‑oriented attitude. /li liFluency in English is mandatory. /li /ul h3Nice to have /h3 ul liIndustry certifications such as OSCP, CEH, GIAC, CompTIA Security+ or equivalent. /li liScripting and automation skills (e.g. Python, PowerShell, Bash). /li liExposure to cloud security (Azure / AWS / GCP) and Active Directory security. /li liPrior experience in complex IT projects or within high‑growth, multi‑country contexts. /li liWorking proficiency in Italian is a plus for our Milan‑based Global IT team. /li /ul h3Location /h3 pHQ Milan, Italy (Hybrid - allowing employees to work 6 days per month remotely) /p h3Compensation Benefits /h3 pbApplicable Collective Agreement: /b CCNL Commercio (Terziario, Distribuzione e Servizi) /p pbContractual Level: /b Employee (1-2) level /p pbContract Type: /b Permanent – Tempo pieno /p pThe reference Gross Annual Salary is approximately in the range of €34.500 - €48.000. The actual compensation will be commensurate with the candidate’s experience and specific skills and knowledge and also to the educational background. /p pThe position is also eligible for an annual Company bonus (‘premio di risultato’) linked to business performance, in line with Company policies. /p pbBenefits /b /p ul li€750 Annual Welfare plan for your personal well‑being across a wide range of services /li libHealth Insurance: /b Fondo Est healthcare coverage + an additional Accident Insurance /li libSupplementary pension scheme: /b option to enrol in the Fondo Fon.Te with employer contributions /li libOffice Perks: /b On‑site canteen and free company parking /li libBeWellProgram: /b Free access to learning platforms and training programs. We invest in your growth through ongoing learning opportunities, while also offering special corporate discounts, dedicated services for you and your loved ones, and initiatives focused on your wellbeing and physical health /li /ul h3Equal Opportunities Statement /h3 pAmplifon is an equal opportunity employer committed to providing a diverse and equitable workforce environment. We believe that through valuing our uniqueness and respecting our differences, we can achieve more, and that diversity adds to our culture. We encourage applications from all genders, corners of the world and individual backgrounds /p /p #J-18808-Ljbffr

📌 Global Cybersecurity Specialist (Milano)
🏢 Amplifon
📍 Milano

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: global cybersecurity specialist (milano) / milano

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: global cybersecurity specialist (milano) / milano