Vulnerability Governance Analyst, Italy at Ion.
È pronto/a a candidarsi? Si assicuri di aver compreso tutte le responsabilità e i compiti associati a questo ruolo prima di procedere.
Key facts
- Location: Milan, Italy
- Engagement: Full-time (hybrid)
- Team: Chief Information Security Office (CISO)
What you'll do
- Contribute to the continuous enhancement of the enterprise Vulnerability Management program to ensure its effectiveness and efficiency.
- Supervise the remediation of vulnerabilities across diverse environments, including infrastructure, cloud services, and applications, while ensuring adherence to established compliance targets.
- Perform risk-based vulnerability assessments that take into account factors such as exploitability, asset significance, and potential business impact.
- Integrate vulnerability data with configuration management, business impact analysis, and software bill of materials (SBOM) to accurately identify affected services and determine the urgency of remediation efforts.
- Utilize a risk model to prioritize vulnerabilities, factoring in elements like active exploitation, CISA Known Exploited Vulnerabilities (KEV), and exposure on the internet.
- Coordinate and manage remediation plans, maintaining communication and follow-up with various technical teams and risk management stakeholders.
- Handle exceptions, implement compensating controls, and oversee risk acceptance processes related to identified vulnerabilities.
- Develop and maintain dashboards, key performance indicators (KPIs), and comprehensive reports for effective vulnerability management.
- Assist in the escalation and governance processes for critical vulnerabilities and high-risk scenarios.
- Collaborate in defining and refining policies, standards, and governance processes related to vulnerability management.
- Support audit activities, regulatory assessments, and compliance initiatives concerning cyber risk and vulnerability management.
Requirements
- A Master's degree (with honors) in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a closely related discipline.
- Between 2 to 5 years of experience in areas such as Vulnerability Management, Security Operations, Cyber Risk, or Security Governance.
- A solid understanding of the vulnerability lifecycle, including management, remediation, and exposure assessment.
- Familiarity with various vulnerability assessment platforms and reporting tools is essential.
- Knowledge of vulnerability prioritization techniques and industry standards, including CVSS, EPSS, and CISA KEV.
- Understanding of software supply chain security concepts, including SBOMs, Software Composition Analysis (SCA), and DevSecOps practices.
- Awareness of frameworks and standards such as ISO 27001, NIST Cybersecurity Framework (CSF), CIS Controls, DORA,
and NIS2, particularly in the context of vulnerability and ICT risk management.
- Strong communication skills to convey technical findings through clear, risk-focused reports and executive summaries.
- Excellent analytical, organizational, and stakeholder management skills.
- Proficiency in both Italian and English is required.
Nice to have
- Possession of relevant certifications such as Security+, CySA+, CISSP, or ISO 27001 would be advantageous.
Skills & tools
- Proficient in using Vulnerability Management platforms
- Familiarity with reporting solutions
- Experience with Configuration Management Database (CMDB)
- Knowledge of Business Impact Analysis (BIA)
- Understanding of SBOM/SCA methodologies
- Familiarity with CVSS, EPSS, and CISA KEV standards
- Experience with exploit intelligence and threat intelligence feeds
- Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 frameworks
Practical notes
- This position offers a permanent employment contract governed by the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
- The Gross Annual Salary (RAL) is competitive, ranging from €40,000 to €50,000, depending on the candidate's experience and qualifications.
- The job grade will be established between B2 and B3 levels following the selection process. xysqume
Candidates belonging to protected categories, as defined by Italian Law (L.68/99), will be given priority during the hiring process.
#J-18808-Ljbffr
📌 Vulnerability Governance Analyst, Italy (Italia)
🏢 Ion
📍 Italia