07 set
|
Generali Italia
|
Roma
07 set
Generali Italia
Roma
Questa posizione è in Generali Italia
Riassunto dell'opportunità da parte della Joinrs AI:
Generali Italia cerca un Vulnerability Analyst e Penetration Tester con laurea in Informatica, Sicurezza IT o esperienza equivalente. Il candidato svolgerà attività di valutazione vulnerabilità, penetration testing, red teaming e analisi di sicurezza, integrando soluzioni AI avanzate.
Offre contratto a tempo pieno, RAL tra 40K€ e 50K€, smart working, formazione e programmi di sviluppo carriera.
Il processo di selezione sarà interamente gestito da Generali Italia.
Questa opportunità è disponibile su Roma - Italy, Trieste - Italy.
As a Vulnerability Analyst and Penetration Tester, you will work closely with the Cyber Security Monitoring team to perform vulnerability assessments, penetration testing, red teaming activities, and security impact analyses related to emerging cyber threats, zero-day vulnerabilities, and advanced attack techniques.
The role also includes leveraging AI-driven cybersecurity solutions and Large Language Models (LLMs) to enhance information gathering, vulnerability analysis, attack surface monitoring, and the identification of indicators of compromise associated with evolving threat actors and attack campaigns.
Activities will include:
- Execution of periodic Vulnerability Assessments across both internal and external perimeters using enterprise-grade security platforms and automated assessment tools.
- Identification, validation, prioritization, and reporting of vulnerabilities to asset owners, with continuous tracking of remediation activities through the organization's Vulnerability Management platform.
- Execution of Web Application Penetration Tests (WAPT), infrastructure penetration tests, and Red Teaming exercises based on internally defined threat scenarios and intelligence-driven attack simulations.
- Collection and correlation of information from OSINT, CLOSINT, Threat Intelligence feeds, and AI-assisted research platforms to identify newly disclosed vulnerabilities, emerging threats, and zero-day exposures.
- Security impact assessment of new vulnerabilities and threat campaigns affecting the organization, including risk evaluation, remediation prioritization, and stakeholder communication.
- Utilization of AI and Machine Learning-based tools to support vulnerability triage, threat hunting, attack pattern analysis, anomaly detection, and proactive identification of emerging cyber risks.
MAIN TASKS
- Perform Red Teaming activities in collaboration with the GOSP CSIRT team, based on agreed cyber threat scenarios, to validate detection, response, and prevention capabilities, identify security gaps, and define remediation actions.
- Conduct Web Application Penetration Testing (WAPT) and infrastructure penetration testing activities to assess security posture, system hardening, configuration effectiveness,
and resilience against real-world attack techniques.
- Execute periodic Vulnerability Assessments on internal and external infrastructures to identify, validate, and prioritize security vulnerabilities.
- Track, monitor, and report identified vulnerabilities through the GOSP Vulnerability Management process, ensuring remediation activities are appropriately managed and verified.
- Analyze newly discovered vulnerabilities, CVEs, and zero-day threats collected from OSINT, CLOSINT, commercial threat intelligence sources, and AI-assisted intelligence platforms, assessing their potential impact on GOSP infrastructure and services.
- Leverage Generative AI and AI-powered cybersecurity solutions to accelerate threat intelligence analysis, vulnerability research, attack path identification, security assessments, and the production of technical reports and remediation recommendations.
- Support proactive threat hunting and attack surface monitoring activities by combining traditional security methodologies with AI-enhanced analytics and automation capabilities.
- Contribute to the continuous improvement of security testing methodologies, adversary emulation techniques, and cybersecurity processes aligned with evolving threat landscapes.
Requirements:
- Degree in Computer Science, IT Security, or equivalent work experience in Information Security.
- 2-5 years of experience in vulnerability assessment / penetration testing activities.
- Knowledge of Vulnerability Assessment, Penetration Testing, Red Teaming, and Vulnerability Management methodologies.
- Familiarity with security frameworks and standards such as OWASP, MITRE ATT&CK;, NIST, and CVSS.
- Knowledge of common vulnerability assessment tools (e.g: Qualys, Nessus, OpenVAS, NMAP)
- Knowledge of main penetration testing tools (e.g: Zap, Burp Suite, Metasploit, Wireshark, John The Ripper, SQLmap)
- Understanding of Threat Intelligence, OSINT techniques, and cyber threat analysis.
- Familiarity with AI/ML technologies, Security Copilots, LLMs, and AI-assisted cybersecurity platforms related to threat detection and vulnerability management.
- Strong analytical mindset, problem-solving skills, and ability to communicate technical findings to both technical and non-technical stakeholders.
- Good knowledge of IT networks, protocols, operating systems, web and application server architectures.
- Good knowledge of Microsoft Active Directory architecture.
- Good knowledge of one or more programming languages (e.g: Python, Power Shell, C/C++).
- Intermediate English proficiency (at least CEFR B1, written and spoken).
- Certifications such as CEH, OSCP, GPEN are a plus.
Soft Skills:
- Ability to work in team and to maintain deadlines on assigned tasks.
- Positive attitude and openness to learn on the job.
- Passion for offensive security.
- Proactive in identifying obstacles and problems that might impact daily activities.
- Capability to perform periodic reporting to management.
- Strong problem-solving capabilities.
- Willingness to cooperate with other teams within the organization.
We offer employment at the V level with the relevant salary, in accordance with the CCNL ANIA for non-executive employees and the Generali Group Company Agreement.
Gross annual salary ranging between 40K€ and 50K€. The final offer will be aligned with the candidate’s professional experience, technical and soft skills relevant to the role, and may include an individual variable component.
We also offer:
- Smart working and flexible hours.
- Corporate welfare system.
- Meal vouchers.
- Supplementary health insurance and discounted insurance policies.
- Well-being initiatives.
- Training and development opportunities.
- Structured continuous learning paths (technical and managerial).
- Career development programs within the Group.
- Access to learning platforms and internal mobility opportunities, including international assignments.
Essere Partner di Vita è la nostra ambizione: ogni giorno vogliamo essere al fianco dei nostri clienti prendendoci cura delle loro vite e dei loro sogni. Questo per noi è Più di un Lavoro.
Siamo parte di un importante Gruppo internazionale con oltre 82 mila persone in tutto il mondo e più di 68 milioni di clienti.
Siamo tra i principali player globali del settore assicurativo: l’innovazione e la sostenibilità sono nel nostro DNA.
Generali Italia è l’assicuratore più conosciuto in Italia con oltre Є28 miliardi di premi totali, 15 mila dipendenti e una rete capillare di 40 mila distributori, oltre ai canali online e di bancassurance. A Generali Italia fanno capo Alleanza Assicurazioni, Das, Genertel e Genertellife, Generali Welion, Generali Jeniot e Leone Alato, oltre alle attività della Business Unit Cattolica.
Il Gruppo Generali offre interessanti opportunità di arricchimento professionale in un contesto lavorativo caratterizzato da:
- Cultura aziendale solida e aperta, modi di lavorare innovativi, formazione e affiancamento a supporto di un inserimento efficace.
- Contesto di lavoro inclusivo in cui ognuno si sente accolto, libero di esprimere al meglio la propria identità, le proprie idee e le proprie capacità: perché siamo Più che diverse, Persone Uniche.
- Qualità dei processi e iniziative per le persone, che distinguono Generali come Top Employer.
[#LI-REMOTE] [#J-MCITY]
📌 Security Analyst - Vulnerability Analyst (Roma)
🏢 Generali Italia
📍 Roma