Crea un profilo in modo da poter essere trovato dalle aziende, ottenere offerte di lavoro più adatte alle tue esigenze e candidarti più velocemente.
  • Cerca lavoro
  • Preferiti
  • Crea CV
    Novità
  • Stipendi
  • Iscrizioni

Vulnerability Governance Analyst, Italy

40.000 € - 50.000 €
Full time

ion

About us:

We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as Vulnerability Governance Analyst . This position is targeted at candidates with 2–5 years of relevant experience in Cybersecurity, Vulnerability Management, or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organization’s vulnerability governance framework and security posture.

Learn more at .


Your role

Your key duties and responsibilities

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments, ensuring compliance with established remediation targets and governance requirements.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services, impacted customers, remediation owners and urgency of action.
  • Prioritize vulnerabilities using a risk-based model that goes beyond technical severity, considering exploitability, evidence of active exploitation, CISA KEV/EPSS, Internet exposure, asset criticality, client impact and multi-tenant blast radius
  • Coordinate remediation plans and follow-up activities with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports.
  • Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
  • Contribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.


Other duties

We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required

  • Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)
  • At least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds.
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
  • Strong analytical, organizational, and stakeholder management skills.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus.

What we offer:

  • Permanent employment contract
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
  • Gross Annual Salary (RAL) ranging from €40,000 to €50,000 , depending on experience, skills, and qualifications
  • Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level
  • Opportunity to join a leading international technology group operating in the financial services industry
  • Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment

Location:

Milan.

Important notes:

According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.

Offerta di lavoro pubblicata 15 ore fa
Offerte di lavoro simili
  • 45.000 € - 55.000 €

    Istituto Gentili è un’azienda biofarmaceutica italiana con un focus nella commercializzazione di molecole innovative in ambito oncologico, delle malattie rare e del dolore, con l’obiettivo di contribuire concretamente al percorso di cura del paziente attraverso soluzioni...
    Consigliato
    Impiego permanente

    Pharma Point Srl

    Milano
    28 giorni fa
  •  ...social responsibility project. To help lead this change, we're looking for a passionate Consultants to join our team in North Italy. Territory to cover: Lombardia, Valle D'Aosta, Liguria, Piemonte. Responsibilities: After comprehensive and ongoing training... 
    Consigliato
    Tempo pieno
    Orario flessibile

    IQVIA

    Milano
    10 giorni fa
  •  ...Nevis (Nevis Identity Suite/Nevis Security Suite) . La posizione è fortemente orientata ad attività di analisi, troubleshooting e governance della soluzione CIAM (Customer Identity & Access Management) in contesti Enterprise complessi. Principali attività -... 
    Consigliato
    Tempo pieno
    Remoto

    HERZUM

    Milano
    un mese fa
  •  ...di server on-premise -capacità di analisi e gestione delle vulnerabilità con valutazione degli impatti su sistemi e applicativi...  ...upgrade -conoscenza di best practice di security (hardening, vulnerability assessment, risk analysis) -gradite certificazioni in ambito... 
    Consigliato
    Tempo pieno
    Libero professionista
    Contratto con partita IVA
    Lavoro ibrido
    Remoto

    SICIS

    Milano
    un mese fa
  • 45.000 € - 50.000 €

    Senior Network Security Engineer Proteggi infrastrutture critiche e garantisci la sicurezza di ambienti complessi! Hai esperienza nella gestione di infrastrutture di rete e sicurezza in contesti enterprise e vuoi lavorare su progetti ad alta criticità? Continua a ...
    Consigliato
    Impiego permanente

    Var Group

    Milano
    un mese fa
  • 27.000 € - 32.000 €

     ...Some experience and background in the following is a plus: Vulnerability and penetration testing Knowledge of automation tools (e.g....  ...collaborate, and celebrate together. Location : Milan or Padua (Italy), with a hybrid working model. The selection process... 
    Stage/Tirocinio
    Lavoro ibrido
    Orario flessibile

    Moviri SpA

    Milano
    un mese fa
  • 30.000 € - 45.000 €

    MC Engineering è una dinamica società di consulenza informatica , con sedi a Torino, Milano, Roma e Bari. Lavoriamo a stretto contatto con realtà innovative nel mondo ICT, portando avanti progetti che spaziano tra vari settori. Per noi, le persone sono al centro di ...
    Lavoro ibrido

    M.C. Engineering Srl

    Milano
    22 giorni fa
  •  ...administration across network devices, firewalls, and Linux operating systems. Executing security checks, technical reviews, and vulnerability follow-up, implementing or coordinating remediation actions with infrastructure teams. Contributing to the configuration... 
    Impiego permanente
    Lavoro ibrido
    Disponibilità immediata
    Lavoro da casa
    Permesso di lavoro
    Orario flessibile

    Etinars

    Milano
    2 mesi fa
  • KA Resources Recruitment sta cercando, per conto di un System Integrator, un Infrastructure Network & Security Engineer. L’azienda é attiva da oltre 30 anni e ha sede a Sesto San Giovanni. Non si accettano candidature di Freelancer, la persona verrá contrattata come...
    Smart working
    Tempo pieno
    Impiego permanente
    Libero professionista
    Auto aziendale

    KA Resources

    Sesto San Giovanni (MI)
    6 giorni fa
  •  ...across network devices, firewalls, and operating systems (Windows/Linux). Executing security checks, technical reviews and vulnerability follow-up, implementing or coordinating remediation actions with infrastructure teams. Contributing to the configuration and... 
    Lavoro ibrido
    Disponibilità immediata
    Lavoro da casa
    Permesso di lavoro
    Orario flessibile

    Etinars

    Milano
    2 mesi fa
  • 40.000 € - 42.000 €

     ...approfondita di: o Container Security o Cloud Security ( AWS, Azure ) o API Security o Sicurezza Open Source · Esperienza nella vulnerability remediation e gestione della sicurezza in ambienti di sviluppo come GitHub. · Conoscenza di strumenti di automazione e... 
    Tempo pieno
    Contratto con partita IVA
    Disponibilità immediata
    Remoto

    Vibe SRL

    Milano
    un mese fa