Crea un profilo in modo da poter essere trovato dalle aziende, ottenere offerte di lavoro più adatte alle tue esigenze e candidarti più velocemente.
  • Cerca lavoro
  • Preferiti
  • Crea CV
    Novità
  • Stipendi
  • Iscrizioni

Vulnerability Governance Analyst, Italy

40.000 € - 50.000 €
Full time

ion

About us:

We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri companies, part of ION Group, we are looking for talented professionals to grow their career as Vulnerability Governance Analyst . This position is targeted at candidates with 2–5 years of relevant experience in Cybersecurity, Vulnerability Management, or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organization’s vulnerability governance framework and security posture.

Learn more at .


Your role

Your key duties and responsibilities

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments, ensuring compliance with established remediation targets and governance requirements.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services, impacted customers, remediation owners and urgency of action.
  • Prioritize vulnerabilities using a risk-based model that goes beyond technical severity, considering exploitability, evidence of active exploitation, CISA KEV/EPSS, Internet exposure, asset criticality, client impact and multi-tenant blast radius
  • Coordinate remediation plans and follow-up activities with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports.
  • Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
  • Contribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.


Other duties

We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required

  • Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)
  • At least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds.
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
  • Strong analytical, organizational, and stakeholder management skills.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus.

What we offer:

  • Permanent employment contract
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
  • Gross Annual Salary (RAL) ranging from €40,000 to €50,000 , depending on experience, skills, and qualifications
  • Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level
  • Opportunity to join a leading international technology group operating in the financial services industry
  • Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment

Location:

Milan.

Important notes:

According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.

Offerta di lavoro pubblicata 2 mesi fa
Offerte di lavoro simili
  •  ...Abbott Laboratories in Italy seeks a Market Access Specialist to help ensure patient access to Abbott's medical devices across Italy. You will monitor regulations, assess economic impact, and collaborate with Marketing and Clinical teams to support reimbursement pathways... 
    Consigliato

    Abbott Laboratories

    Milano
    2 giorni fa
  •  ...Overview In this role you help patients in Italy access Abbott's innovative medical technologies by shaping market access strategies and reimbursement pathways. You will analyze the Italian healthcare landscape and collaborate with cross-functional teams to communicate... 
    Consigliato

    Abbott

    Milano
    2 giorni fa
  • ph3About Abbott in Italy /h3 pAbbott is a global leader in healthcare, committed to helping people live their best lives at every stage. Across diagnostics, medical devices, nutrition, and branded generics, we design solutions that make a real impact. In Italy, we bring... 
    Consigliato
    Stage/Tirocinio

    Abbott Laboratories

    Milano
    2 giorni fa
  •  ...Overview As Market Access Specialist at Abbott Italy, you help ensure patient access to innovative medical technologies across divisions. You'll analyze regulations, craft value propositions, and support pricing and reimbursement decisions within the Italian healthcare... 
    Consigliato

    Abbott

    Milano
    2 giorni fa
  • pAbbott in Italia cerca un Market Access Specialist per supportare l'accesso a tecnologie mediche innovative. Il ruolo include monitoraggio regolatorio nazionale, analisi economiche e strumenti di costo per guidare le decisioni. /ppL'esperto collaborerà con Marketing, Clinica...
    Consigliato

    Abbott

    Milano
    2 giorni fa
  • Overview You join IQVIA to help reduce stroke-related disability by steering hospitals toward stroke-ready care. In this role you will support training and organizational tools, promote new guidelines, and lead quality monitoring across a regional network. You’ll guide...
    Tempo pieno
    Orario flessibile

    IQVIA

    Milano
    2 giorni fa
  • 37.000 € - 38.000 €

    ppEvery 30 minutes, a stroke patient who could have been saved either dies or is permanently disabled because they were treated in the wrong hospital. /p /brpbOur mission is clear: /b to increase the number of patients treated in stroke-ready hospitals and to optimize the...
    Part-time
    Tempo pieno
    Disponibilità immediata
    Orario flessibile

    IQVIA Argentina

    Milano
    9 ore fa
  • pSky Italia Srl is seeking a Penetration Tester to identify and validate security vulnerabilities across Sky Italy applications, systems, networks, and cloud environments. You will translate findings into actionable insights and work with teams to remediate risks in a... 
    Impiego permanente
    Lavoro ibrido
    Remoto

    Sky Italia Srl

    Milano
    10 ore fa
  • 40.000 €

     ...rely on. /li /ul pAs a Penetration Tester, you will be responsible for identifying, assessing, and validating security vulnerabilities in Sky Italy applications, systems, networks, and cloud environments. You will also play an active role in supporting the remediation... 
    Impiego permanente
    Stage/Tirocinio
    Remoto
    Orario flessibile

    Sky Italia Srl

    Milano
    9 ore fa
  • 40.000 €

     ...people can rely on. As a Penetration Tester, you will be responsible for identifying, assessing, and validating security vulnerabilities in Sky Italy applications, systems, networks, and cloud environments. You will also play an active role in supporting the remediation... 
    Impiego permanente
    Stage/Tirocinio
    Lavoro ibrido
    Remoto
    Orario flessibile

    Sky Italia Srl

    Milano
    2 giorni fa
  • 25.000 € - 32.000 €

     ...Per conto di una primaria società di consulenza operante nell'ambito della trasformazione digitale, della governance IT e della sicurezza informatica, siamo alla ricerca di uno/una Cyber Security Engineer_appartenente alle categorie protette da inserire all'interno... 
    Smart working

    W EXECUTIVE S.R.L.

    Milano
    29 giorni fa
  •  ...Penetration Test su applicazioni web, applicazioni client/mobile e reti aziendali (interne, esterne, wireless) per identificare vulnerabilità e fornire raccomandazioni di sicurezza; Utilizzo di strumenti e tecniche aggiornate per individuare vulnerabilità ;... 

    ManpowerGroup

    Milano
    2 giorni fa
  • AGM Solutions è alla ricerca di un Penetration Tester AI-powered per lavorare in modalità full remote dall'Italia, con laurea in discipline tecnico scientifiche e comprovata esperienza in test di penetrazione web/API. Richiesta conoscenza di OWASP WSTG, Burp Suite Professional...
    Remoto

    AGM Solutions

    Milano
    2 giorni fa
  •  ...IOT Cloud Sistemi di Trasmissione e Telecomunicazioni Cybersecurity: WAPT, VA, Digital Identity, DLP, Data Protection, Governance, Corporate Security Data Analysis, Data Engineering. Data Visualization Business Intelligence, Machine Learning Sistemi... 
    Tempo pieno
    Lavoro ibrido
    Disponibilità immediata
    Dal lunedì al venerdì
    40 h/sett.

    IDATA GROUP

    Milano
    9 ore fa
  •  ...BIP CyberSec cerca un Red Team Penetration Tester Expert per potenziare il RED team di Cyber Defense. Il candidato parlerà di vulnerabilità tecnologiche, di processo e delle persone, con focus su Web/Mobile/IoT, phishing e movimenti laterali. Si richiede laurea in informatica... 
    Remoto

    BIP

    Milano
    2 giorni fa
  •  ...AGM Solutions si occupa di studiare ed implementare soluzioni tecnologiche ed innovative offrendo servizi per ICT Governance, ICT Security & GDPR Compliance. Siamo alla ricerca, per un nostro cliente su Milano, di un* AI Penetration Tester , in modalità full remote... 
    Contratto con partita IVA
    Remoto

    AGM Solutions

    Milano
    2 giorni fa
  •  ...this role you will perform security testing across networks, mobile and web applications, and embedded/IoT products to identify vulnerabilities and simulate attacks. You will join Spike Reply's Cyber Security Team, serving national and international clients and... 
    Orario flessibile

    Reply

    Milano
    2 giorni fa
  •  ...clienti.ðAccetti la sfida?All’interno del Red Team di Cyber Defense, offriamo servizi di Vulnerability Management, Penetration Test e Red Team, volti ad identificare e testare vulnerabilità tecnologiche, di processo e delle persone (social engineering).Sarai tu ad entrare... 
    Remoto
    Orario flessibile

    Business Integration Partners

    Milano
    9 ore fa
  •  ...lavorando nel Red Team di Cyber Defense per identificare minacce e vulnerabilità. Collabori con team cross‐funzionali per migliorare la...  ...(RFID, lockpicking, NAC bypass) Attività occasionali di Vulnerability Assessment, Code Review e manutenzione dell'infrastruttura interna... 
    Remoto
    Orario flessibile

    Business Integration Partners

    Milano
    2 giorni fa
  •  ...minacce informatiche complesse. Lavorerai a contatto con un team specializzato in vulnerability management, penetration testing e red teaming, contribuendo a identificare vulnerabilità tecniche, di processo e umane. Fare parte di BIP CyberSec significa crescere professionalmente... 
    Remoto
    Orario flessibile

    Business Integration Partners

    Milano
    2 giorni fa
  • Overview In questo ruolo ti occupi di test di accettazione su reti FTTH/GPON e sistemi di gestione, con attività di rollout FTTH. Lavorerai in un contesto ICT orientato all’innovazione, collaborando con team multi-disciplinari e contribuendo a garantire qualità e affidabilità...

    Transtec Services

    Milano
    2 giorni fa
  • Transtec Services Srl, società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un Access Tester Specialist per una delle nostre aziende clienti.Requisiti:Esperienza nell’attività di test di accettazione su OLT (FTTH/GPON...

    Transtec Services

    Milano
    2 giorni fa
  • Transtec Services Srl , società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un Access Tester Specialist per una delle nostre aziende clienti. Requisiti: Esperienza nell’attività di test di accettazione su...

    Transtec Services Srl

    Milano
    2 giorni fa
  • pstrongTranstec Services Srl /strong, società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un strongAccess Tester Specialist /strong per una delle nostre aziende clienti. /p pstrongRequisiti: /strong /p ul liEsperienza...

    Transtec Services Srl

    Milano
    2 giorni fa
  • 35.000 € - 45.000 €

    Lutech cerca un Cyber Security Offensive Consultant da inserire nel team Cyber Security. L’opportunità prevede penetration testing su web, infrastrutture e app mobile, con uso di strumenti avanzati come Nmap, Burp Suite, Metasploit, OWASP ZAP e Nikto. Verrà data attenzione...
    Impiego permanente
    Lavoro ibrido

    Lutech

    Milano
    10 ore fa
  • ppRanked #1 for Safety, Quality and Patient Satisfaction, Jupiter Medical Center is the leading destination for world-class health care in Palm Beach County and the greater Treasure Coast. /ppOutstanding physicians, state-of-the-art facilities, innovative techniques and...
    Tempo pieno

    Jupiter Medical Center

    Milano
    2 giorni fa
  • A leading consulting firm in Milan is looking for a Penetration Tester Expert to engage in offensive security practices. The role involves conducting penetration tests on a variety of platforms and participating in red and purple teaming to bolster client security. Candidates...
    Smart working
    Remoto

    Accenture Italia

    Milano
    2 giorni fa
  • 18.808 €

    pFortinet is seeking a Systems Engineer - Mid-Enterprise in Italy to lead the technical aspects of the mid-enterprise sales cycle, align security solutions with customer needs, and drive opportunities to closure. /ppYou will partner with sales, deliver POCs, run workshops... 

    Zoomcar

    Milano
    2 giorni fa
  •  ...Quik Hire Staffing in Italy is seeking a Network Security Engineer for a full-time, remote-leaning hybrid role. You will design, implement, and maintain secure network infrastructure to protect against cyber threats. Responsibilities include monitoring traffic, analyzing... 
    Tempo pieno
    Lavoro ibrido
    Remoto

    Quik Hire Staffing

    Milano
    2 giorni fa
  •  ...with strong coding and DevOps discipline. /ppThe role includes hands-on work across REST APIs, database design, IaC, CI/CD, and system design, with a competitive salary in Milan and remote-from-Italy option. Equity offered for exceptional contributions. /p #J-18808-Ljbffr
    Remoto
    Orario flessibile

    TROPICO Security

    Milano
    2 giorni fa