Global Cybersecurity Specialist
Amplifon
Penetration testing & assessment — plan and perform penetration tests and security assessments on web and mobile applications, internal systems and internet-facing infrastructure, identifying vulnerabilities, misconfigurations and exposure (e.g. unmanaged accounts, weak authentication, unnecessary services, exposed personal data).
Remediation ownership — produce clear, risk-based reports and drive remediation with system, application and infrastructure owners through to closure, then re-test to confirm fixes are effective.
Controlled validation — support authorized, red-team-style validation activities (e.g. credential/dump validation, lateral-movement checks) to confirm real-world exploitability.
Lifecycle management — run and continuously mature the vulnerability management lifecycle: discovery, triage, prioritization, remediation tracking and verification.
Strategy — collaborate in the development and execution of robust vulnerability management strategies across the global estate.
Platform operations — operate, configure and tune security consoles and platforms across endpoint, network and identity — for example EDR (e.g. SentinelOne), endpoint and patch management (e.g. Ivanti) and network security / firewalls (e.g. Cisco ASA) — ensuring compliance with company policies and industry best practice.
Access & credential hygiene — strengthen access and credential hygiene on shared and critical systems (account reviews, deprovisioning of stale users, credential rotation, reduction of data exposure).
Detection & response — contribute to security monitoring and to the detection, analysis, containment and recovery phases of security incidents, working alongside the SOC and specialized external partners (e.g. threat-intelligence and incident-response providers).
Post-incident hardening — support lessons-learned and hardening activities to reduce the likelihood and impact of recurrence.
ISMS & regulation — contribute to the Information Security Management System (ISO/IEC 27001), information security risk assessments and regulatory alignment (e.g. NIS2), keeping security practices consistent with company policies.
Asset lifecycle & KPIs — support asset life-cycle management and endpoint standardization initiatives using digital tools, and identify and track KPIs relevant to a secure, well-governed asset and vulnerability portfolio.
Supplier management — oversee the engagement and management of external suppliers and partners (penetration testing, vulnerability and security services), managing scope, quality and delivery against organizational expectations.
Bachelor’s degree in a STEM field with a focus on cybersecurity or a related discipline — or equivalent hands-on experience.
Solid understanding of penetration testing tools and methodologies (network and web/mobile application testing; familiarity with frameworks such as OWASP).
Working knowledge of vulnerability management, security assessment techniques and common attack techniques (e.g. authentication weaknesses, credential attacks such as pass-the-hash, lateral movement).
Experience with security platforms across endpoint, network and identity (e.g. EDR, endpoint/patch management, firewalls).
Awareness of information security frameworks and regulations (e.g. ISO/IEC 27001, NIS2, GDPR / personal-data protection).
Proactive mindset, dedicated to continuous improvement and adept at navigating transformational initiatives.
Strong problem-solving skills with a meticulous, process-oriented approach.
Ability to thrive in a dynamic, fast-paced, multi-country environment while managing multiple priorities concurrently.
Exceptional communication skills and a collaborative, team-oriented attitude.
Fluency in English is mandatory.
Industry certifications such as OSCP, CEH, GIAC, CompTIA Security+ or equivalent.
Scripting and automation skills (e.g. Python, PowerShell, Bash).
Exposure to cloud security (Azure / AWS / GCP) and Active Directory security.
Prior experience in complex IT projects or within high-growth, multi-country contexts.
Working proficiency in Italian is a plus for our Milan
-based Global IT team.
- €750 Annual Welfare plan for your personal well-being across a wide range of services
- Health Insurance: Fondo Est healthcare coverage + an additional Accident Insurance
- Supplementary pension scheme: option to enrol in the Fondo Fon.Te with employer contributions
- Office Perks: On-site canteen and free company parking
- BeWellProgram: Free access to learning platforms and training programs. We invest in your growth through ongoing learning opportunities, while also offering special corporate discounts, dedicated services for you and your loved ones, and initiatives focused on your wellbeing and physical health