Security Analyst - Vulnerability Analyst
40.000 €Generali
As a Vulnerability Analyst and Penetration Tester, you will work closely with the Cyber Security Monitoring team to perform vulnerability assessments, penetration testing, red teaming activities, and security impact analyses related to emerging cyber threats, zero-day vulnerabilities, and advanced attack techniques.
The role also includes leveraging AI-driven cybersecurity solutions and Large Language Models (LLMs) to enhance information gathering, vulnerability analysis, attack surface monitoring, and the identification of indicators of compromise associated with evolving threat actors and attack campaigns.
Activities will include:
- Execution of periodic Vulnerability Assessments across both internal and external perimeters using enterprise-grade security platforms and automated assessment tools.
- Identification, validation, prioritization, and reporting of vulnerabilities to asset owners, with continuous tracking of remediation activities through the organization's Vulnerability Management platform.
- Execution of Web Application Penetration Tests (WAPT), infrastructure penetration tests, and Red Teaming exercises based on internally defined threat scenarios and intelligence-driven attack simulations.
- Collection and correlation of information from OSINT, CLOSINT, Threat Intelligence feeds, and AI-assisted research platforms to identify newly disclosed vulnerabilities, emerging threats, and zero-day exposures.
- Security impact assessment of new vulnerabilities and threat campaigns affecting the organization, including risk evaluation, remediation prioritization, and stakeholder communication.
- Utilization of AI and Machine Learning-based tools to support vulnerability triage, threat hunting, attack pattern analysis, anomaly detection, and proactive identification of emerging cyber risks.
MAIN TASKS
- Perform Red Teaming activities in collaboration with the GOSP CSIRT team, based on agreed cyber threat scenarios, to validate detection, response, and prevention capabilities, identify security gaps, and define remediation actions.
- Conduct Web Application Penetration Testing (WAPT) and infrastructure penetration testing activities to assess security posture, system hardening, configuration effectiveness, and resilience against real-world attack techniques.
- Execute periodic Vulnerability Assessments on internal and external infrastructures to identify, validate, and prioritize security vulnerabilities.
- Track, monitor, and report identified vulnerabilities through the GOSP Vulnerability Management process, ensuring remediation activities are appropriately managed and verified.
- Analyze newly discovered vulnerabilities, CVEs, and zero-day threats collected from OSINT, CLOSINT, commercial threat intelligence sources, and AI-assisted intelligence platforms, assessing their potential impact on GOSP infrastructure and services.
- Leverage Generative AI and AI-powered cybersecurity solutions to accelerate threat intelligence analysis, vulnerability research, attack path identification, security assessments, and the production of technical reports and remediation recommendations.
- Support proactive threat hunting and attack surface monitoring activities by combining traditional security methodologies with AI-enhanced analytics and automation capabilities.
- Contribute to the continuous improvement of security testing methodologies, adversary emulation techniques, and cybersecurity processes aligned with evolving threat landscapes.
Requirements
- Degree in Computer Science, IT Security, or equivalent work experience in Information Security.
- 2-5 years of experience in vulnerability assessment / penetration tests activities.
- Knowledge of Vulnerability Assessment, Penetration Testing, Red Teaming, and Vulnerability Management methodologies.
- Familiarity with security frameworks and standards such as OWASP, MITRE ATT&CK, NIST, and CVSS.
- Knowledge of the main market tools and processes to perform vulnerability assessments (e.g: Qualys, Nessus, OpenVAS, NMAP, etc).
- Knowledge on the main penetration testing tools available on the market (e.g: Zap, Burp suite, Metasploit, Wireshark, John The Ripper, SQLmap, etc).
- Understanding of Threat Intelligence, OSINT techniques, and cyber threat analysis.
- Familiarity with AI/ML technologies, Security Copilots, LLMs, and AI-assisted cybersecurity platforms applied to threat detection, vulnerability management, and security operations.
- Strong analytical mindset, problem-solving skills, and ability to communicate technical findings to both technical and non-technical stakeholders.
- Good knowledge of IT networks and protocols, Operating systems, web and application server architectures.
- Good knowledge of Microsoft Active Directory architecture and .
- Good knowledge of one or more programming languages (e.g: python, PowerShell, C/C++, etc)
- Intermediate English (at least CEFR B1, written/spoken)
- Availability of certificates is a plus (e.g., CEH, OSCP, GPEN, etc)
Soft Skills:
- Ability to work in team and to maintain deadlines on assigned tasks
- Positive attitude and open to learn on the job
- Passionate about offensive security
- Proactive in identifying obstacles and problems that might impact your daily activities
- Capability to perform periodical report to your manager
- Very good problem-solving capabilities
- Open to cooperation with other team within the organization
We offer employment at the V level with the relevant salary, in accordance with the CCNL ANIA for non-executive employees and the Generali Group Company Agreement.
Gross annual salary ranging between 40K€ and 50K€. The final offer will be aligned with the candidate’s professional experience, technical and soft skills relevant to the role, and may include an individual variable component.
We also offer
- Smart working and flexible hours
- Corporate welfare system
- Supplementary health insurance and discounted insurance policies
- Training and development
- Structured continuous learning paths (technical and managerial)
- Career development programs within the Group
- Access to learning platforms and internal mobility opportunities, including international
Company Profile
Joining Generali means becoming part of an international Group with a strong heritage and a forward-looking vision, where people are at the center of our sustainable growth strategy.
We foster a responsible, inclusive, and innovation-driven work environment, where everyone can contribute to creating value for customers, society, and the communities in which we operate. We believe that diversity, equity and inclusion are essential to building a stronger culture and driving sustainable growth.
At Generali, you will find opportunities to grow through continuous learning, career development paths, and internal mobility across the Group. We recognize talent and merit, and support flexibility as a key enabler of well-being and a sustainable work-life balance.
Working with us means sharing strong values and taking on meaningful challenges together to build a safer and more sustainable future every day.
As an Equal Opportunity Employer, Generali evaluates all applications based exclusively on objective and gender-neutral criteria, including skills, experience and potential, ensuring fairness and transparency throughout the selection process.
#J-18808-Ljbffr40.000 €
ppAs a Vulnerability Analyst and Penetration Tester, you will work closely with the Cyber Security Monitoring team to perform vulnerability assessments, penetration testing, red teaming activities, and security impact analyses related to emerging cyber threats, zero-day...ConsigliatoOrario flessibile- .../a Penetration Tester a Roma per unirsi al team di Offensive Security. Questa figura avrà la responsabilità di lavorare su progetti... ...critici come Finance e Aerospace, richiedendo competenze in Vulnerability Assessment e Penetration Testing. /ppCerchiamo professionisti...ConsigliatoOrario flessibile
- ...developing transformation strategies focused on security, efficiently integrate and manage new or... ...on client-facing projects mainly related to Vulnerability Assessment, Penetration Test, Mobile Security Assessment, Secure Code Review, Network Security Assessment, Red...Consigliato
- ...will join PwC Italy’s Ethical Hacking team to assess security across client systems, identify vulnerabilities, and support security-by-design deliverables. You... ...Collaborate with internal and client teams to deliver secure solutions Requisiti fondamentali ~4 years in a...Consigliato
- ...entrerai a far parte del team di Offensive Security di Capgemini Italia, dove avrai l’... ...competenze in almeno due ambiti tra: Vulnerability Assessment, Penetration Testing, Red Teaming... ....* Conosci a fondo le principali vulnerabilità delle applicazioni web (es. SQL...ConsigliatoImpiego permanenteOrario flessibile
- ...decennale in soluzioni e servizi nellambito dellInformation & Communication Technology, sta cercando per ampliamento organico: Security Analyst L1 Il candidato ideale ha almeno 2 anni di esperienza nel ruolo Competenze richieste obbligatorie: ~ Conoscenza...Lavoro ibridoRemotoTurno di notteTurni
- ...Clariter Group è alla ricerca di un SENIOR SECURITY ANALYST altamente qualificato, con una solida esperienza nel campo della cybersecurity, per rafforzare il nostro team di sicurezza IT. La figura sarà coinvolta nellidentificazione, analisi e gestione delle minacce informatiche...Remoto
- Un'azienda leader in cybersecurity, con sede a Roma, cerca un Security Intelligence Blue Team Specialist. Il candidato ideale avrà una laurea in discipline STEM e fino a 2 anni di esperienza in sicurezza informatica. Sarà responsabile dell'analisi e risposta a incidenti...
35.000 € - 45.000 €
La risorsa, inserita nel team SOC, si occuperà della gestione di incidenti di sicurezza complessi. Il ruolo è incentrato prevalentemente sulla gestione della piattaforma anti-DDoS Arbor (Netscout), che costituisce la parte preponderante dell'attività quotidiana. ...Impiego permanente- Sync Lab S.r.l. cerca un System Security Analyst SIEM a Roma. Sarai responsabile della gestione e ottimizzazione dei sistemi di sicurezza e dell'integrazione dei log IT. Offriamo un contratto a tempo indeterminato, formazione professionale, e retribuzione competitiva in...Impiego permanente
35.000 € - 45.000 €
ppLa risorsa, inserita nel team SOC, si occuperà della gestione di incidenti di sicurezza complessi. /ppIl ruolo è incentrato prevalentemente sulla gestione della piattaforma anti-DDoS Arbor (Netscout), che costituisce la parte preponderante dell'attività quotidiana. /ppbNello...Impiego permanente- ...tecnologiche ed innovative offrendo servizi per ICT Governance, ICT Security & GDPR Compliance. Siamo un'azienda certificata Great... ...di ticketing Competenze in ambito networking e vulnerability management Capacità di supporto nella gestione dei fornitori...Lavoro ibrido
- ...sicurezza e identificare punti deboli /li liIdentificare e sfruttare vulnerabilità, analizzare il codice, e comunicare i risultati in report... ...dell'inglese /li liCertificazioni come CEH, CISSP, CCNA Security /li liContratto a tempo indeterminato /li liPercorsi di formazione...Impiego permanente
- ...Ethical Hacking. Il candidato ideale svolgerà attività relative a Vulnerability Assessment, Penetration Test e Sicurezza del Codice.... ...progetti rivolti ai clienti, concentrandosi sulla scoperta di vulnerabilità di sicurezza su varie piattaforme e supportando i team di sviluppo...
- Battistolli Servizi Integrati cerca un Addetto/a al controllo accessi da impiegare presso la sede di Roma Zona Eur. La funzione include sorveglianza di beni e immobili, accoglienza e gestione degli accessi, con controllo e custodia secondo le direttive aziendali. La...Part-timeTempo determinatoDisponibilità immediata
- ...Applicativo che lavori per un importante cliente. La risorsa sarà responsabile dell'identificazione, valutazione e mitigazione delle vulnerabilità della sicurezza delle applicazioni, conducendo test di penetrazione e fornendo raccomandazioni per migliorare la resilienza...Lavoro ibrido
- ...fornituradi soluzioni su misura perclienti pubblici e privati. Leattività si articolano in tredivisioni operative: Safety& Security: servizi disicurezza e guardiania, controllo accessi,accoglienza, prevenzione incendi e primosoccorso; Facility:servizidi...Part-time35 h/sett.
- pDacomat srl cerca una risorsa junior nel ruolo di Junior Security Advisor. La posizione è ibrida, con sede di riferimento tra Roma, Milano, Torino, Bologna o Napoli, e presenza in Castelfidardo quattro giorni al mese. /ppSi richiede laurea STEM, conoscenze di base di...Stage/TirocinioLavoro ibrido
- ...il nostro team di bIT Cybersecurity /b un/una bInformation Security Analyst /b. /ph3Disponibilità a viaggiare /h3h3Tipologia Contratto... ...log di sistema e alla rilevazione di anomalie o potenziali vulnerabilità. /ppParteciperai all’implementazione e al miglioramento continuo...
- Transtec Services Srl , società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un Access Tester Specialist per una delle nostre aziende clienti. Requisiti: Esperienza nell’attività di test di accettazione su...
- pstrongTranstec Services Srl /strong, società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un strongAccess Tester Specialist /strong per una delle nostre aziende clienti. /p pstrongRequisiti: /strong /p ul liEsperienza...
- pGenerali is seeking a Vulnerability Analyst and Penetration Tester to join the Cyber Security Monitoring team in Italy. You will perform vulnerability assessments, penetration tests, red teaming exercises, and security impact analyses against evolving threats. /ppYou will...
- Transtec Services Srl, società di servizi e consulenza che opera nel settore ICT e dell’Innovazione tecnologica, è alla ricerca di un Access Tester Specialist per una delle nostre aziende clienti.Requisiti:Esperienza nell’attività di test di accettazione su OLT (FTTH/GPON...
- Overview In questo ruolo ti occupi di test di accettazione su reti FTTH/GPON e sistemi di gestione, con attività di rollout FTTH. Lavorerai in un contesto ICT orientato all’innovazione, collaborando con team multi-disciplinari e contribuendo a garantire qualità e affidabilità...
- ...strengthen digital identity and access management. The role focuses on ensuring proper user/device access, enforcing RBAC, and maintaining secure authentication across systems. /ppYou will support continuous improvement of ICT security posture in a fast-paced, humanitarian...
- pWorld Food Programme (WFP) is seeking a HRMOI Org Security Analyst (Consultant) to strengthen governance and alignment of Workday organizational data and security across HQ Rome and country offices. The role focuses on data quality, access controls, and system integrity...
- pWorld Food Programme recherche un analyste org. et sécurité HRMOI/HRM (Consultant) basé à Rome pour renforcer la gouvernance des données et la sécurité des systèmes RH au sein du bureau HRMOI/HRM. /ppLe candidat idéal possède une expérience avec Workday, une connaissance...
- ...Experis - Gruppo Manpower srl cerca un SOC Security Analyst L1/L2 da inserire in un Security Operations Center per una realtà internazionale nel pharma. Si richiede esperienza in SOC, analisi e gestione incidenti, conoscenza di Microsoft Sentinel/Defender, KQL e MITRE...Impiego permanenteSomministrazioneLavoro ibrido2 giorni/sett.
- ...World Food Programme in Rome, Italy, seeks an HRMOI Org & Security Analyst (Consultant) to strengthen data governance and security of HR organizational data in Workday and related systems. The role supports governance, audits, and data quality across HR processes....
- Fidelitas S.p.A. cerca un addetto/a alla sicurezza per presidiare l'accesso e gestire le persone in contesto aperto al pubblico, assicurando condizioni di sicurezza secondo le indicazioni del cliente. Il candidato ideale possiede esperienza nella sicurezza non armata...Part-timeImpiego permanente