5 часов назад
Vulnerability Governance Analyst (Cybersecurity)
40 000 - 50 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Vulnerability Governance Analyst (Cybersecurity): Strengthening enterprise vulnerability governance across infrastructure, cloud, endpoint, and application environments with an accent on risk-based prioritization, remediation oversight, and regulatory compliance. Focus on correlating vulnerability intelligence with CMDB, BIA, SBOM/SCA, and ownership data, managing risk exceptions, and producing executive security reporting.
Location: Milan, Italy; hybrid workplace
Gross annual salary: €40,000–€50,000, depending on experience, skills, and qualifications.
Company
provides workflow and process automation software, real-time data, business intelligence, and consultancy services for financial institutions, trading firms, central banks, governments, and corporations.
What you will do
- Support the governance and continuous improvement of the enterprise Vulnerability Management program.
- Monitor remediation activities across infrastructure, cloud, endpoint, and application environments against defined targets.
- Perform risk-based vulnerability analysis using exploitability, asset criticality, exposure, business impact, threat intelligence, CISA KEV, and EPSS.
- Correlate vulnerability data with CMDB, BIA, SBOM/SCA, and application ownership information to identify affected services, customers, owners, and urgency.
- Coordinate remediation plans, exceptions, compensating controls, and risk acceptance with Infrastructure, Cloud, Development, Application Security, and Risk teams.
- Maintain vulnerability dashboards, KPIs, operational metrics, executive reports, and support critical vulnerability escalations, audits, and regulatory assessments.
Requirements
- Master’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field.
- 2–5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or a related area.
- Understanding of vulnerability lifecycle management, remediation processes, exposure management, vulnerability assessment platforms, and reporting solutions.
- Knowledge of CVSS, EPSS, CISA KEV, exploit intelligence, threat intelligence feeds, SBOMs, SCA, and DevSecOps environments.
- Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
- Excellent knowledge of Italian and English is required. Strong analytical, organizational, communication, and stakeholder management skills are expected.
Nice to have
- Security+, CySA+, CISSP, ISO 27001, or equivalent certification.
Culture & Benefits
- Permanent employment contract.
- Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
- Work within an international technology group serving the financial services industry.
- Exposure to enterprise-scale cybersecurity governance in a dynamic, international environment.
- Candidates belonging to the protected categories list under Italian Law L.68/99 receive priority.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 часов назад
Junior Offensive Security Engineer
38 000 - 54 000€
10 часов назад
Senior Security Incident Response Analyst (Fintech)
5 часов назад
Senior Internal IT Auditor (FinTech)
19 часов назад
Technical Account Manager (Cybersecurity)
6 дней назад
Cloud & AI Security Architect
12 часов назад