Назад
Company hidden
5 часов назад

Vulnerability Governance Analyst (Cybersecurity)

40 000 - 50 000
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Italy
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Governance Analyst (Cybersecurity): Strengthening enterprise vulnerability governance across infrastructure, cloud, endpoint, and application environments with an accent on risk-based prioritization, remediation oversight, and regulatory compliance. Focus on correlating vulnerability intelligence with CMDB, BIA, SBOM/SCA, and ownership data, managing risk exceptions, and producing executive security reporting.

Location: Milan, Italy; hybrid workplace

Gross annual salary: €40,000–€50,000, depending on experience, skills, and qualifications.

Company

hirify.global provides workflow and process automation software, real-time data, business intelligence, and consultancy services for financial institutions, trading firms, central banks, governments, and corporations.

What you will do

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor remediation activities across infrastructure, cloud, endpoint, and application environments against defined targets.
  • Perform risk-based vulnerability analysis using exploitability, asset criticality, exposure, business impact, threat intelligence, CISA KEV, and EPSS.
  • Correlate vulnerability data with CMDB, BIA, SBOM/SCA, and application ownership information to identify affected services, customers, owners, and urgency.
  • Coordinate remediation plans, exceptions, compensating controls, and risk acceptance with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Maintain vulnerability dashboards, KPIs, operational metrics, executive reports, and support critical vulnerability escalations, audits, and regulatory assessments.

Requirements

  • Master’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field.
  • 2–5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or a related area.
  • Understanding of vulnerability lifecycle management, remediation processes, exposure management, vulnerability assessment platforms, and reporting solutions.
  • Knowledge of CVSS, EPSS, CISA KEV, exploit intelligence, threat intelligence feeds, SBOMs, SCA, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Excellent knowledge of Italian and English is required. Strong analytical, organizational, communication, and stakeholder management skills are expected.

Nice to have

  • Security+, CySA+, CISSP, ISO 27001, or equivalent certification.

Culture & Benefits

  • Permanent employment contract.
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
  • Work within an international technology group serving the financial services industry.
  • Exposure to enterprise-scale cybersecurity governance in a dynamic, international environment.
  • Candidates belonging to the protected categories list under Italian Law L.68/99 receive priority.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →