Vulnerability Governance Analyst, Italy
IonItalyFull-time (hybrid)6d ago
SecurityDevSecOpsComplianceOperationsSupportAnalystSolutionsCommunityExecutiveEngineeringInfrastructureAutomation
Job description
Vulnerability Governance Analyst, Italy at Ion.
About the role
This position involves enhancing the Chief Information Security Office function within Cedacri, part of the ION Group. You will contribute to strengthening the organization's vulnerability governance framework and overall security posture. This role is ideal for professionals with 2-5 years of experience in cybersecurity, vulnerability management, or information security governance.
Key facts
What you'll do
- Support the ongoing improvement of the enterprise Vulnerability Management program.
- Oversee vulnerability remediation across various environments like infrastructure, cloud, and applications, ensuring compliance with targets.
- Conduct risk-based vulnerability analysis, considering factors like exploitability, asset importance, and business impact.
- Connect vulnerability data with configuration management, business impact analysis, and software bill of materials to identify affected services and remediation urgency.
- Prioritize vulnerabilities using a risk model that considers active exploitation, CISA KEV, and internet exposure.
- Coordinate remediation plans and follow-up with various technical and risk teams.
- Manage exceptions, compensating controls, and risk acceptance processes for vulnerabilities.
- Create and maintain dashboards, key performance indicators, and reports for vulnerability management.
- Assist with the escalation and governance of critical vulnerabilities and high-risk situations.
- Help define and refine vulnerability management policies, standards, and governance processes.
- Support audits, regulatory assessments, and compliance related to cyber risk and vulnerability management.
Requirements
- Master's degree (with honors) in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field.
- 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, or Security Governance.
- Understanding of vulnerability lifecycle management, remediation, and exposure management.
- Familiarity with vulnerability assessment platforms and reporting tools.
- Knowledge of vulnerability prioritization methods and industry standards like CVSS, EPSS, and CISA KEV.
- Familiarity with software supply chain security, SBOMs, SCA, and DevSecOps.
- Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements for vulnerability and ICT risk management.
- Ability to communicate technical findings through clear, risk-focused reports and executive summaries.
- Strong analytical, organizational, and stakeholder management abilities.
- Excellent command of both Italian and English.
Nice to have
- Relevant certifications such as Security+, CySA+, CISSP, or ISO 27001.
Skills & tools
- Vulnerability Management platforms
- Reporting solutions
- CMDB
- BIA
- SBOM/SCA
- CVSS
- EPSS
- CISA KEV
- Exploit intelligence
- Threat intelligence feeds
- ISO 27001
- NIST CSF
- CIS Controls
- DORA
- NIS2
Practical notes
- This is a permanent employment contract under the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
- The Gross Annual Salary (RAL) ranges from €40,000 to €50,000, depending on experience and qualifications.
- The job grade will be determined between B2 and B3 level after the selection process.
- Priority will be given to candidates belonging to protected categories as per Italian Law (L.68/99).