Talent.com
Fineco Bank
Cybersecurity Incident Response LeadFineco Bank • Turbigo, Italy
Cybersecurity Incident Response Lead

Cybersecurity Incident Response Lead

Fineco Bank • Turbigo, Italy
3 giorni fa
Descrizione dell’offerta di lavoro

Fineco Bank is a leading European bank with 20 years of history and a fully digital, branchless approach. We offer a wide range of products including trading, investment and payment services, a proprietary trading/investment platform, and banking solutions for domestic and international demand.



È questo il ruolo che sta cercando? Se sì, continui a leggere per maggiori dettagli e si ricordi di candidarsi oggi stesso.
Position

We are looking for a Cybersecurity Incident Response Lead to join the ICT & Cybersecurity department. This role heads the end‑to‑end IR program, leads incident response coordination, and provides clear status to management. The lead works closely with SOC, technical teams, and governance functions, orchestrating contributions from teams not directly reporting to Cybersecurity.


The role is not SOC shift management nor purely forensic or compliance. The focus is coordinating incident response, maturing the IR program, orchestrating involved technical teams, and turning cyber events into operational decisions, manager communication, and audit‑ready evidence.


Principali Attività


  • Guide operational coordination of security incident response: triage, containment priority, reconstruct initial vector, kill chain, propagation, blast radius, and coordination of eradication and recovery with owner teams.
  • Maintain an operational timeline and structured decision log during incidents, tracking hypotheses, containment decisions, owners, available evidence, and residual risks.
  • Build, maintain, and test the IR program: playbook, runbook, escalation procedures, roles and responsibilities, incident classification criteria, and continuous improvement mechanisms.
  • Contribute to the evolution of detection and response capabilities, defining requirements with the SOC based on real incidents, tabletop exercises, threat intelligence, and improving SIEM/SOAR/EDR/XDR workflows.
  • Integrate threat intelligence into the IR cycle: translate indicators of compromise, TTPs and threat scenarios into concrete detection, hunting, containment, and hardening actions.
  • Conduct structured post‑incident reviews: root‑cause analysis, impact measurement, lessons learned, remediation roadmap, and follow‑up with technical teams and management.
  • Plan and lead periodic exercises: tabletop, crisis simulations, collaborative sessions with SOC, red team, blue team to test program maturity, quality of escalations, and operational readiness.
  • Support governance functions with incident classification for regulatory purposes, evidence collection, timeline reconstruction, and presentation of technical elements for escalation or formal notifications.
  • Produce technical reports and executive summaries during and after incidents, ensuring clear, timely, and consistent communication to management, governance, and operational teams.


Requirements


  • At least 7 years of experience in incident response, security operations, or cyber crisis management with demonstrable operational coordination in complex enterprise environments.
  • Proficiency with key IR frameworks: ISO/IEC 27035, SANS IR Process, NIST SP 800‑61 or equivalents; use MITRE ATT&CK for TTP analysis, gap detection, and control improvement.
  • Hands‑on experience with SIEM, EDR/XDR enterprise, forensic analysis tools, and incident handling workflows.
  • Strong knowledge of networks, protocols, system/application logs, and traffic analysis techniques to reconstruct attack vectors, lateral movement, privilege escalation, and persistence.
  • Scripting and automation skills, preferably Python, to support triage, enrichment, evidence collection, repetitive task automation, and workflow customization.
  • Understanding of attack surfaces in hybrid on‑prem/cloud environments, native AWS/Azure logs, cloud identity, container workloads, propagation scenarios, and containment techniques.
  • Ability to make containment decisions with incomplete information, under time pressure, and with potential impact on service, business, and operational continuity.
  • Capability to communicate the same incident across audiences: technical between SOC and infrastructure/app teams; concise, risk‑based, decision‑oriented to management and governance.
  • Ability to orchestrate teams not hierarchically reporting to Cybersecurity, leveraging process, technical authority, clarity of priorities, and communication quality.
  • Excellent command of English.


Gradite


  • Certifications: GCIH, GCFE, GCIA (GIAC) or similar.
  • Deep knowledge of Windows/Linux enterprise, Active Directory (useful for lateral movement and privilege escalation investigations).
  • Experience in banking or regulated financial services.
  • Exposure to threat intelligence platforms (MISP, OpenCTI) and proactive threat hunting techniques.
  • Experience managing major incidents, cyber crisis exercises, or war room operations in regulated contexts.
  • Familiarity with classification, escalation, and regulatory reporting processes for ICT/cyber incidents in finance.


Other Information


  • High visibility role on mission‑critical infrastructure: proprietary platform, core banking, and brokerage used by 1.8 million customers in real time.
  • Hybrid technical environment of real complexity on‑prem/cloud where incidents have direct business impact.
  • Exposure to structured regulatory processes (DORA).
  • Direct responsibility on a substantial perimeter within ICT & Cyber, strategic weight for the bank.
  • High‑profile technical team, problem‑solving culture.


Sede di lavoro

Milano (alternating on‑site presence and smart working). xysqume


Il Gruppo Fineco is proud to be an Equal Opportunity Employer and is committed to creating a safe and inclusive workplace based on mutual respect and diversity, offering equal job opportunities. Fineco “The Place To Be”.


#J-18808-Ljbffr

Creare un avviso di lavoro per questa ricerca

Cybersecurity Incident Response Lead • Turbigo, Italy

Offerte simili

Hybrid: Post-Acquisition Integration Lead

CorsicefNovara, piemonte, Italy

Corsicef a Milano ricerca un Integration Manager per guidare l'integrazione delle nuove filiali nel proprio ecosistema aziendale.La figura avrà responsabilità nella pianificazione e monitoraggio de... Mostra di più

 • In evidenza

Digital Tech Lead

EatalyTurbigo, lombardia, Italy

Siamo un gruppo unito e curioso che ama mettersi in gioco.Collaboriamo in vista di un obiettivo comune, in un ambiente dinamico e stimolante.Crediamo nelle nostre persone, dando valore ai percorsi ... Mostra di più

 • In evidenza

Automotive Cybersecurity Engineer

Capgemini Engineeringturbigo, lombardia, Italy

In strongCapgemini Engineering /strong, leader mondiale nei servizi di ingegneria, uniamo un team globale di talenti dell’ingegneria, scienza e architettura per aiutare le aziende più innovative de... Mostra di più

 • In evidenza

InfoSec Specialist: Firewall, SIEM & Remediation

Smartedge Solutionsturbigo, lombardia, Italy

A technology company is seeking an Information Security Specialist to manage security activities and remediation efforts in Europe.You will collaborate with IT and InfoSec to enhance IT security ac... Mostra di più

 • In evidenza

Cybersecurity - IAM Engineer - Senior Associate - Milano [OTS]

PwC Italyturbigo, lombardia, Italy

Siamo alla ricerca di un/una Cybersecurity Senior Associate con focus su Identity Access Management (IAM) da inserire all’interno del nostro team Cyber.La risorsa contribuirà alla progettazione, i... Mostra di più

 • In evidenza

Cybersecurity Solutions Sales Specialist — Hybrid

NTT DATA Europe & Latamturbigo, lombardia, Italy

NTT DATA Europe Latam in Lombardia cerca un Sales Specialist in ambito Cybersecurity con forte spirito commerciale e passione per la tecnologia.Cerchiamo una figura capace di coniugare consulenza ... Mostra di più

 • In evidenza

Cybersecurity Sales Specialist

NTT DATA Europe & Latamturbigo, lombardia, Italy

Cerchiamo un bSales Specialist in ambito Cybersecurity /b! /p pLa risorsa cercata è un/a professionista con forte spirito commerciale e passione per la tecnologia, capace di coniugare competenze co... Mostra di più

 • In evidenza

Cybersecurity Incident Response Lead

Fineco BankTurbigo, lombardia, Italy

Fineco Bank is a leading European bank with 20 years of history and a fully digital, branchless approach.We offer a wide range of products including trading, investment and payment services, a prop... Mostra di più

 • In evidenza

Senior Risk Manager: 3LoD Risk & Controls Lead

Scope Ratingturbigo, lombardia, Italy

A leading credit rating agency based in Milan is seeking a Risk Manager to oversee non-financial risk management.You will help design risk frameworks and support senior management in mitigating ris... Mostra di più

 • In evidenza

Cyber Security Engineer/ Log Management - TELECOMMUNICATION

ALTEN Italiaturbigo, lombardia, Italy

Luogo: /b Milano (ibrido) /ppALTEN supporta le strategie di sviluppo dei propri clienti nelle aree dell’innovazione, della RD e dei sistemi informativi tecnologici.Nato più di 30 anni fa e presente... Mostra di più

 • In evidenza

IT Security & Compliance Leader: Risk & Incident Response

The Adecco Groupturbigo, lombardia, Italy

A global leader in workforce solutions is seeking an IT Security Compliance Manager to oversee IT security governance and ensure compliance with corporate standards and legal regulations.This role... Mostra di più

 • In evidenza

Security Analyst L1 – SOC Monitoring & Incident Response

Tinexta Cyberturbigo, lombardia, Italy

Un'azienda nel settore della cybersecurity cerca un Security Analyst L1 per monitorare e rispondere a eventi di sicurezza.Il candidato ideale ha 2-3 anni di esperienza in un SOC, una laurea in Info... Mostra di più

 • In evidenza

Tech Lead to CTO: Platform Architect & Leader

ChallengingTurbigo, lombardia, Italy

Una società di consulenza IT cerca un/a Tech Lead Full Stack con almeno 10 anni di esperienza, in particolare con solidi background in sviluppo software.La figura lavorerà in un contesto ibrido, in... Mostra di più

 • In evidenza

Datacenter Security Operations Lead

Rangers BattistolliTurbigo, lombardia, Italy

Rangers Battistolli is seeking a motivated Site Security Manager to lead operations at our client datacenter in Turbigo, Italy.The role involves managing a dedicated team, ensuring compliance with ... Mostra di più

 • In evidenza

Cybersecurity Threat Intelligence Specialist - EU Institution

Leonardo BelgiumIspra, lombardia, Italy

Cybersecurity Threat Intelligence Specialist.You will join a newly established, cross‑functional cybersecurity team focused on assessing and mitigating risks related to.This role sits at the inters... Mostra di più

 • In evidenza

Senior Cyber Threat Hunter ML-Driven Defense

Intesa SanpaoloTurbigo, lombardia, Italy

Una banca internazionale è alla ricerca di un Cyber Threat Hunter Expert per il team di Cyber Threat Hunting.Il candidato sarà responsabile della conduzione di attività di Threat Hunting, analisi f... Mostra di più

 • In evidenza

Cybersecurity Health & Public Executive

Accenture ItaliaTurbigo, lombardia, Italy

In Accenture, potrai portare la tua visione innovativa per reinventare interi settori di mercato, lavorando con le aziende più importanti a livello mondiale.Modella il futuro del business e della t... Mostra di più

 • In evidenza

InfoSec Security Operations Lead – Milan (On-site)

Insight International (UK) Ltdturbigo, lombardia, Italy

A leading international security firm in Turbigo, Italy, is looking for a candidate to manage InfoSec activities and coordinate remediation across Europe.The ideal candidate possesses strong commun... Mostra di più

 • In evidenza

Cyber Security & Resilience Consultant

Siaturbigo, lombardia, Italy

Descrizione del lavoro /h3 pSia is a next-generation, global management consulting group.Founded in 1999, we were born digital.Today our strategy and management capabilities are augmented by data s... Mostra di più

 • In evidenza

Security Consultant – Technical Security Assessment (NIS2, DORA, ISO 27001)

NG SECURITY ITALYsomma lombardo, lombardia, Italy

Siamo una società specializzata in cybersecurity, governance e compliance, che supporta organizzazioni pubbliche e private nell’adeguamento normativo e nel rafforzamento della postura di sicurezza.... Mostra di più