Talent.com
ION
Vulnerability Governance Analyst, ItalyION • Milan
Vulnerability Governance Analyst, Italy

Vulnerability Governance Analyst, Italy

ION • Milan
Più di 30 giorni fa
Descrizione dell’offerta di lavoro

About us:

We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as Vulnerability Governance Analyst. This position is targeted at candidates with 2–5 years of relevant experience in Cybersecurity, Vulnerability Management, or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organization’s vulnerability governance framework and security posture.

Learn more at .


Your role

Your key duties and responsibilities

  • Support the governance and continuous improvement of the enterprise Vulnerability Management program.
  • Monitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments, ensuring compliance with established remediation targets and governance requirements.
  • Perform risk-based vulnerability analysis considering exploitability, asset criticality, exposure, business impact, and threat intelligence.
  • Correlate vulnerability intelligence with CMDB, BIA, SBOM/SCA and application ownership data to identify exposed services, impacted customers, remediation owners and urgency of action.
  • Prioritize vulnerabilities using a risk-based model that goes beyond technical severity, considering exploitability, evidence of active exploitation, CISA KEV/EPSS, Internet exposure, asset criticality, client impact and multi-tenant blast radius
  • Coordinate remediation plans and follow-up activities with Infrastructure, Cloud, Development, Application Security, and Risk teams.
  • Manage remediation exceptions, compensating controls, and risk acceptance processes.
  • Develop and maintain vulnerability dashboards, KPIs, operational metrics, and executive reports.
  • Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
  • Contribute to the definition and continuous improvement of vulnerability management policies, standards, and governance processes.
  • Support audits, regulatory assessments, and compliance activities related to cyber risk and vulnerability management.


Other duties

We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required

  • Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)
  • At least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas.
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices.
  • Familiarity with vulnerability assessment platforms and reporting solutions.
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds.
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments.
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management.
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
  • Strong analytical, organizational, and stakeholder management skills.
  • Excellent knowledge of Italian and English.
  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent would be considered a plus.

What we offer:

  • Permanent employment contract
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
  • Gross Annual Salary (RAL) ranging from €40,000 to €50,000, depending on experience, skills, and qualifications
  • Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level
  • Opportunity to join a leading international technology group operating in the financial services industry
  • Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment

Creare un avviso di lavoro per questa ricerca

Vulnerability Governance Analyst, Italy • Milan

Offerte simili

Categorie Protette - Junior Cyber Security Analyst

DeloitteMilano - Italy

Questa posizione è in Deloitte.Riassunto dell'opportunità da parte della.Informatica, Ingegneria Informatica o materie STEM.La risorsa lavorerà in modalità hybrid, collaborando con team senior per ... Mostra di più

 • In evidenza

Cyber Protection – Data & AI Security Expert

AccentureMilano - Italy

Questa posizione è in Accenture.Riassunto dell'opportunità da parte della.I candidati lavoreranno con tecnologie innovative per sviluppare soluzioni di protezione dati e definire strategie all’avan... Mostra di più

 • In evidenza

Italian Content Trust & Safety Analyst (Lisbon/Porto)

Cross Border TalentsBresso, lombardia, Italy

Cross Border Talents is seeking an Italian-speaking Content Reviewer to join our international team in Lisbon.This role involves reviewing legal and compliance-related content across social media p... Mostra di più

 • In evidenza

SOC Analyst L2 - L3

Michael Page International Italia S.r.l.Milano, lombardia, Italy

Percorso di crescita con certificazioni.Azienda leader nei servizi di cybersecurity gestiti, con un Security Operation Center di livello enterprise che fornisce monitoraggio H24, incident response ... Mostra di più

 • In evidenza

Senior IAM CyberArk Engineer — Identity Security Leader

DGSsesto san giovanni, lombardia, Italy

DGS, una tech company in crescita, cerca un IAM CyberArk Security Senior Engineer da inserire nel team Professional Services dell'area Identity Security Governance.La risorsa collaborerà con team ... Mostra di più

 • In evidenza

QHSE JUNIOR

OpenjobmetisCastel San Giovanni - Italy

Questa posizione è in Openjobmetis.Il processo di selezione sarà interamente gestito Openjobmetis.Agenzia per il Lavoro ricerca e seleziona, per azienda cliente, un/a QHSE JUNIOR a Castel San Giova... Mostra di più

Climate Technical Excellence Analyst

GeneraliMilano, lombardia, Italy

Within the P&C & Reinsurance Office function, we are looking for a talented and proactive resource to join the Climate Technical Excellence Unit.We are looking for a professional to support the def... Mostra di più

 • In evidenza

Global Travel Portfolio Analyst — Data-Driven Growth

WeRoad LtdMilano, lombardia, Italy

WeRoad is seeking a Portfolio Analyst to own global portfolio visibility, analyze demand and profitability, and guide decisions across markets and products.You will partner with Revenue and Supply ... Mostra di più

 • In evidenza

Specialista Governance Rete - Alleanza Assicurazioni

Generali ItaliaMilan

Questa posizione è in Generali Italia.Riassunto dell'opportunità da parte della.La risorsa contribuirà alla definizione e allo sviluppo dei modelli organizzativi di rete, applicando processi codifi... Mostra di più

 • In evidenza

AI Governance Specialist

Bip ItaliaMilano - Italy

Questa posizione è in Bip Italia.Riassunto dell'opportunità da parte della.Giurisprudenza, Economia, Business Administration o Informatica e 3-6 anni di esperienza in Legal, Compliance, Risk o Gove... Mostra di più

 • In evidenza

Senior SOC Analyst – L2/L3 | Hybrid & Growth Path

Michael Page International Italia S.r.l.milano, lombardia, Italy

Un'azienda leader nel settore della cybersecurity è alla ricerca di un professionista con esperienza nella gestione di incidenti di sicurezza complessi e conoscenza approfondita di sistemi SIEM com... Mostra di più

 • In evidenza

IT Technical Governance Lead

ENGIE Groupmilano, lombardia, Italy

WHO IS ENGIE? /bENGIE puts sustainable development at the center of its activities (electricity, natural gas, energy efficiency, and services) to meet the challenges of the energy transition to a ... Mostra di più

 • In evidenza

Continuous Improvement specialist - Addetto tempi e metodi

Randstad ItalyStradella, Lombardia, Italia

Hai una laurea in Ingegneria Gestionale e breve esperienza nell’analisi tempi e metodi maturata in contesti industriali?.Vuoi inserirti in un’importante azienda logistica con oltre 80.La divisione ... Mostra di più

 • In evidenza

Business Transformation Analyst - Remote, Travel-Ready

Candy Hoover Group SrlBrugherio, lombardia, Italy

Candy Hoover Group Srl is looking for a Digital Transformation Specialist based in Brugherio, Italy.This role requires experience in managing business requirements for digital processes in the home... Mostra di più

 • In evidenza

Milano Hybrid: Compliance Risk Advisory Analyst

MarshMilano, lombardia, Italy

Una società di consulenza cerca un Associate Consultant per la consulenza sul rischio a Milano.Il candidato supporterà il team nella compliance e nella gestione dei rischi, collaborando con collegh... Mostra di più

 • In evidenza

Climate Tech Excellence Analyst (NatCat) - Milan/Trieste

GeneraliMilano, lombardia, Italy

A leading global insurance provider is seeking an Analyst to join their Climate Technical Excellence Unit.The role involves supporting methodologies related to Natural Catastrophes and climate risk... Mostra di più

 • In evidenza

Integrator Engineer – Risk Systems, Europe Travel

Risk Systems Consultingmilano, lombardia, Italy

A consulting firm specializing in Risk Management is seeking an Integrator Engineer to deliver technical solutions for key clients in Italy.The role involves setting up complex systems and developi... Mostra di più

 • In evidenza

IT Vulnerability Specialist

Generali ItaliaMilano - Italy

Questa posizione è in Generali Italia.Riassunto dell'opportunità da parte della.Vulnerability Operations Specialist.IT e gestione vulnerabilità, preferibilmente con competenze in AI generativa.La r... Mostra di più

 • In evidenza

Logistics Investment Analyst – Italy (Growth & Deals)

P3 Logistic ParksMilano, lombardia, Italy

An international logistics provider in Milan is searching for an experienced Investment Analyst to join their team.This role involves assessing logistics real estate opportunities, managing relatio... Mostra di più

 • In evidenza

Identity Security Expert

Accenture ItaliaMilano, lombardia, Italy

Cyber Protection Expert - Identity and Access Management.Cyber Protection Expert - Identity and Access Management.Be among the first 25 applicants.Cyber Protection Expert - Identity and Access Mana... Mostra di più