We are a community of visionary innovators dedicated to providing pioneering software and consultancy services to financial institutions trading firms central banks governments and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software as well as providing real-time data and business intelligence to help people make better decisions. We are 13000 employees we operate globally with 80 global offices and we serve over 4800 customers worldwide.
For the strengthening of the Chief Information Security Office (CISO) function within Cedacris companies part of ION Group we are looking for talented professionals to grow their career as Vulnerability Governance Analyst. This position is targeted at candidates with 25 years of relevant experience in Cybersecurity Vulnerability Management or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organizations vulnerability governance framework and security posture.
Support the governance and continuous improvement of the enterprise Vulnerability Management program.
Monitor vulnerability remediation activities across infrastructure cloud endpoint and application environments ensuring compliance with established remediation targets and governance requirements.
Perform risk-based vulnerability analysis considering exploitability asset criticality exposure business impact and threat intelligence.
Correlate vulnerability intelligence with CMDB BIA SBOM/SCA and application ownership data to identify exposed services impacted customers remediation owners and urgency of action.
Prioritize vulnerabilities using a risk-based model that goes beyond technical severity considering exploitability evidence of active exploitation CISA KEV/EPSS Internet exposure asset criticality client impact and multi-tenant blast radius
Coordinate remediation plans and follow-up activities with Infrastructure Cloud Development Application Security and Risk teams.
Manage remediation exceptions compensating controls and risk acceptance processes.
Develop and maintain vulnerability dashboards KPIs operational metrics and executive reports.
Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
Contribute to the definition and continuous improvement of vulnerability management policies standards and governance processes.
Support audits regulatory assessments and compliance activities related to cyber risk and vulnerability management.
Other duties
We might ask you to perform other tasks and duties as your role expands.
Your skills experience and qualifications required
Masters degree in Cybersecurity Computer Science Computer Engineering Information Technology or a related field (with honors)
At least 2-5 years of experience in Vulnerability Management Security Operations Cyber Risk Security Governance or related areas.
Understanding of vulnerability lifecycle management remediation processes and exposure management practices.
Familiarity with vulnerability assessment platforms and reporting solutions.
Knowledge of vulnerability prioritization methodologies and industry references such as CVSS EPSS CISA KEV exploit intelligence and threat intelligence feeds.
Familiarity with software supply chain security concepts SBOMs SCA practices and DevSecOps environments.
Knowledge of ISO 27001 NIST CSF CIS Controls DORA and NIS2 requirements related to vulnerability and ICT risk management.
Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
Strong analytical organizational and stakeholder management skills.
Excellent knowledge of Italian and English.
Relevant certifications such as Security CySA CISSP ISO 27001 or equivalent would be considered a plus.
What we offer:
Permanent employment contract
Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
Gross Annual Salary (RAL) ranging from 40000 to 50000 depending on experience skills and qualifications
Job grade to be determined upon completion of the selection process with final assessment between B2 and B3 level
Opportunity to join a leading international technology group operating in the financial services industry
Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment
Location:
Milan.
Important notes:
According to the Italian Law (L.68/99) candidates belonging to the protected categories list will be given priority.
We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.
Required Experience:
IC
About us:We are a community of visionary innovators dedicated to providing pioneering software and consultancy services to financial institutions trading firms central banks governments and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and...
About us:
We are a community of visionary innovators dedicated to providing pioneering software and consultancy services to financial institutions trading firms central banks governments and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software as well as providing real-time data and business intelligence to help people make better decisions. We are 13000 employees we operate globally with 80 global offices and we serve over 4800 customers worldwide.
For the strengthening of the Chief Information Security Office (CISO) function within Cedacris companies part of ION Group we are looking for talented professionals to grow their career as Vulnerability Governance Analyst. This position is targeted at candidates with 25 years of relevant experience in Cybersecurity Vulnerability Management or Information Security Governance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to strengthen the organizations vulnerability governance framework and security posture.
Support the governance and continuous improvement of the enterprise Vulnerability Management program.
Monitor vulnerability remediation activities across infrastructure cloud endpoint and application environments ensuring compliance with established remediation targets and governance requirements.
Perform risk-based vulnerability analysis considering exploitability asset criticality exposure business impact and threat intelligence.
Correlate vulnerability intelligence with CMDB BIA SBOM/SCA and application ownership data to identify exposed services impacted customers remediation owners and urgency of action.
Prioritize vulnerabilities using a risk-based model that goes beyond technical severity considering exploitability evidence of active exploitation CISA KEV/EPSS Internet exposure asset criticality client impact and multi-tenant blast radius
Coordinate remediation plans and follow-up activities with Infrastructure Cloud Development Application Security and Risk teams.
Manage remediation exceptions compensating controls and risk acceptance processes.
Develop and maintain vulnerability dashboards KPIs operational metrics and executive reports.
Support the escalation and governance of critical vulnerabilities and high-risk exposure scenarios.
Contribute to the definition and continuous improvement of vulnerability management policies standards and governance processes.
Support audits regulatory assessments and compliance activities related to cyber risk and vulnerability management.
Other duties
We might ask you to perform other tasks and duties as your role expands.
Your skills experience and qualifications required
Masters degree in Cybersecurity Computer Science Computer Engineering Information Technology or a related field (with honors)
At least 2-5 years of experience in Vulnerability Management Security Operations Cyber Risk Security Governance or related areas.
Understanding of vulnerability lifecycle management remediation processes and exposure management practices.
Familiarity with vulnerability assessment platforms and reporting solutions.
Knowledge of vulnerability prioritization methodologies and industry references such as CVSS EPSS CISA KEV exploit intelligence and threat intelligence feeds.
Familiarity with software supply chain security concepts SBOMs SCA practices and DevSecOps environments.
Knowledge of ISO 27001 NIST CSF CIS Controls DORA and NIS2 requirements related to vulnerability and ICT risk management.
Ability to communicate technical findings through clear risk-based reporting and executive-level summaries.
Strong analytical organizational and stakeholder management skills.
Excellent knowledge of Italian and English.
Relevant certifications such as Security CySA CISSP ISO 27001 or equivalent would be considered a plus.
What we offer:
Permanent employment contract
Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
Gross Annual Salary (RAL) ranging from 40000 to 50000 depending on experience skills and qualifications
Job grade to be determined upon completion of the selection process with final assessment between B2 and B3 level
Opportunity to join a leading international technology group operating in the financial services industry
Exposure to enterprise-scale cybersecurity governance activities within a dynamic and international environment
Location:
Milan.
Important notes:
According to the Italian Law (L.68/99) candidates belonging to the protected categories list will be given priority.
We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.