ION Group logo
ION GroupPosted 1 month ago

Vulnerability Governance Analyst, Italy

$40,000–$50,000 year

On-siteMilan, Lombardy, Italy

Full TimeMasters DegreeEnterprise

Job Summary

Monitor vulnerability remediation activities across infrastructure, cloud, endpoint, and application environments while performing risk-based analysis considering exploitability, asset criticality, and threat intelligence. Correlate intelligence with CMDB, BIA, and SBOM data to prioritize vulnerabilities using a model that factors in CISA KEV, EPSS, and multi-tenant blast radius. Coordinate remediation plans with Infrastructure, Cloud, and Application Security teams, manage exceptions and compensating controls, and develop dashboards and executive reports. Support audits, regulatory assessments, and the continuous improvement of governance policies within the Chief Information Security Office.

Required Qualifications

  • Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field (with honors)
  • At least 2-5 years of experience in Vulnerability Management, Security Operations, Cyber Risk, Security Governance, or related areas
  • Understanding of vulnerability lifecycle management, remediation processes, and exposure management practices
  • Familiarity with vulnerability assessment platforms and reporting solutions
  • Knowledge of vulnerability prioritization methodologies and industry references such as CVSS, EPSS, CISA KEV, exploit intelligence, and threat intelligence feeds
  • Familiarity with software supply chain security concepts, SBOMs, SCA practices, and DevSecOps environments
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, DORA, and NIS2 requirements related to vulnerability and ICT risk management
  • Ability to communicate technical findings through clear risk-based reporting and executive-level summaries
  • Strong analytical, organizational, and stakeholder management skills
  • Excellent knowledge of Italian and English

Desired Qualifications

  • Relevant certifications such as Security+, CySA+, CISSP, ISO 27001, or equivalent

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce