.
Overview
We are looking for an experienced and motivated individual to join the Cybersecurity Oversight team at Intesa Sanpaolo. You will join a group dedicated to verifying and measuring the Group's security solutions and defining investment strategies. You will work with a holistic and global approach, creating value for both the Parent Company and the Legal Entities of the Intesa Sanpaolo Group. In an international, dynamic, and fast-growing context, you will have the opportunity to collaborate closely with diverse professional backgrounds and corporate cultures.
What your activities will be
- Design and support the implementation of dashboarding and monitoring systems
- Design and support the implementation of machine learning algorithms and data analysis
- Identification, verification, and monitoring of corporate security measures in order to improve their coverage and completeness
- Analyze, understand, and verify the implementation of Cybersecurity requirements deriving from the Bank's project initiatives, in terms of consistency, policies, and standards
- Prepare reports related to the verifications and measurements performed, highlighting gaps and deficiencies, including through the production and maintenance of appropriate indicators (e.g., KPIs)
- Ensure constant and effective monitoring of all remediation activities regarding gaps identified during verification and measurement to ensure their timely resolution
- Participate in and manage projects, coordinating suppliers and internal staff to achieve objectives, interfacing with all involved corporate functions, and handling reporting to management
- Maintain effective relationships with internal stakeholders active in verification and monitoring processes
- Contribute to the management of the budget, forecasting, and multi-year planning process
Who we are looking for
If you have the following characteristics, we are waiting for you:
- 5-10 years of experience in the cybersecurity field
- Degree in Computer Science/Scientific field
- Knowledge of cybersecurity topics, with particular reference to the Finance sector and the protection of digital services aimed at customers and internal users, the main security vulnerabilities, and threats deriving from cyber attacks
- Knowledge of reference frameworks (e.g., NIST Cybersecurity, ISO 27001, ISO 22301...) and Cybersecurity and Business Continuity regulations (e.g., Law 133 on the national cyber security perimeter, Circular 285, NIS Directive, PSD2...)
- Ability to govern project initiatives with high organizational and technological complexity
- Knowledge of the English language
- Knowledge of reporting and data analysis systems
- Knowledge of the main Cybersecurity solutions and technologies for infrastructure protection: network, endpoint, mobile device, IoT devices, mainframe
- Microsegmentation, SASE frameworks, vulnerability management and application & code security, data security
- Knowledge of data protection technologies (Data Masking, Tokenization, Data Classification, Data Loss Prevention, backup security...)
- Knowledge of security technological solutions regarding symmetric and asymmetric cryptography, on-prem and cloud encryption key management, and digital certificate management
- Knowledge of digital identity management solutions, with experience gained in Identity Access Management
- Knowledge of security and protection solutions for cloud, multi-cloud, and hybrid architectures
- Knowledge of API management, preferably in the context of Open Digital Banking architectures
The following knowledge is considered a preferential qualification:
- Risk and compliance management
- Data analysis
- Security architectures and solutions
- Offensive Security certifications - OSCP, OSCE, OSWE, EC-Council CEH (Certified Ethical Hacker), ISACA - CSX Fundamentals, CISSP, PMP
What we offer you
-
Gross annual salary starting from €50.000
-
The Group provides a variable component of remuneration as regulated by the Remuneration Policies available on the Group's website
-
Complementary elements regulated by the National Collective Labor Agreement for the Credit Sector and second-level company agreements
-
Professional development initiatives to support the growth of our people
-
Extensive training offer through the Corporate Academy dedicated to the continuous development of professional, managerial, and transversal skills at all levels
-
Possibility to join flexible work arrangements and the 4x9 short week
-
Modern and integrated corporate welfare system ( link)
-
Health coverage and supplementary pension starting from hiring
-
Advantages on the Group's banking products and services
Who we are
We are leaders in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.
People are at the center; we take care of them by committing to creating an inclusive culture within the Group where everyone feels like a protagonist and valued.
The Chief Security Officer Governance Area oversees physical security, cybersecurity, and the Group's operational continuity in an integrated way, leveraging specialized skills and advanced technological solutions, with the goal of ensuring high security standards at an international level.
The Area includes the Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management structures, ensuring a coordinated and transversal approach to the protection of the Group.
Join our international reality. The future is not waited for, it is chosen!
#sharingfuture
We guarantee an inclusive and equal opportunity environment. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with Legislative Decrees 198/2006, 215/03, and 216/03.
For the evaluation of applications, the data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to read the dedicated Privacy Policy.
