.
Overview
Joining the Cybersecurity Defence Centre team, you will be responsible for modeling, detecting, and countering cyber threats enhanced by the use of frontier LLMs, AI agents, and advanced automation by sophisticated attackers.
What your activities will be
- Analyze the impact of generative AI, frontier LLMs, and AI agents on the evolution of cyber threats, evaluating how these technologies can increase the speed, scalability, and effectiveness of attacks along the cyber kill chain
- Analyze scenarios of reconnaissance, phishing, social engineering, vulnerability discovery, exploit chaining, evasion, and automation of offensive activities enabled by AI
- Define threat scenarios and detection use cases to identify AI-enabled attacks and anomalous behaviors
- Develop and optimize AI agents to support the SOC, improving triage, automatic enrichment, event correlation, alert prioritization, and incident response
- Contribute to strengthening defensive capabilities by collaborating on the evolution of processes, methodologies, and operational tools oriented toward managing emerging AI-based threats
Who we are looking for
If you have the following characteristics, we are waiting for you:
- 3-5 years of experience in the role
- Solid knowledge of Detection & Response tools: SIEM, XDR, SOAR, EDR, NDR, Threat Intelligence platforms, and response automation
- Knowledge of tactics, techniques, and procedures used by sophisticated cyber actors, both offensively and defensively
- Experience in defining detection use cases, correlation rules, hunting activities, and SOC playbooks
- Scripting and development skills with Python, KQL, or equivalent tools
- Familiarity with LLMs, AI agents, prompt engineering, agentic workflows, and generative AI applied to cybersecurity
- Design of AI agents to support the SOC, ensuring control, traceability, and quality of outputs
- Knowledge of MITRE ATT&CK, MITRE ATLAS, Cyber Kill Chain, OWASP Top 10 for LLM Applications, and NIST AI RMF
- Excellent knowledge of the English language
What we offer you
-
Gross annual salary starting from €45.000
-
The Group provides a variable component of remuneration as regulated by the Remuneration Policies available on the Group's website
-
Complementary elements regulated by the National Collective Labor Agreement for the Credit Sector and second-level company agreements
-
Professional development initiatives to support the growth of our people
-
Extensive training offer through the Corporate Academy dedicated to the continuous development of professional, managerial, and soft skills at all levels
-
Possibility to join flexible work arrangements and the 4x9 short week
-
Modern and integrated corporate welfare system ( link)
-
Health coverage and supplementary pension scheme starting from hiring
-
Advantages on the Group's banking products and services
Who we are
We are leaders in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.
People are at the center; we take care of them by committing to creating an inclusive culture within the Group where everyone feels like a protagonist and valued.
The Chief Security Officer Governance Area oversees the physical security, cybersecurity, and operational continuity of the Group in an integrated way, leveraging specialized skills and advanced technological solutions with the goal of ensuring high international security standards.
The Area includes the Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management structures, ensuring a coordinated and cross-functional approach to protecting the Group.
Join our international reality. The future is not waited for, it is chosen!
#sharingfuture
We guarantee an inclusive and equal opportunity environment. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with Legislative Decrees 198/2006, 215/03, and 216/03.
For the evaluation of applications, the data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to read the dedicated Privacy Notice.
