.
Overview
You will join the Cybersecurity department and be responsible for leading, consolidating, and implementing DevSecOps paradigms within the organization. You will support the team in ensuring the adoption of appropriate security measures, focusing on secure code design as an enabling factor for protecting the Bank against application vulnerabilities and software supply chain attacks.
What your activities will be
- Define the architecture and standards for the Secure Software Development Life Cycle (SSDLC) on an enterprise scale, adapting them to Agile and Cloud-Native methodologies
- Contribute to engineering the integration of security tools (SAST, DAST, IAST, SCA, Container Security) within CI/CD pipelines, evaluating and promoting the adoption of AI-driven tools
- Design solutions for Software Supply Chain security, evaluating and promoting the adoption of dedicated technologies and processes (e.g., SBOM Software Bill of Materials)
- Define and evolve secure code development guidelines, adapting them to the continuously evolving cyber threat landscape
Who we are looking for
If you have the following characteristics, we are waiting for you:
- At least 5 years of experience in an Application Security Architect or DevSecOps Lead role
- Advanced knowledge of application security frameworks such as OWASP SAMM, BSIMM, and NIST SSDF
- Experience in security automation within GitLab, GitHub, and Jenkins pipelines and in Security as Code paradigms
- Skills in protecting microservices, APIs, and Kubernetes environments
- Ability to mentor and promote a Security Champion culture within development teams
- Knowledge of attack scenarios, vulnerabilities, and threats to banking and application systems
- Excellent knowledge of the English language
The following certifications are considered a plus:
- CISSP, CSSLP, Security+, CISM, CSX, OSCP, OSCE, ISO 27001, ISO 22301, and Cloud Security
What we offer you
-
Gross annual salary starting from €50.000
-
The Group provides a variable remuneration component as regulated by the Remuneration Policies available on the Group's website
-
Complementary elements regulated by the National Collective Labor Agreement for the Credit Sector and second-level company agreements
-
Professional development initiatives to support the growth of our people
-
Extensive training offer through the Corporate Academy dedicated to the continuous development of professional, managerial, and transversal skills at all levels
-
Possibility to join flexible work arrangements and the 4x9 short week
-
Modern and integrated corporate welfare system ( link)
-
Health coverage and supplementary pension starting from hiring
-
Advantages on the Group's banking products and services
Who we are
We are leaders in Italy and one of the main banking groups in Europe. Join us and be part of our success story! With over 20 million customers in Italy and abroad, we are a true engine of sustainable growth with a strong commitment to the environment and a tangible impact on society.
People are at the center; we take care of them by committing to creating an inclusive culture within the Group where everyone feels like a protagonist and valued.
The Chief Security Officer Governance Area oversees the physical security, cybersecurity, and operational continuity of the Group in an integrated manner, leveraging specialized skills and advanced technological solutions with the goal of ensuring high international security standards.
The Area includes the Security Staff, Group Security Planning & Models Monitoring, Corporate and Physical Security, and Cybersecurity, Antifraud & Business Continuity Management structures, ensuring a coordinated and transversal approach to protecting the Group.
Join our international reality. The future is not waited for, it is chosen!
#sharingfuture
We guarantee an inclusive and equal opportunity environment. We will consider all applications regardless of race, religion, sexual orientation, gender identity, marital status, age, disability, or any other protected category in compliance with Legislative Decrees 198/2006, 215/03, and 216/03.
For the evaluation of applications, the data will be used by Intesa Sanpaolo S.p.A. as Data Controller. We invite you to read the dedicated Privacy Notice.
