Mid-Level, Senior
As a Vulnerability Analyst and Penetration Tester, you will work closely with the Cyber Security Monitoring team to perform vulnerability assessments, penetration testing, red teaming activities, and security impact analyses related to emerging cyber threats, zero-day vulnerabilities, and advanced attack techniques.
The role also includes leveraging AI-driven cybersecurity solutions and Large Language Models (LLMs) to enhance information gathering, vulnerability analysis, attack surface monitoring, and the identification of indicators of compromise associated with evolving threat actors and attack campaigns.
Activities will include:
Execution of periodic Vulnerability Assessments across both internal and external perimeters using enterprise-grade security platforms and automated assessment tools.
Identification, validation, prioritization, and reporting of vulnerabilities to asset owners, with continuous tracking of remediation activities through the organization's Vulnerability Management platform.
Execution of Web Application Penetration Tests (WAPT), infrastructure penetration tests, and Red Teaming exercises based on internally defined threat scenarios and intelligence-driven attack simulations.
Collection and correlation of information from OSINT, CLOSINT, Threat Intelligence feeds, and AI-assisted research platforms to identify newly disclosed vulnerabilities, emerging threats, and zero-day exposures.
Security impact assessment of new vulnerabilities and threat campaigns affecting the organization, including risk evaluation, remediation prioritization, and stakeholder communication.
Utilization of AI and Machine Learning-based tools to support vulnerability triage, threat hunting, attack pattern analysis, anomaly detection, and proactive identification of emerging cyber risks.
MAIN TASKS
Perform Red Teaming activities in collaboration with the GOSP CSIRT team, based on agreed cyber threat scenarios, to validate detection, response, and prevention capabilities, identify security gaps, and define remediation actions.
Conduct Web Application Penetration Testing (WAPT) and infrastructure penetration testing activities to assess security posture, system hardening, configuration effectiveness, and resilience against real-world attack techniques.
Execute periodic Vulnerability Assessments on internal and external infrastructures to identify, validate, and prioritize security vulnerabilities.
Track, monitor, and report identified vulnerabilities through the GOSP Vulnerability Management process, ensuring remediation activities are appropriately managed and verified.
Analyze newly discovered vulnerabilities, CVEs, and zero-day threats collected from OSINT, CLOSINT, commercial threat intelligence sources, and AI-assisted intelligence platforms, assessing their potential impact on GOSP infrastructure and services.
Leverage Generative AI and AI-powered cybersecurity solutions to accelerate threat intelligence analysis, vulnerability research, attack path identification, security assessments, and the production of technical reports and remediation recommendations.
Support proactive threat hunting and attack surface monitoring activities by combining traditional security methodologies with AI-enhanced analytics and automation capabilities.
Contribute to the continuous improvement of security testing methodologies, adversary emulation techniques, and cybersecurity processes aligned with evolving threat landscapes.
Degree in Computer Science, IT Security, or equivalent work experience in Information Security.
2-5 years of experience in vulnerability assessment / penetration tests activities.
Knowledge of Vulnerability Assessment, Penetration Testing, Red Teaming, and Vulnerability Management methodologies.
Familiarity with security frameworks and standards such as OWASP, MITRE ATT&CK, NIST, and CVSS.
Knowledge of the main market tools and processes to perform vulnerability assessments (e.g: Qualys, Nessus, OpenVAS, NMAP, etc).
Knowledge on the main penetration testing tools available on the market (e.g: Zap, Burp suite, Metasploit, Wireshark, John The Ripper, SQLmap, etc).
Understanding of Threat Intelligence, OSINT techniques, and cyber threat analysis.
Familiarity with AI/ML technologies, Security Copilots, LLMs, and AI-assisted cybersecurity platforms applied to threat detection, vulnerability management, and security operations.
Strong analytical mindset, problem-solving skills, and ability to communicate technical findings to both technical and non-technical stakeholders.
Good knowledge of IT networks and protocols, Operating systems, web and application server architectures.
Good knowledge of Microsoft Active Directory architecture and .
Good knowledge of one or more programming languages (e.g: python, PowerShell, C/C++, etc)
Intermediate English (at least CEFR B1, written/spoken)
Availability of certifications is a plus (e.g., CEH, OSCP, GPEN, etc)
Soft Skills:
Ability to work in team and to maintain deadlines on assigned tasks
Positive attitude and open to learn on the job
Passionate about offensive security
Proactive in identifying obstacles and problems that might impact your daily activities
Capability to perform periodical report to your manager
Very good problem-solving capabilities
Open to cooperation with other team within the organization
We offer employment at the V level with the relevant salary, in accordance with the CCNL ANIA for non-executive employees and the Generali Group Company Agreement.
Gross annual salary ranging between 40K€ and 50K€. The final offer will be aligned with the candidate’s professional experience, technical and soft skills relevant to the role, and may include an individual variable component.
We also offer
Smart working and flexible hours
Corporate welfare system
Meal vouchers
Supplementary health insurance and discounted insurance policies
Well-being initiatives
Training and development
Structured continuous learning paths (technical and managerial)
Career development programs within the Group
Access to learning platforms and internal mobility opportunities, including international
Essere Partner di Vita è la nostra ambizione: ogni giorno vogliamo essere al fianco dei nostri clienti prendendoci cura delle loro vite e dei loro sogni. Questo per noi è Più di un Lavoro.
Siamo parte di un importante Gruppo internazionale con oltre 82 mila persone in tutto il mondo e più di 68 milioni di clienti. Siamo tra i principali player globali del settore assicurativo: l’innovazione e la sostenibilità sono nel nostro DNA. Generali Italia è l’assicuratore più conosciuto in Italia con oltre Є28 miliardi di premi totali, 15 mila dipendenti e una rete capillare di 40 mila distributori, oltre ai canali online e di bancassurance. A Generali Italia fanno capo Alleanza Assicurazioni, Das, Genertel e Genertellife, Generali Welion, Generali Jeniot e Leone Alato, oltre alle attività della Business Unit Cattolica.
Il Gruppo Generali offre delle interessanti opportunità di arricchimento professionale in un contesto lavorativo caratterizzato da:
Cultura aziendale solida e aperta, modi di lavorare innovativi, formazione e affiancamento a supporto di un inserimento efficace Ambiente di lavoro inclusivo in cui ognuno si sente accolto, libero di esprimere al meglio la propria identità, le proprie idee e le proprie capacità: perché siamo Più che diverse, Persone Uniche Qualità dei processi e iniziative per le nostre persone, che ci distinguono come Top Employer.
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well Generali Italia matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.