Security, Vulnerability
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Continuando accetti i nostri Termini & Informativa sulla privacy.
Security, Vulnerability & Compliance Manager (m/f/d)
Azienda : Allianz Tipo Lavoro : Full Time ItalyDescrizione Lavoro
- Security, Vulnerability & Compliance Manager (m/f/d)
About the Job
The Security, Vulnerability & Compliance Manager plays a crucial role in safeguarding Allianz Technology's technology landscape by driving enterprise-wide security, resilience, compliance and governance coordination across CTO2 and multiple Operating Entities (OEs). You will be responsible for managing vulnerability lifecycles, coordinating remediation oversight, tracking compliance against regulatory and internal standards, and presenting risk posture and countermeasures to key stakeholders to support informed, timely and defensible decision-making.
The role acts as the operational coordination and governance engine behind complex cross-functional security and resilience programmes. It ensures visibility, accountability, escalation management, KPI transparency and executive reporting in line with DORA, the Allianz Risk Shield (ARS), Identity & Access Management (IAM), the Configuration Management Database (CMDB), Vulnerability Management (AVM), Third Party Risk Management (TPRM), Web Application Firewall (WAF) coverage and broader security governance objectives.
You will operate at the intersection of executive communication, programme governance and technical infrastructure strategy — translating complex, high-volume security data into clear narratives and actionable countermeasures for governance forums, SteerCos and executive leadership across the OE landscape.
What you do
- Coordinate and govern enterprise-wide Security & Resilience initiatives across CTO2 regions and Operating Entities, applying a proactive "manage by exception" operating model: organise and facilitate recurring governance forums, SteerCos, operational reviews and executive reporting on a defined monthly cadence, maintain governance structures, stage gates, escalation paths, SPOC models and delivery-tracking mechanisms, ensure action ownership, accountability and follow-through to agreed deadlines, and support leadership teams in identifying delivery risks, blockers, dependencies, remediation priorities and countermeasures.
- Govern Allianz Risk Shield (ARS) programme execution across CTO2 environments, including planning, tracking and reporting of compliance progress: monitor self-attestation, evidence collection, testing progress, control effectiveness and compliance-score targets, drive remediation and uplift activities required to achieve and sustain those targets, coordinate Service Owners, SPOCs, Information Security Officers and regional stakeholders to maintain momentum, manage escalations relating to unmanaged risks, Archer remediation actions and compliance blockers, and ensure audit readiness, evidence completeness and governance of mitigation actions, reassessments and remediation tracking.
- Oversee the end-to-end vulnerability remediation lifecycle across Operating Entities (identification, prioritisation, remediation tracking, verification), track backlog reduction, remediation targets, SLA compliance and KPIs, govern executive reporting for vulnerability management, coordinate enterprise Attack Surface Management (ASM) governance (exposed URLs, internet-facing applications, cloud exposure, WAF onboarding), govern GitHub Advanced Security, code scanning, repository onboarding and secure-development remediation tracking, support governance for secure coding, DevSecOps, CI/CD security controls and software supply-chain security, support risk-acceptance governance and transparency of legacy or non-remediable vulnerabilities, and ensure vulnerability dashboards, Power BI metrics and reporting data remain accurate, timely and actionable.
- Drive enterprise CMDB remediation and data-quality improvement (CI-to-service mapping accuracy, ownership validation, mandatory attribute completion), lead CMDB Quality Management governance across infrastructure, applications and service portfolios, coordinate alignment between CMDB, Service Portfolio Management (SPM), Service Validation and ADO IT structures, support service rationalisation, managed-service classification and ownership-alignment exercises, govern remediation of partially managed, unmanaged, deprecated or misaligned service records, coordinate decommissioning governance for obsolete, legacy, redundant or out-of-scope services and infrastructure (including exit-programme and platform-retirement activities), ensure service inventories and governance reporting remain aligned throughout transformation and exit activities, and track remediation KPIs in alignment with audit and compliance deadlines.
- Manage IAM authorization-concept completion and governance across in-scope systems and services, support implementation and tracking of IAM remediation activities and large-scale remediation pro