Digital Risk
2 settimane fa
Allianz is seeking a hands-on and detail-oriented Attack Surface Management (ASM) Expert to support the continuous discovery, monitoring, and reduction of Allianz's risk exposure. In this role, you will be responsible for identifying assets, detecting vulnerabilities and misconfigurations, and ensuring risks are addressed before they can be exploited. You will work closely with IT, security operations, and architecture teams to maintain visibility across the global environment and proactively reduce Allianz's attack surface. This role is essential in strengthening our preventive cyber defense and enabling secure business innovation.
Your mission in the role will be:
To support and follow on the following prioritization, reporting, risk registration and consequence management on managing attack surface. This includes engaging the following activities:
- Asset Discovery & Exposure Mapping: Continuously identify and map Allianz's external-facing digital assets (domains, IPs, cloud services, applications), ensuring complete visibility into the attack surface. Analyse findings from ASM tools, correlate with threat intelligence and business context, and prioritize exposures based on exploitability and potential impact.
- Issue Validation & Remediation Support: Validate identified risks and exposures, work with IT, DevOps, and application owners to ensure timely mitigation and track remediation progress.
- Misconfiguration & Shadow IT Detection: Detect unapproved or misconfigured systems and services (e.g., open ports, weak encryption, unmanaged cloud services), and initiate appropriate follow-up actions.
- Documentation & Reporting: Maintain detailed documentation of findings, support reporting to management, and contribute to dashboards and KPIs that reflect ASM maturity and progress.
- Security Best Practices Advocacy: Promote awareness of ASM risks and secure deployment practices across IT and development teams, helping reduce exposure from the ground up.
What you bring:
- Educational Background: Higher education degree in Information Security, Computer Science, or a related technical field.
- Attack Surface Management Expertise: Proven hands-on experience in identifying, classifying, and managing external digital assets. Skilled in using ASM platforms (e.g., CyCognito, Palo Alto Cortex Xpanse, Rapid7, or similar) to detect unknown assets, misconfigurations, and exposure risks.
- Technical and Analytical Skills: Solid understanding of internet protocols, DNS, SSL/TLS, cloud infrastructure (AWS, Azure, GCP), and web application technologies. Strong ability to analyse external exposure data, correlate with threat intelligence, and recommend practical remediation actions.
- Collaboration and Communication: Ability to collaborate with IT operations, DevOps, vulnerability management, and SOC teams to support risk reduction. Effective communicator with the ability to document findings, articulate risk impact, and support mitigation efforts in a clear, actionable manner
What we offer
- We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad.
- We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location).
- From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered.
- Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach.
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us.
We at Allianz believe in a diverse and inclusive workforce and are proud to be an equal opportunity employer. We encourage you to bring your whole self to work, no matter where you are from, what you look like, who you love or what you believe in. We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, disability or sexual orientation.
Join us. Let's care for tomorrow.
#LI-IT1
-
IT Governance, Risk
1 settimana fa
Italia Allianz A tempo pienoAs IT Governance, Risk & Compliance (GRC) Manager at Allianz, you play a key role in ensuring that our IT operations run securely, efficiently, and in line with regulatory standards. You'll design, oversee, and continuously enhance governance and risk management processes that help protect our organization and enable innovation. This position is perfect for...
-
Information Security Risk Management
2 settimane fa
Italia Allianz A tempo pienoThe Allianz Group Information Security Function is responsible for ensuring that Information Security and Cyber Risks, which could potentially impact the successful delivery of Allianz business objectives, are identified and appropriately managed. It ensures that Allianz is adequately protected in accordance with legal and regulatory requirements....
-
Senior Consultant Compliance, Risk
7 giorni fa
Italia SCS Consulting A tempo pienoSenior Consultant Compliance, Risk & Audit Se sei una persona che ha voglia di mettersi in gioco, dinamica e curiosa, desideri crescere e ampliare le tue competenze, SCS Consulting può offrirti reali opportunità sia dal punto di vista della crescita professionale che di formazione continua in un ambiente che valorizza le persone. SCS è un'azienda in forte...
-
IT Digital Workplace Team Leader
19 ore fa
Italia Telema International A tempo pienoDescrizione:Per primario Gruppo Bancario si ricerca una/un:IT Digital Workplace Team Leader(1/26)La figura cercata sarà inserita all'interno del dipartimento infrastrutture, e avrà la responsabilità di gestire e guidare l'evoluzione digital workplace per i dipendenti dell'azienda.Avrà il compito di gestire le progettualità di mantenimento, evoluzione e...
-
Risk Project Controlling and Modelling Analyst
2 settimane fa
Italia Randstad Italia A tempo pienoRandstad Italia Spa, Florence branch, is looking for a RISK PROJECT CONTROLLING AND MODELLING ANALYST for a major multinational company operating in the Oil & Gas sector. We offer : an initial 12 month temporary contract with the possibility of direct placement in the company. CCNL Metalworking Industry, RAL 34-35.000€. Benefit : possibility of smart...
-
Digital Drilling Engineer
2 settimane fa
Italia SLB A tempo pienoJob Title Digital Drilling Engineer (Fresh Graduate) About Us We are a global technology company, driving energy innovation for a balanced planet. At SLB we create amazing technology that unlocks access to energy for the benefit of all. We are facing the world’s greatest balancing act- how to simultaneously reduce emissions and meet the world’s growing...
-
Product Manager, Digital Quality Management
6 minuti fa
Italia DSM A tempo pienoJob Title: Product Manager, Digital Quality Management City, Country: Barcelona, Spain or Hyderabad, IndiaAt dsm-firmenich, we seek for a highly skilled and experienced Product Manager, Digital Quality Management to join our team.You'll be at the heart of leading delivery of transformative digital solutions that drive real business impact. You'll partner...
-
Credit & Operations Specialist
1 giorno fa
Italia CashMe SpA A tempo pienoDescrizione del lavoro Unisciti al Team di CashMe Spa come Credit & Operations Specialist Sei pronto a fare la differenza in una delle FinTech più innovative del panorama italiano? CashMe Spa è alla ricerca di un talento da inserire nel team, dove potrai giocare un ruolo cruciale nella gestione dei crediti e dei clienti, contribuendo direttamente alla...
-
Chief Operating Officer
3 settimane fa
Italia Adecco A tempo pienoAdecco cerca per proprio cliente specializzato nel settore pagamenti digitali un Chief Operating Officer (COO). In stretta collaborazione con il CEO e il leadership team, il COO traduce la strategia in piani operativi concreti, assicurando l’allineamento tra persone, processi e sistemi. Responsabilità Principali: Supervisionare le operazioni aziendali...
-
Audit Specialist
4 settimane fa
italia Nexi Group A tempo pienoShape the Future of Payments with Nexi in 2025 Envision a world where every transaction feels effortless, safe, and connected. At Nexi, we’re leading this transformation, building tools and solutions that redefine how the world pays. By joining us, you’ll play a part in creating the next generation of digital payments in an innovative, supportive, and...