Group IT Security Manager

21 ore fa

Milan, Lombardy, Italia Bolton Group Tempo pieno

Overview

In this role you will translate Bolton's security strategy into practical architectures and controls, driving cross-functional initiatives to reduce risk and enable business transformation. You will lead security architecture, SOC governance, and platform hardening across cloud, identity, network, and endpoints. The position involves collaborating with IT and security partners to embed security into projects and operations. This is a hands-on, impact-focused leadership role at a fast-moving, multinational family-owned company.

Retribuzione / Benefits

  • Meal vouchers worth 12 for smart working days
  • Faschim health insurance plan
  • Corporate welfare plan
  • Flexible smart working policy
  • Permanent contract
  • Full-time or part-time option

Responsabilità

  • Drive Zero Trust and secure-access initiatives from design to rollout and handover
  • Govern and improve the managed SOC service, including playbooks, escalation paths and integration with ITSM
  • Assess IT services/changes for security, prioritise vulnerabilities, manage exceptions and remediation
  • Evolve SIEM/EDR, secure-access, password-management platforms and maintain technical hardening standards
  • Lead security initiatives, supplier evaluations, and track delivery and handover, with ongoing reporting to stakeholders

Requisiti fondamentali

  • 5 years in IT/Cyber Security with senior responsibility for technical initiatives or autonomous delivery
  • Hands-on SIEM/EDR, managed SOC and incident-response experience
  • Strong knowledge of vulnerability assessment, remediation and security exceptions
  • Experience securing cloud, identity, endpoints and networks with Zero Trust and technical standards
  • Ability to coordinate IT teams and providers, balancing risk reduction, business continuity, cost and global scalability
  • Excellent Italian and English; Spanish a plus
  • Cross-functional collaboration
  • Clear communication of technical risk to international stakeholders
  • Proactive and autonomous delivery
  • SIEM/EDR (operational expertise)
  • SOC management and incident response
  • Vulnerability assessment and remediation