Information Security

3 giorni fa

varese, lombardia, Italia EssilorLuxottica Tempo pieno

Contract: Permanent/Full time
Compensation
If you’ve worn a pair of glasses, we’ve already met.
We are a global leader in the design, manufacture, and distribution of ophthalmic lenses, frames, and sunglasses. We offer our industry stakeholders in over 150 countries access to a global platform of high-quality vision care products (such as the Essilor brand, with Varilux, Crizal, Eyezen, Stellest and Transitions), iconic brands that consumers love (such as Ray-Ban, Oakley, Persol, Oliver Peoples, Vogue Eyewear and Costa), as well as a network that offers consumers high-quality vision care and best-in-class shopping experiences (such as Sunglass Hut, LensCrafters, Salmoiraghi & Viganò and the GrandVision network), and leading e-commerce platforms.
Join our global community of over 190,000 dedicated employees around the world in driving the transformation of the eyewear and eyecare industry.
Discover more by following us on LinkedIn
Your #FutureInSight with EssilorLuxottica
Are you willing to pioneer new frontiers, foster inclusivity and collaboration, embrace agility, ignite passion, and make a positive impact on the world? Join us in redefining the boundaries of what’s possible.
Your role
In this role you will report directly to an Information Security Manager and you will be responsible for strengthening the Company’s cyber detection and response capabilities. You will coordinate the monitoring of security events, support incident triage and investigation, drive response and containment activities with IT and business stakeholders, and contribute to the continuous improvement of use cases, playbooks, reporting and incident readiness. The role requires a strong operational security mindset, the ability to work across geographies and functions, and a practical approach to translating security alerts and incidents into clear actions and remediation plans.
Main Responsibilities

  • Security monitoring and detection - Coordinate the monitoring of security events and alerts across the Company’s environment, ensuring timely identification of potential threats and suspicious activities.
  • Incident triage and investigation - Support the analysis, validation and prioritization of security incidents, working with IT Security, SOC providers and relevant stakeholders to determine impact, scope and required actions.
  • Response coordination and containment - Coordinate response activities during security incidents, supporting containment, eradication and recovery actions in alignment with internal processes and escalation paths.
  • Use case, playbook and process improvement - Contribute to the definition and continuous improvement of detection use cases, incident response playbooks, escalation criteria and operational procedures.
  • Reporting and remediation follow-up - Prepare clear incident updates and management reporting, track remediation actions, and escalate risks, delays and recurring weaknesses to the CISO / relevant stakeholders.
Main Requirements
  • Bachelor’s degree in Information Security, Information Technology, Computer Science, Engineering, or similar strongly desired.
  • Professional information security certifications such as CISSP, CISM, GCIH, GCIA, GCFA, Security+ or similar are strongly desired.
  • Knowledge of security monitoring, incident detection, incident response, threat analysis, endpoint security, network security, identity and access management, vulnerability management and data protection.
  • Demonstrated experience in coordinating security monitoring and incident response activities, including alert triage, investigation support, containment coordination, remediation tracking and stakeholder communication.
  • Experience with SOC operations, SIEM platforms, endpoint detection and response solutions, threat intelligence, log analysis and common attack techniques; understanding of security frameworks such as NIST, ISO 27001 and MITRE ATT&CK.
  • Knowledge of incident response lifecycle, escalation models, crisis management principles, evidence handling and post-incident review practices.
  • Knowledge of relevant Information Security / Data Protection laws and regulations, including requirements that may impact incident management and notification processes.
  • Ability to translate technical security findings into clear business-oriented messages, actions and priorities for technical and non-technical stakeholders.
  • Knowledge of core IT processes, including infrastructure operations, application management, change management, access management and service management.
  • Project management skills, teamwork, individual accountability and ability to coordinate multiple stakeholders during time-sensitive situations.
  • Proven ability to communicate effect