About this role
Ariston Group is a global leader in sustainable climate and water comfort, listed on Euronext Milan. In 2025 the group reported 2.7 billion-euro revenues, with almost 11,000 employees, direct presence in 41 countries in 5 continents, 32 production sites and 31 research and development centers. The group demonstrates its commitment to sustainability through renewable and high-efficiency solutions, including heating heat pumps, water heating heat pumps, hybrids, domestic ventilation, air handling, electric components, and solar thermal systems, while continuously investing in technological innovation, digitalization, and advanced connectivity solutions. The group operates under global strategic brands Ariston, Wolf and Elco, and brands such as Calorex, NTI, Atag, Domotec, Brink, Chromagen, Racold, as well as Thermowatt and Ecoflam in the components and combustion technologies business.
Department : ICT
Reports To: ICT Security
Location : Fabriano/Milan, Italy
Position Overview
We are looking for a Cyber Defence Management to lead the team responsible for defining and executing the Group ICT security strategy, implementing and improving technical security controls, managing cyber defence operations, coordinating incident response, and governing vulnerability management.
The role combines strategic leadership with operational accountability, ensuring that cyber defence capabilities are aligned with business priorities, the enterprise risk profile, and applicable regulatory and compliance requirements. The Cyber Defence Manager leads internal resources and external service providers, oversees day-to-day security operations, and drives the continuous improvement of prevention, detection, response and remediation capabilities across the Group ICT environment.
Key Responsibilities
- Define and execute the Group ICT Cyber Defence strategy and roadmap, ensuring alignment with business objectives, cybersecurity risks, architecture principles and compliance requirements.
- Lead and develop the Cyber Defence function, setting priorities, objectives, operating models and capability development plans.
- Ensure the effectiveness and continuous improvement of preventive, detective and responsive security controls across the Group's IT environment.
- Oversee cyber defence services, technologies and third-party providers, ensuring effective monitoring, threat detection, incident response and service performance.
- Lead the management of major cybersecurity incidents and drive the continuous enhancement of incident response processes, playbooks and recovery capabilities.
- Establish and govern vulnerability management and cyber threat intelligence processes, ensuring timely risk identification, prioritisation and remediation.
- Define and monitor cybersecurity operational metrics, risk indicators and reporting, providing regular updates and recommendations to the Group CISO and key stakeholders.
- Manage relationships with security vendors and service providers, ensuring service quality, contractual compliance and continuous improvement.
Required Qualifications
- At least 8 years of progressive experience in cybersecurity, with significant responsibility for cyber defence, security operations, incident response and vulnerability management, preferably within complex, global or multi-country environments.
- Proven experience leading cybersecurity teams and managing security service providers in distributed organisations; experience in industrial and OT environments is considered a plus.
- Strong knowledge of cybersecurity operations, threat detection, incident response, vulnerability management and security controls, combined with a solid understanding of enterprise IT technologies, modern security architectures and related security technologies and platforms.
- Demonstrated ability to manage high-severity incidents, drive continuous improvement initiatives, define operational processes and performance metrics, and effectively coordinate technical and business stakeholders.
- Hands-on familiarity with security technologies such as SIEM, SOAR, EDR/XDR, network security, cloud security, vulnerability management and threat intelligence platforms is preferred.
- Strong understanding of recognized cybersecurity frameworks and standards, such as NIST and ISO/IEC 27001, with relevant professional certifications (e.g. CISSP, CISM, GIAC or equivalent) considered a plus.
- Excellent leadership, communication and stakeholder management skills, with the ability to translate technical risks into business priorities.
- Fluent English proficiency, both written and spoken.
Equal opportunity, pay transparency & fairness
The compensation package will be determined based on the candidate’s experience, skills and the scope of the role, applying objective and gender-neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone.
As a reference, for this position we offer a salary starting from €52.000 gross per year, depending on the candidate’s experience, skills and the scope of the role. This position is covered by the CCNL Metalmeccanici Industria.
We are committed to the principle of equal employment opportunity for all people. We strive to provide a work environment that is accessible, welcoming and inclusive, in full compliance with applicable legal requirements. In line with this commitment, we promote fair, transparent and equitable reward practices. The compensation package will be determined based on the experience, skills and the scope of the role, applying objective and gender‑neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone.