Corporate Cyber Security Senior Analyst
About Barilla
At Barilla, we believe that every great journey begins with passion and a bold vision. From our humble beginnings in 1877 in a small shop in Parma, Italy, we’ve blossomed into a global leader in the food industry, guided by our commitment to progress and excellence.
Today, Barilla is an international group present in more than 100 countries and we are proud to be recognized as the world’s top food company by reputation. With 22 beloved brands in our portfolio, we are world leader for pasta, the number one choice for ready-made sauces in Europe, leader for bakery products in Italy, and for crispbread across Scandinavia with Wasa.
Our success story is written by a passionate team of almost 9,000 dedicated employees across 30 plants and offices worldwide, all united by a shared mission to nourish the future with purpose and passion.
Are you ready to add your unique flavor to our journey?
Position Summary
The Cyber Security Senior Analyst operates within the Global Corporate Cybersecurity team (distinct from Regional and Plant roles) and supports the secure and resilient operation of Barilla's global digital environment through hands-on cybersecurity operations and engineering, technical oversight of external managed services and delivery of cybersecurity change.
Reporting to the Global Corporate Cybersecurity Manager, the role is part of the Cybersecurity Director's organisational line and may engage directly with the Director on delegated activities, technical reviews, management-review inputs or major escalations. It has no internal direct reports but may technically supervise service providers, consultants and specialists. It leads low- and medium-complexity cybersecurity initiatives, owns assigned work packages within high- or critical-complexity programmes, and is a core operational contributor to incident response and threat hunting. It supports the Information Security Management System and the NIS2 obligations applicable to Barilla as an important entity in the food sector.
Key Responsibilities & Deliverables
- Operate, administer and continuously improve assigned corporate cybersecurity technologies and services across hybrid cloud, on-premises and SaaS environments. Reliable lifecycle and health management for assigned controls, CTI integrations and telemetry pipelines, covering connector health, ingestion completeness, latency, duplication and normalisation across hybrid cloud, on-premises, SaaS and relevant IT/OT environments.
Tested changes and proofs of concept, current operating guides, controlled handovers to application-management services and a prioritised improvement backlog. - Perform detection engineering, CTI feed and platform integration, IoC operationalisation, threat hunting and evidence-led incident response, complementing and challenging external SOC, MDR and specialist services. Correlated investigations and attack-chain timelines that distinguish compromise, misconfiguration, false positives and authorised activity, with authorised containment and recovery validation.
Validated CTI source/role mappings and IoC propagation; hunting queries and detections tested on representative telemetry for KQL/schema, cadence/lookback, severity, entity mapping, exclusions/watchlists, overlap, false positives and SOAR thresholds; improved playbooks. - Provide technical input to cybersecurity service sourcing, renewal and transition, and task, coordinate, review and challenge delivery by managed services, consultants and providers. Collaborate with third-party partners and suppliers to support the delivery of cybersecurity services and initiatives, ensuring effective execution and alignment with organizational security requirements. Evidence-based inputs to service requirements, evaluations, renewals and transitions; clear priorities, capacity/coverage visibility, reconciled queues, verified SLAs/KPIs/quality and delegated technical validation or acceptance.
Challenged findings, tracked escalations and corrective actions, acceptance evidence for service transitions and SIEM/SOAR changes, measurable improvement and knowledge transfer. - Perform risk-based vulnerability, exposure and secure-configuration or hardening management, including urgent and zero-day cases, for the Corporate scope and relevant IT/OT interfaces. Validated findings prioritised by exploitability, threat context, asset criticality and business impact, with accountable remediation owners and target dates.
Risk-based remediation plans and tracked exceptions with owners and dates; verified closure or documented acceptance by the accountable risk owner; consolidated backlogs, metrics and escalation of overdue critical actions. - Perform security-by-design and supplier security reviews, support GDPR privacy-by-design technical requirements in coordination with Privacy/DPO, and deliver cybersecurity projects and changes: lead low- and medium-complexity initiatives and own assigned work packages in high- or critical-complexity programmes. Documented security and privacy requirements, architecture and risk reviews, supplier assessments, legal or contractual dependencies, go/no-go conditions, compensating controls and register or TIS outcomes.
Test and acceptance evidence, implementation and rollback plans, controlled handover to operations, updated runbooks and timely escalation of risks, dependencies and decisions. - Support secure identity and access management, including privileged access, access governance and investigation of anomalous or high-risk access conditions. Reviewed technical requirements and access-control configurations, with identified exceptions, anomalies and corrective actions.
Reliable evidence and corrective actions for access reviews, privileged and emergency access and account-lifecycle processes, including authorised session-revocation and password-reset support during incidents. - Maintain operational procedures, response readiness and control evidence supporting cybersecurity governance, risk management, ISO/IEC 27001 and NIS2 implementation. Current procedures, playbooks, contact/escalation matrices, IT/OT hand-offs and response plans; documented contributions to tabletop exercises and standards, with tracked actions.
Control evidence, KPIs and action tracking for risks and audits, plus verified inputs to NIS2 incident assessment, escalation and notification workflows. - Analyse cybersecurity performance and emerging threats, communicate risk and recommend practical improvements to controls, services and technologies. Concise technical and management reporting based on meaningful service, incident, vulnerability and control-effectiveness metrics.
Job Requirements and Qualifications
- Bachelor's degree or national equivalent in Cybersecurity, Information Security, Computer Science, ICT/Engineering or a related field. Equivalent demonstrable technical training and hands-on experience may be considered.
- Typically at least 2 years of relevant hands-on experience in cybersecurity operations, security engineering, system/network/cloud security or consulting in a structured environment. Candidates with less experience may be considered where demonstrated ability is supported by relevant cybersecurity internships or apprenticeships, hands-on SOC/incident-response practice, or a recognised Information/Cyber Security certification.
- Professional English fluency is mandatory; Italian is mandatory.
- Hands-on experience with Microsoft security or comparable platforms (e.g. Azure/Entra ID/Microsoft 365, Defender XDR, Sentinel)
- Scripting or automation language such as PowerShell or Python.
- Working knowledge of ISO/IEC 27001:2022 and 27002:2022, NIST Cybersecurity Framework 2.0, NIS 2. Knwoledge of CTI/TIP (MISP, STIX/TAXII), IAM/PAM, vulnerability management, and email, web, network or cloud controls will be considered a plus.
Compensation package
- The gross annual base salary (RAL) offered will be no less than € 38.000, in accordance with the provisions of the applicable National Collective Bargaining Agreement (CCNL Industria Alimentare)
- The Company is committed to offering a competitive compensation package and, following the selection process, may propose a final gross annual base salary above the stated level, commensurate with the candidate's experience, skills, and qualifications
Additional information
- Type of contract: permanent contract
- Location: Parma HQ
At Barilla, we are committed to creating an inclusive and equitable workplace where diversity in all its forms is valued and embraced. Our employment policies and practices are designed to ensure equal employment opportunities for all, regardless of age, race, color, citizenship, faith, religion, creed, gender, sex, pregnancy, gender identity or characteristics of expression, sexual orientation, marital status, genetic information, medical condition, protected veteran status, disability, or any other characteristic protected by law. Our commitment to equal employment stems from our unwavering belief that it is not only the right thing to do, but it is also a fundamental driver of innovation and business success.