Information Security - Identity Lifecycle Management

31 lug - Milano
EssilorLuxottica

ppbCompensation /b /p /brpbIf you’ve worn a pair of glasses, we’ve already met. /b We are a global leader in the design, manufacture, and distribution of ophthalmic lenses, frames, and sunglasses. We offer our industry stakeholders in over b150 countries /b access to a global platform of high-quality vision care products (such as the Essilor brand, with Varilux, Crizal, Eyezen, Stellest and Transitions), iconic brands that consumers love (such as Ray-Ban, Oakley, Persol, Oliver Peoples, Vogue Eyewear and Costa), as well as a network that offers consumers high-quality vision care and best-in-class shopping experiences (such as Sunglass Hut, LensCrafters, Salmoiraghi Viganò and the GrandVision network), and leading e-commerce platforms. /p /brpJoin our global community of over b190 000 /b bdedicated /b bemployees /b around the world in driving the transformation of the eyewear and eyecare industry. /p /brpDiscover more by following us on LinkedIn! /p /brpbYour #FutureInSight with EssilorLuxottica /b /p /brpAre you willing to pioneer new frontiers, foster inclusivity and collaboration, embrace agility, ignite passion, and make a positive impact on the world? Join us in redefining the boundaries of what’s possible. /p /brh3Your role /h3 /brpYou will be responsible for the management and coordination of activities within Company’s Information Security Master Plan, related to Identity Lifecycle management and SoD Project and Initiatives. As Information Security Governance specialist you will be working across multiple teams, interacting with both IT and Business stakeholders, to facilitate, coordinate, advise, monitor and enable the implementation of the Information Security policies. This role will support the execution of strategic and cross-functional initiatives across the Governance domain, with a focus on awareness, training programs, project coordination, process and procedures risk management and security compliance. /p /brh3Main Responsibilities /h3 /brul /brliInformation Security Planning - Plan and estimate budget and time schedule for activities to be included into Information Security Master Plan. /li /brliOversight on maintenance and implementation of Information Security policies / procedures - Ensure the oversight of the implementation of the activities, identifying and reporting issues, risks and opportunities to the CISO / relevant stakeholders. /li /brliDesign and deliver awareness campaigns, workshops, and training initiatives tailored to different audiences. /li /brliSupport the selection and evaluation of training content and platforms, in collaboration with HR, Communication and other providers. /li /brliContribute to the definition and review of Identity Lifecycle models and controls and Segregation of Duties (SoD) in collaboration with Business owners, IT, HR, Risk Management, Privacy and Compliance, Internal Control and Internal Audit. /li /brliLead and coordinate the Identity Lifecycle and SoD projects for non-finance areas (i.e. SAP modules MM and SD),



ensuring the extension of Identity Management governance to all business applications and data repositories. /li /brliCollaborate with HR Business Partners (HRBP), Business Process Owners (BPO), and IT to define, implement, and maintain a centralized Role-Based Access Control (RBAC) library. /li /brliMap, monitor, and evaluate application profiles (especially administrative roles) for non-finance departments, identifying anomalies and enforcing segregation of duties. /li /brliSupervise and execute risk assessments for access requests outside the standard RBAC library, defining exception workflows and compensating controls. /li /brliValidate new access or function requests against the approved role library and assess risks for exceptions or non-standard assignments. /li /brliDefine and enforce control processes for access provisioning, exception handling, and periodic reviews, including onboarding, role/function changes, and offboarding. /li /brliCollaborate on the design and implementation of automated processes for onboarding, role changes, and offboarding, ensuring integration with HRIS and target systems. /li /brliSupport the periodic review and maintenance of the RBAC role library, working closely with HRBP and BPOs to refine roles and ensure SoD is maintained. /li /brliParticipate in incident investigations related to identity and access management, analyzing root causes and recommending improvements to lifecycle and SoD controls. /li /brliPromote awareness and training on SoD principles and identity governance among business stakeholders, HR, and IT. /li /brliAct as a governance and control point within the Identity Lifecycle Management process, ensuring that access delegation requests are appropriate, risk-assessed, and aligned with the RBAC model and SoD process. /li /brliContribute to the definition and review of SoD models and controls in collaboration with IT, Internal Control, HR, Risk Management and Internal Audit. /li /brliDefine and maintain a comprehensive KPI framework for RBAC lifecycle governance, including the design of automated dashboards and anomaly-detection metrics, the setup of threshold-based alerts and escalation workflows, and the regular reporting of access-governance performance and identified risks to the appropriate security and risk committed /li /br /ul /brh3Main Requirements /h3 /brul /brliBachelor’s degree in information security, Information Technology, Computer Science, Engineering,



Statistical or similar /li /brliAt least 2 years of experience gained in the ICT Risk Management or Security area with particular focus on the Identity Management and Segregation of Duties; /li /brliKnowledge of SAP Basis especially on User Profile Security Management /li /brliKnowledge of SAP GRC tool for risk analysis /li /brliKnowledge of relevant business processes (i.e. Make - to - Deliver, Procure to Pay, Hire to Retire) /li /brliKnowledge of international standards and best practices in domain of Information Security, Data Protections and Business Continuity (e.g. GDPR, ISO 27001, NIST 800-53, NIS2 etc.) /li /brliKnowledge of relevant Information Security / Data Protection laws and regulations (e.g. Privacy, Health sensitive information, PCI DSS) /li /brliUnderstanding of regulatory requirements for AI systems (ISO/IEC 42001:2023) /li /brliGood project management skills, teamwork and individual accountability /li /brliAdequate data analytic fundamental skills /li /brliProven ability to communicate to all levels in a technical and non-technical manner /li /brliKnowledge about most common IT Security solutions. /li /brliExcellent oral and written English language skills /li /br /ul /brh3Optional Requirements /h3 /brul /brliProfessional information security certifications (such as CISM, ISO 27001 Lead Auditor, CISSP, CISA) /li /br /ul /brh3What’s In It For You /h3 /brpIn EssilorLuxottica, you are not defined just by your job title. Each career adventure is unique; have a glimpse of some of the benefits you will enjoy as a successful candidate: /p /brul /brliAccess to our cutting-edge learning platform, Leonardo, and personalized development programs to help you grow professionally and personally. /li /brliEnjoy flexible work conditions, health insurance coverage, ticket restaurants, internal rooftop canteen. /li /brliAccess special offers for employees on a vast range of eyewear, eye care products, and fashion apparel, so you can enjoy our world-class brands firsthand. /li /brliEnjoy our "Disconnect Program" a holistic approach to work-life balance, including initiatives for mental health, yoga, jogging sessions, and more, designed to help you recharge and stay healthy. /li /br /ul /brh3Recruiting process /h3 /brpOur recruitment process may vary; If you are selected, you will be contacted by our recruiters to guide you through the specific steps for your application. /p /brh3Salary Package /h3 /brul /brliAnnual Gross Salary: 35 .500 Eur - 53.000 Eur /li /brliComprehensive Benefits Package: /brul /brliSupplementary Health insurance coverage /li /brliSupplementary Pension Plan /li /brliAccess to the EssilorLuxottica Corporate Welfare Catalog /li /brliTransportation - Discounted pass /li /brliMeal Vouchers as per company guidelines /li /brliExclusive employee discounts on company products /li /brliCompany-provided laptop and mobile phone /li /br /ul /br /li /br /ul /brh3Our Diversity, Equity and Inclusion commitment /h3 /brpWe are committed to creating an inclusive environment for all employees. We celebrate diversity and provide equal opportunities to all, regardless of race, gender, ethnicity, religion, disability, sexual orientation, or any other characteristic that makes we unique. /p /p #J-18808-Ljbffr

131- Corso di amministrazione del personale in azienda, paghe e contributi - per destinatari di AssegnoVERONA

06 ago - Sommacampagna
PENTA FORMAZIONE

106387 - It Manager

06 ago - Bresso
ETJCA

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per information security - identity lifecycle management / milano

105917 - Carrellista

06 ago - Creazzo
Ali S. P. A

102929 - Addetto Alla Logistica - €28.000 All'Anno

06 ago - Vicenza
Adecco Italia