Security Governance Analyst, Italy

31 lug - Milano
Ion

ph3About us: /h3 pWe are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world.
We strive to simplify the way people work.
We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions.
We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.
/p pFor the strengthening of the Chief Information Security Office (CISO) function within Cedacri's companies, part of ION Group, we are looking for talented professionals to grow their career as bSecurity Governance Analyst /b.
This position is targeted at candidates with b2–5 years of relevant experience /b in Information Security Governance, Cybersecurity Risk Management, or ICT Compliance.
Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to support cybersecurity governance initiatives across the organization.
/p pLearn more at /p h3Your role /h3 h3Your key duties and responsibilities /h3 ul liSupport the implementation and continuous improvement of the Information Security Governance framework /li liSupport the implementation, maintenance, and continuous improvement of the Information Security Governance framework across the organization.
/li liDevelop, maintain, and review cybersecurity policies, standards, procedures, and governance documentation.
/li liSupport cybersecurity risk management activities, including risk assessments, remediation tracking, exception management, and risk treatment planning.




/li liMonitor the effectiveness and maturity of security controls and ensure governance activities remain aligned with organizational objectives and regulatory requirements.
/li liMaintain governance evidence, action plans, ownership records, dependencies, and remediation initiatives to support audit readiness and effective reporting.
/li liPrepare KPI/KRI dashboards for management on coverage, timeliness and effectiveness of controls, including asset/API inventories, SBOM/SCA coverage, patching performance, exception aging and action-plan closure.
/li liCollaborate with Technology, Risk, Compliance, Legal, and Business stakeholders to ensure alignment with security governance requirements.
/li liSupport internal audits, external audits, regulatory assessments, and client due diligence activities.
/li liContribute to the implementation of regulatory and industry frameworks, including DORA, NIS2, ISO *****, NIST CSF, and related standards.
/li liSupport governance transformation initiatives and continuous improvement programs aimed at strengthening cybersecurity oversight capabilities.
/li /ul h3Other duties /h3 pWe might ask you to perform other tasks and duties as your role expands.
/p h3Your skills, experience, and qualifications required /h3 ul liMaster's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Law, Management Engineering, or a related field (with honors).
/li liAt least 2-5 years of experience in Information Security Governance, ICT Risk Management,



Cybersecurity Compliance, Internal Audit, or related functions.
/li liGood understanding of cybersecurity governance principles, governance requirements for vulnerability management, patch management, incident response, secure SDLC, third-party risk and operational resilience.
/li liKnowledge of international standards and frameworks such as ISO *****, NIST CSF, COBIT, CIS Controls, DORA, and NIS2.
/li liExperience supporting audit activities, compliance assessments, regulatory initiatives, or governance reporting processes.
/li liAbility to translate complex technical topics into clear governance, risk, and management reporting outputs.
/li liStrong analytical, organizational, and stakeholder management skills.
/li liAdvanced knowledge of Microsoft Excel and PowerPoint.
/li liExcellent knowledge of Italian and English.
/li liProfessional certifications such as ISO *****, CISA, CRISC, Security+, or equivalent would be considered a plus.
/li /ul h3What we offer: /h3 ul liPermanent employment contract /li liItalian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico) /li liGross Annual Salary (RAL) ranging from b€40,000 to €50,000 /b, depending on experience, skills, and qualifications /li liJob grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level /li liOpportunity to join a leading international technology group operating in the financial services industry /li liExposure to enterprise-wide cybersecurity governance activities in a dynamic and international environment /li /ul h3Location: /h3 pMilan.
/p h3Important notes: /h3 pAccording to the Italian Law (L.*****), candidates belonging to the protected categories list will be given priority.
/p /p #J-*****-Ljbffr

Operai imbianchini/verniciatori

07 ago - Ambivere
MD Consulting srls

Cintabile amministrativo

07 ago - Ottaviano
planeta

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per security governance analyst, italy / milano

Aiutante pizzaiolo

07 ago - Catania
Pizzeria fratelli pomodoro di Riccardo Patti

Autista di autoarticolati-ravenna (ra)-#25109

07 ago - Ravenna
Lavora con noi italia srls