07 ago - Italia
Ion
ppSecurity Governance Analyst, Italy at Ion. About the role Ion is on the lookout for a dedicated individual to join the Chief Information Security Office team within the Cedacri division. This position involves overseeing security frameworks, conducting risk assessments, and preparing compliance reports. You will collaborate with various departments to uphold our cybersecurity standards and ensure that our practices align with regulatory requirements. /ph3Key facts /h3pLocation: MilanbrEngagement: Full-time (hybrid)brTeam: Chief Information Security Office (CISO) /ph3What you'll do /h3ulliRegularly update and manage documentation related to cybersecurity policies, standards, and governance frameworks to ensure they remain current and effective. /liliPerform thorough risk assessments, monitor remediation activities, and handle security exceptions to mitigate potential vulnerabilities. /liliAssess the maturity of existing security controls to confirm they align with both regulatory requirements and internal objectives. /liliMaintain comprehensive records and evidence necessary for audits, client due diligence processes, and responses to regulatory inquiries. /liliDevelop and manage Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) dashboards that cover critical areas such as patch management, API inventories, and Software Bill of Materials (SBOM) and Software Composition Analysis (SCA) coverage. /liliCollaborate with Legal, Risk, Compliance, and Technology teams to ensure that security requirements are well integrated and understood across the organization. /liliSupport the implementation and adoption of various frameworks, including DORA, NIS2, ISO 27001, and NIST Cybersecurity Framework (CSF).
/liliEngage in continuous improvement initiatives related to cybersecurity governance and compliance processes. /liliProvide training and guidance to staff on security policies and best practices to foster a culture of security awareness. /liliParticipate in incident response activities and contribute to the development of incident response plans. /liliStay updated on the latest cybersecurity trends, threats, and regulatory changes to ensure the organization remains compliant and secure. /liliPrepare reports for senior management that summarize risk assessments and compliance status, along with recommendations for improvement. /li /ulh3Requirements /h3ulliA Master's degree in Cybersecurity, Computer Science, Computer Engineering, IT, Law, or Management Engineering, preferably with honors. /liliBetween 2 to 5 years of relevant professional experience in ICT Risk Management, Information Security Governance, or Cybersecurity Compliance. /liliStrong understanding of governance principles related to incident response, secure Software Development Life Cycle (SDLC), vulnerability management, and third-party risk management. /liliFamiliarity with key frameworks and standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, and NIS2 is essential. /liliProven experience in managing audit processes and regulatory reporting requirements.
/liliExcellent communication skills, particularly the ability to convey technical risk information to management and stakeholders effectively. /liliProficiency in both Italian and English is required to facilitate communication within the team and with external partners. /li /ulh3Nice to have /h3ulliProfessional certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Security+, or ISO 27001 auditor credentials would be advantageous. /liliExperience with cybersecurity tools and technologies that enhance governance and compliance efforts. /liliKnowledge of emerging cybersecurity trends and threats to proactively address potential risks. /li /ulh3Skills tools /h3ulliProficient in Microsoft Excel for data analysis and reporting. /liliSkilled in Microsoft PowerPoint for creating presentations and communicating findings effectively. /li /ulh3Practical notes /h3ulliCompensation: The gross annual salary (RAL) for this position ranges from 40,000 to 50,000 Euros, depending on the candidate's experience and qualifications. /liliContract: This is a permanent role governed by the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico). /liliGrade: The final job grade will be determined at the conclusion of the selection process, likely at levels B2 or B3. /liliPriority: Candidates who are registered under Italian Law (L.68/99) for protected categories will be given preference in the hiring process. /li /ulpThis role at Ion offers a unique opportunity to contribute to the cybersecurity landscape within a dynamic organization. /p /p #J-18808-Ljbffr
08 ago - Carini
Mary
08 ago - Melegnano
Sicurezza e Gestioni
08 ago - Napoli
Ilaria
08 ago - Milano
dalia2