23 ago - Ispra
MEERAB GROUP
- Definition of compliance requirements for JRC information‑system controls, in close collaboration with the System owners and System managers
- Preparation of templates covering security processes, controls and technical solutions across all JRC digital services
- Support System Owners and IT service providers with the elaboration of their:
- Business Impact Assessment and Scope of Security
- Risk Assessment exercise
- Security Plan
- Secure System Architecture Design
- Implementation Plan
- Assistance with the management of remediation activities, including tracking of non‑conformities, assignment of corrective actions to system owners and verification of their closure within agreed time‑frames
- Development and maintenance of security baselines for the JRC systems and services
- Coordination and review of risk‑assessments, ensuring that identified risks are evaluated against the defined compliance criteria and that mitigation measures are documented
- Reporting of compliance status to the JRC LISO, highlighting gaps and progress on remediation
- Interaction with system owners and IT service providers and other relevant Commission services to ensure consistent in
Requirements
- 2 years of post-secondary education or higher
- Good knowledge of ISO 27000 family of standards, the EC Security Policies, the EC Risk‑management methodology and related risk‑assessment techniques
- Good experience in the security domain, including the development and review of security methodologies, Business Impact Assessments,
Risk Assessments and Secure System Architecture Design
- Ability to review draft Security Plans and related security‑plan material efficiently and fast
- Ability to give business and technical presentations to system owners, IT service providers
- Ability to apply high quality standards in documentation, template creation and guidance material for security planning
- Ability to cope with fast changing technologies used in cloud services, AI‑driven applications and other digital services within the JRC environment
- Very good communication skills with technical and non-technical audiences to facilitate multilingual, multicultural meetings and stakeholder engagement
- Analysis and problem solving skills
- Capability to write clear and structured technical documents
- Ability to participate in technical meetings and good communication skills
- Relevant certifications in Governance, Risk and Compliance or Risk Management and Audit or broad Cybersecurity are an advantageous asset (CGRC, CRISC, CISA, CISSP, CISM, etc..)
- Ability to integrate in an international/multicultural environment, rapid self-starting capability and experience in working in team;
- Ability to participate in multilingual meetings;
- Ability to work in multi-cultural environment, on multiple large projects;
- Ability to establish trusting relationships with counterparts in partnering organizations;
- Excellent team player
- Ability to understand, speak and write English C1 will be an advantage;
- High degree of discretion and integrity.
24 ago - Italia
Club Esse
24 ago - Porto Recanati
SIME
24 ago - Italia
Rödl
24 ago - Roma
Installazioni Impianti