14 set - Milano
Kühne + Nagel
OverviewIn this role you strengthen the company's cybersecurity posture by leading governance, risk, and compliance efforts with a focus on NIS2.
You collaborate with IT, Legal, Compliance, and regional security teams to ensure regulatory alignment and a resilient security culture.
You'll drive security improvements across the organization, including third-party risk and incident management, while supporting audits and KPI reporting.
This is a chance to shape security programs at a global logistics leader, with impact across global operations.
Retribuzione / Benefitssafe and stable environment
focus on well-being
professional growth and development
international opportunities
supportive teamwork
innovative culture and continuous improvement
ResponsabilitàLead the implementation of NIS2 requirements including gap assessments, remediation plans, and ongoing compliance monitoring
Establish and maintain information security governance, policies, and controls aligned with Global and EMEA standards
Conduct security risk assessments, manage risk treatment plans, and monitor control effectiveness
Coordinate security incident management and regulatory reporting with IT, Legal, Compliance, and cyber teams
Support internal and external audits, regulatory inspections, and timely remediation of findings
Drive third-party and supply chain security risk management including supplier due diligence
Define, monitor, and report security KPIs and risk metrics to local leadership and EMEA Information Security
Deliver security awareness initiatives and promote cybersecurity and compliance culture across the organization
Requisiti fondamentaliDegree in Information Security, Computer Science, Engineering, Law/Compliance, or equivalent professional experience
Proven experience in Information Security Governance, Risk & Compliance (GRC) or related security functions
Experience implementing security frameworks and regulatory requirements (ideally NIS2, ISO *****, NIST CSF, or CIS Controls)
Strong knowledge of information security risk management, ISMS processes, and audit readiness
Understanding of cybersecurity domains such as vulnerability management, IAM, SIEM, endpoint security, network security, backup and recovery, and encryption
Excellent stakeholder management, communication, and project management skills
Relevant certifications such as CISSP, CISM, CRISC, or ISO ***** Lead Implementer/Auditor are advantageous
Fluent English and professional Italian
Stakeholder management
Clear communication
Project management
Vulnerability management
IAM
SIEM
16 set - Lissone
Adecco Italia
16 set - Somma Lombardo
SAMARCANDA
16 set - Catanzaro
Gierre Contact Call Center
16 set - Avigliana
Gelati PEPINO 1884