Cybersecurity Governance, Risk & Compliance (Grc) Consultant

22 set - Bardi
Lifted, an Upwork

This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response .

What You’ll Do:

- Conduct cybersecurity risk assessments for COET srl.
- Analyze threats, vulnerabilities, control effectiveness, and residual risks.
- Maintain and update cybersecurity risk registers.
- Track risk mitigation and remediation activities through completion.
- Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
- Develop and monitor cybersecurity policies, standards, and control requirements.
- Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
- Support cybersecurity governance forums and reporting activities.
- Assist with internal and external cybersecurity audits.
- Coordinate evidence collection and remediation tracking.
- Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.
- Support control assessments and gap analyses.
- Prepare materials for management and governance reviews.
- Escalate significant cybersecurity risks and emerging trends.
- Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
- Provide guidance on cybersecurity risk management processes and requirements.
- Promote cybersecurity awareness and risk-informed decision-making.

Nice to Haves:

- Experience in Information Security governance, risk management,



compliance, and incident response.
- Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.
- CISSP, CISM, or an equivalent certification is desirable.
- Fluency in both Italian and English.
- Strong communication and stakeholder management skills.
- Ability to work independently and collaborate with cybersecurity and business teams.
- Cybersecurity risk assessments and updated risk registers.
- Risk mitigation and remediation tracking.
- Cybersecurity policies, standards, and control requirements.
- Audit evidence, control assessments, and gap analysis support.
- Governance review materials and cybersecurity reporting.

Location Requirement

- On-site presence at COET premises in San Donato Milanese, Italy , at least 3 times per month .

Additional Information

- Category: Information Security & Compliance
- Duration: September 14, 2026 to September 14, 2027
- The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
- Candidates should be comfortable proceeding under either engagement structure. If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.

Cybersecurity Governance, Risk & Compliance (GRC) Consultant • San Donato Milanese, Lombardy, Italy

#J-18808-Ljbffr

Luxury Travel Consultant

23 set - Roma
Meet and Greet Italy

Macchinista di Linea

23 set - Montone
Openjobmetis

Ricevi nuove offerte di lavoro

Crea una Job Alert gratuita per cybersecurity governance, risk & compliance (grc) consultant / bardi

M Associate

23 set - Milano
MindMatch

Magazziniere - €1.700 al mese

23 set - Vigevano
Adecco Italia