22 set - Cusano Milanino
Experteer Italy
Specialista Senior / Project Manager
As Information Security Manager at Kuehne+Nagel, you lead governance, risk, and compliance efforts to strengthen cybersecurity and regulatory posture. You will drive NIS2 implementation, partner with IT, Legal, Compliance, and regional security teams, and promote a resilient security culture across the organization. You tackle risk assessments, incident coordination, and third-party security, shaping secure operations for global logistics. This is an opportunity to impact how we protect critical systems and enable trustworthy service delivery.
- safe and stable environment
- international growth opportunities
- teamwork that matters
- flexible work environment
- Lead the implementation of NIS2 requirements with gap assessments, remediation plans, and ongoing monitoring
- Establish and maintain information security governance, policies, and controls aligned with Global and EMEA standards
- Conduct security risk assessments, manage risk treatment plans, and monitor control effectiveness
- Coordinate security incident management and regulatory reporting with IT, Legal, Compliance, and cybersecurity teams
- Support internal and external audits and regulatory inspections with timely remediation of findings
- Drive third-party and supply chain security risk management including supplier assessments and due diligence
- Define, monitor, and report security KPIs and risk metrics to local leadership and EMEA Information Security
- Deliver security awareness initiatives and promote a cybersecurity culture across the organization
- Degree in Information Security, Computer Science, Engineering, Law/Compliance, or equivalent professional experience
- Proven experience in Information Security Governance, Risk & Compliance (GRC) or related security functions
- Experience implementing security frameworks and regulatory requirements (NIS2, ISO 27001, NIST CSF, or CIS Controls)
- Strong knowledge of information security risk management, ISMS processes, and audit readiness
- Good understanding of security domains: vulnerability management, IAM, SIEM, endpoint security, network security, backup and recovery, encryption
- Excellent stakeholder management, communication, and project management skills for technical and non-technical audiences
- Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are advantageous
- Fluent English and professional Italian required
#J-18808-Ljbffr
23 set - Bologna
Gruppo Hera
23 set - Milano
Hitachi Energy
23 set - Treviso
Sinelec
23 set - Milano
Avanade