21 set - Bardi
Lifted, an Upwork
ppThis opportunity is ideal for an experienced Information Security professional with knowledge of bcybersecurity governance, risk management, compliance, and incident response /b.
/p h3What You'll Do: /h3 ul liConduct cybersecurity risk assessments for COET srl.
/li liAnalyze threats, vulnerabilities, control effectiveness, and residual risks.
/li liMaintain and update cybersecurity risk registers.
/li liTrack risk mitigation and remediation activities through completion.
/li liRecommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
/li liDevelop and monitor cybersecurity policies, standards, and control requirements.
/li liReview risk assessments, mitigation plans, exceptions, and risk acceptance requests.
/li liSupport cybersecurity governance forums and reporting activities.
/li liAssist with internal and external cybersecurity audits.
/li liCoordinate evidence collection and remediation tracking.
/li liAssess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.
/li liSupport control assessments and gap analyses.
/li liPrepare materials for management and governance reviews.
/li liEscalate significant cybersecurity risks and emerging trends.
/li liCollaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
/li liProvide guidance on cybersecurity risk management processes and requirements.
/li liPromote cybersecurity awareness and risk-informed decision-making.
/li /ul h3Nice to Haves: /h3 ul liExperience in Information Security governance,
risk management, compliance, and incident response.
/li liKnowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO *****, and GDPR.
/li liCISSP, CISM, or an equivalent certification is desirable.
/li liFluency in both Italian and English.
/li liStrong communication and stakeholder management skills.
/li liAbility to work independently and collaborate with cybersecurity and business teams.
/li liCybersecurity risk assessments and updated risk registers.
/li liRisk mitigation and remediation tracking.
/li liCybersecurity policies, standards, and control requirements.
/li liAudit evidence, control assessments, and gap analysis support.
/li liGovernance review materials and cybersecurity reporting.
/li /ul h3Location Requirement /h3 ul liOn-site presence at COET premises in bSan Donato Milanese, Italy /b, at least b3 times per month /b.
/li /ul h3Additional Information /h3 ul libCategory: /b Information Security Compliance /li libDuration: /b September 14, **** to September 14, **** /li liThe client is still evaluating the appropriate engagement structure.
The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
/li liCandidates should be comfortable proceeding under either engagement structure.
If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.
/li /ul pCybersecurity Governance, Risk Compliance (GRC) Consultant • San Donato Milanese, Lombardy, Italy /p /p #J-*****-Ljbffr
24 set - Cinisello Balsamo
Manpowergroup
24 set - Italia
MAURELLI GROUP
24 set - Italia
AYES - Management & Technology Consulting
24 set - Veneto
Alpinestars