Security Governance Analyst, Italy (Milano)

Security Governance Analyst, Italy (Milano)

02 ago
|
Informatica / Software
|
Milano

02 ago

Informatica / Software

Milano

About us: We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions.

We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri's companies, part of ION Group, we are looking for talented professionals to grow their career as Security Governance Analyst. This position is targeted at candidates with 2–5 years of relevant experience in Information Security Governance, Cybersecurity Risk Management, or ICT Compliance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross‐functional teams to support cybersecurity governance initiatives across the organization.

Learn more at

Your role Your key duties and responsibilities Support the implementation and continuous improvement of the Information Security Governance framework

Support the implementation, maintenance, and continuous improvement of the Information Security Governance framework across the organization

Develop, maintain, and review cybersecurity policies, standards, procedures, and governance documentation

Support cybersecurity risk management activities, including risk assessments, remediation tracking, exception management, and risk treatment planning





Monitor the effectiveness and maturity of security controls and ensure governance activities remain aligned with organizational objectives and regulatory requirements

Maintain governance evidence, action plans, ownership records, dependencies, and remediation initiatives to support audit readiness and effective reporting

Prepare KPI/KRI dashboards for management on coverage, timeliness and effectiveness of controls, including asset/API inventories, SBOM/SCA coverage, patching performance, exception aging and action‐plan closure

Collaborate with Technology, Risk, Compliance, Legal, and Business stakeholders to ensure alignment with security governance requirements

Support internal audits, external audits, regulatory assessments, and client due diligence activities

Contribute to the implementation of regulatory and industry frameworks, including DORA, NIS2, ISO 27001, NIST CSF, and related standards

Support governance transformation initiatives and continuous improvement programs aimed at strengthening cybersecurity oversight capabilities

Other duties We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Law, Management Engineering, or a related field (with honors)

At least 2-5 years of experience in Information Security Governance,



ICT Risk Management, Cybersecurity Compliance, Internal Audit, or related functions

Good understanding of cybersecurity governance principles, governance requirements for vulnerability management, patch management, incident response, secure SDLC, third‐party risk and operational resilience

Knowledge of international standards and frameworks such as ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, and NIS2

Experience supporting audit activities, compliance assessments, regulatory initiatives, or governance reporting processes

Ability to translate complex technical topics into clear governance, risk, and management reporting outputs

Strong analytical, organizational, and stakeholder management skills

Advanced knowledge of Microsoft Excel and PowerPoint

Excellent knowledge of Italian and English

Professional certifications such as ISO 27001, CISA, CRISC, Security+, or equivalent would be considered a plus

What we offer: Permanent employment contract

Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)

Gross Annual Salary (RAL) ranging from €40,000 to €50,000, depending on experience, skills, and qualifications

Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level

Opportunity to join a leading international technology group operating in the financial services industry

Exposure to enterprise-wide cybersecurity governance activities in a dynamic and international environment

Location: Milan

Important notes: According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.

📌 Security Governance Analyst, Italy (Milano)
🏢 Informatica / Software
📍 Milano

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: security governance analyst, italy (milano) / milano

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: security governance analyst, italy (milano) / milano