Security Governance Analyst, Italy (Roma)

Security Governance Analyst, Italy (Roma)

07 ago
|
Altro
|
Roma

07 ago

Altro

Roma

Security Governance Analyst, Italy at Ion. About the role Ion is on the lookout for a dedicated individual to join the Chief Information Security Office team within the Cedacri division. This position involves overseeing security frameworks, conducting risk assessments, and preparing compliance reports. You will collaborate with various departments to uphold our cybersecurity standards and ensure that our practices align with regulatory requirements.

Continui a leggere per scoprire di cosa avrà bisogno per avere successo in questa posizione, incluse competenze, qualifiche ed esperienza.
Key facts

Location: Milan
Engagement: Full-time (hybrid)
Team: Chief Information Security Office (CISO)
What you'll do

Regularly update and manage documentation related to cybersecurity policies, standards, and governance frameworks to ensure they remain current and effective.
Perform thorough risk assessments, monitor remediation activities, and handle security exceptions to mitigate potential vulnerabilities.
Assess the maturity of existing security controls to confirm they align with both regulatory requirements and internal objectives.
Maintain comprehensive records and evidence necessary for audits, client due diligence processes, and responses to regulatory inquiries.
Develop and manage Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) dashboards that cover critical areas such as patch management, API inventories, and Software Bill of Materials (SBOM) and Software Composition Analysis (SCA) coverage.
Collaborate with Legal, Risk, Compliance, and Technology teams to ensure that security requirements are well integrated and understood across the organization.
Support the implementation and adoption of various frameworks,



including DORA, NIS2, ISO 27001, and NIST Cybersecurity Framework (CSF).
Engage in continuous improvement initiatives related to cybersecurity governance and compliance processes.
Provide training and guidance to staff on security policies and best practices to foster a culture of security awareness.
Participate in incident response activities and contribute to the development of incident response plans.
Stay updated on the latest cybersecurity trends, threats, and regulatory changes to ensure the organization remains compliant and secure.
Prepare reports for senior management that summarize risk assessments and compliance status, along with recommendations for improvement.
Requirements

A Master's degree in Cybersecurity, Computer Science, Computer Engineering, IT, Law, or Management Engineering, preferably with honors.
Between 2 to 5 years of relevant professional experience in ICT Risk Management, Information Security Governance, or Cybersecurity Compliance.
Strong understanding of governance principles related to incident response, secure Software Development Life Cycle (SDLC), vulnerability management, and third-party risk management.
Familiarity with key frameworks and standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, and NIS2 is essential.




Proven experience in managing audit processes and regulatory reporting requirements.
Excellent communication skills, particularly the ability to convey technical risk information to management and stakeholders effectively.
Proficiency in both Italian and English is required to facilitate communication within the team and with external partners.
Nice to have

Professional certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Security+, or ISO 27001 auditor credentials would be advantageous.
Experience with cybersecurity tools and technologies that enhance governance and compliance efforts.
Knowledge of emerging cybersecurity trends and threats to proactively address potential risks.
Skills & tools

Proficient in Microsoft Excel for data analysis and reporting.
Skilled in Microsoft PowerPoint for creating presentations and communicating findings effectively.
Practical notes

Compensation: The gross annual salary (RAL) for this position ranges from 40,000 to 50,000 Euros, depending on the candidate's experience and qualifications.
Contract: This is a permanent role governed by the Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
Grade: The final job grade will be determined at the conclusion of the selection process, likely at levels B2 or B3.
Priority: Candidates who are registered under Italian Law (L.68/99) for protected categories will be given preference in the hiring process. xlwpduy
This role at Ion offers a unique opportunity to contribute to the cybersecurity landscape within a dynamic organization.

#J-18808-Ljbffr

📌 Security Governance Analyst, Italy (Roma)
🏢 Altro
📍 Roma

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: security governance analyst, italy (roma) / roma

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: security governance analyst, italy (roma) / roma