Compliance Specialist (IT) (Pavia)

Compliance Specialist (IT) (Pavia)

05 set
|
Changetheblock
|
Pavia

05 set

Changetheblock

Pavia

pThe JRC Local Informatics Security Officer (LISO) with in the directorate JRC.T (Digital Transformation, AI and Data), in partnership with other Commission services and stakeholders, has among his responsibilities to ensure that, in JRC, adequate security measures are in place and operational for the information systems and their supporting IT infrastructures, enabling the successful implementation of the Commission's Digital Transformation and EU policies. /ppThe Commission's adopted comprehensive standards on Information Systems Security, established through Decision 2017/46, mandate that all critical information receives appropriate protection levels consistently across the European Commission. These standards require that suitable security controls are systematically identified and integrated into Commission Information Systems. /ppTo support the JRC System Owners and IT service providers in being compliant with these requirements, the LISO requires specialized technical expertise to advise on the implementation of the EC cybersecurity policy within JRC, conduct reviews of processes and controls to assess their effectiveness and overall alignment with the EC regulatory frameworks and policies. /ppbr/pulliDescription of the tasks /li /ulpThe external service provider will perform the following tasks: /pulliDefinition of compliance requirements for JRC information‑system controls, in close collaboration with the System owners and System managers /liliPreparation of templates covering security processes, controls and technical solutions across all JRC digital services /liliSupport System Owners and IT service providers with the elaboration of their:



/liliBusiness Impact Assessment and Scope of Security /liliRisk Assessment exercise /liliSecurity Plan /liliSecure System Architecture Design /liliImplementation Plan /liliAssistance with the management of remediation activities, including tracking of non‑conformities, assignment of corrective actions to system owners and verification of their closure within agreed time‑frames /liliDevelopment and maintenance of security baselines for the JRC systems and services /liliCoordination and review of risk‑assessments, ensuring that identified risks are evaluated against the defined compliance criteria and that mitigation measures are documented /liliReporting of compliance status to the JRC LISO, highlighting gaps and progress on remediation /liliInteraction with system owners and IT service providers and other relevant Commission services to ensure consistent interpretation and application of security policies /li /ulpbr/ppLevel of education /ppAs stated in section 5.1 of FREIA Specifications for the technical profiles for operational services the minimum educational qualification is a Level of education corresponding to Level 5 of the European Qualification Framework, which typically corresponds to 2 years of post-secondary education or higher, for the Junior and Confirmed seniority levels, and a Level of education corresponding to Level 6 of the European Qualification Framework,



which typically corresponds to a Bachelor degree or higher, for the Senior seniority levels. /ppbr/ppSpecific knowledge, skills and expertise /ppThe following specific knowledge, skills and expertise are required for the performance of the above listed tasks: /pulliGood knowledge of ISO 27000 family of standards, the EC Security Policies, the European Commission Risk‑management methodology and related risk‑assessment techniques /liliGood experience in the security domain, including the development and review of security methodologies, Business Impact Assessments, Risk Assessments and Secure System Architecture Design /liliAbility to review draft Security Plans and related security‑plan material efficiently and fast /liliAbility to give business and technical presentations to system owners, IT service providers /liliAbility to apply high quality standards in documentation, template creation and guidance material for security planning /liliAbility to cope with fast changing technologies used in cloud services, AI‑driven applications and other digital services within the JRC environment /liliVery good communication skills with technical and non-technical audiences to facilitate multilingual, multicultural meetings and stakeholder engagement /liliAnalysis and problem solving skills /liliCapability to write clear and structured technical documents /liliAbility to participate in technical meetings and good communication skills /liliRelevant certifications in Governance, Risk and Compliance or Risk Management and Audit or broad Cybersecurity are an advantageous asset (CGRC, CRISC, CISA, CISSP, CISM, etc..) /li /ulpbr/ppbr/ppbr/p

📌 Compliance Specialist (IT) (Pavia)
🏢 Changetheblock
📍 Pavia

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: compliance specialist (it) (pavia) / pavia

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: compliance specialist (it) (pavia) / pavia