Risk Management & Compliance Associate (Agrate Brianza)

Risk Management & Compliance Associate (Agrate Brianza)

06 set
|
Appsierra Group
|
Agrate Brianza

06 set

Appsierra Group

Agrate Brianza

Define and document cybersecurity compliance requirements for information-system controls in collaboration with system owners and system managers.
Develop and maintain templates covering security processes, controls and technical security solutions across digital services.
Support system owners and IT service providers with:

Business Impact Assessments (BIA).
Definition of security scope.
Security plans.
Secure system architecture designs.
Implementation plans.
Assist with cybersecurity remediation activities, including:

Contribute to the development and maintenance of security baselines for information systems and digital services.
Coordinate and review risk assessments, ensuring that identified risks are evaluated against established compliance criteria and that mitigation measures are properly documented.
Prepare compliance-status reports highlighting security gaps, risks and remediation progress.
Collaborate with system owners, IT service providers and other stakeholders to ensure consistent interpretation and implementation of cybersecurity policies.
Participate in technical and stakeholder meetings and communicate security requirements to both technical and non-technical audiences.
Produce clear, structured and high-quality security documentation, templates and guidance material.
Keep up to date with evolving technologies, particularly cloud services, AI-driven applications and other digital services, and their associated cybersecurity implications.
Minimum EQF Level 5 education,



typically corresponding to at least two years of post-secondary education or higher.
Educational background in Cybersecurity, Information Security, Computer Science, IT, Risk Management, Governance, Audit or a related discipline.
Practical experience or demonstrable knowledge of information security and cybersecurity compliance.
Good knowledge of the ISO/IEC 27000 family of standards.
Knowledge of information-security governance, risk-management principles and security controls.
Understanding of Business Impact Assessments, Risk Assessments and Secure System Architecture.
Ability to review and assess security plans and related documentation.
Ability to produce clear, structured and professional technical documentation.
Good communication skills and the ability to explain cybersecurity concepts to technical and non-technical stakeholders.
Ability to work effectively in an international and multicultural environment.
Good level of written and spoken English.
Professional certifications in cybersecurity, governance, risk, compliance, risk management or auditing are considered an advantage, such as:
CRISC
CISA
CISSP
CISM




Other relevant cybersecurity or GRC certifications
Information security governance and compliance.
ISO 27001 / ISO 27000 standards.
Cybersecurity policies and security controls.
Business Impact Assessment methodologies.
Security planning and documentation.
Secure system architecture principles.
Security baselines and control frameworks.
Compliance monitoring and remediation tracking.
Cybersecurity requirements for cloud and modern digital services.
Emerging security considerations related to AI-driven applications.
Ability to present technical information clearly to different audiences.
Ability to work across multiple projects and stakeholders.
Comfortable working in multilingual and multicultural environments.
Ability to build trusted relationships with system owners, IT providers and institutional stakeholders.
High level of discretion, professionalism and integrity.
The ideal candidate is an early-career cybersecurity or information-security professional interested in developing a career in Governance, Risk & Compliance (GRC).
You should have a solid foundation in information security standards and risk management, be comfortable working with security documentation and assessments, and have the communication skills required to interact with both technical and business stakeholders.
Experience with ISO 27001, risk assessments, security plans, security controls, compliance monitoring or cybersecurity audits would be particularly relevant.
#

📌 Risk Management & Compliance Associate (Agrate Brianza)
🏢 Appsierra Group
📍 Agrate Brianza

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: risk management & compliance associate (agrate brianza) / agrate brianza

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: risk management & compliance associate (agrate brianza) / agrate brianza