Cybersecurity Governance, Risk & Compliance (Grc) Consultant (Bardi)

Cybersecurity Governance, Risk & Compliance (Grc) Consultant (Bardi)

25 set
|
Lifted, an Upwork
|
Bardi

25 set

Lifted, an Upwork

Bardi

This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response .

Scorra verso il basso per trovare i dettagli completi dell'offerta, inclusa l'esperienza richiesta e le mansioni associate.
What You’ll Do:

-

- Conduct cybersecurity risk assessments for COET srl.

- Analyze threats, vulnerabilities, control effectiveness, and residual risks.

- Maintain and update cybersecurity risk registers.

- Track risk mitigation and remediation activities through completion.

- Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.

- Develop and monitor cybersecurity policies, standards, and control requirements.

- Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.

- Support cybersecurity governance forums and reporting activities.

- Assist with internal and external cybersecurity audits.

- Coordinate evidence collection and remediation tracking.

- Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.

- Support control assessments and gap analyses.

- Prepare materials for management and governance reviews.

- Escalate significant cybersecurity risks and emerging trends.

- Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.

- Provide guidance on cybersecurity risk management processes and requirements.

- Promote cybersecurity awareness and risk-informed decision-making.

Nice to Haves:





-

- Experience in Information Security governance, risk management, compliance, and incident response.

- Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.

- CISSP, CISM, or an equivalent certification is desirable.

- Fluency in both Italian and English.

- Strong communication and stakeholder management skills.

- Ability to work independently and collaborate with cybersecurity and business teams.

- Cybersecurity risk assessments and updated risk registers.

- Risk mitigation and remediation tracking.

- Cybersecurity policies, standards, and control requirements.

- Audit evidence, control assessments, and gap analysis support.

- Governance review materials and cybersecurity reporting.

Location Requirement

-

- On-site presence at COET premises in San Donato Milanese, Italy , at least 3 times per month .

Additional Information

-

- Category: Information Security & Compliance

- Duration: September 14, 2026 to September 14, 2027

- The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.

- Candidates should be comfortable proceeding under either engagement structure. xjncmbx If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.

Cybersecurity Governance, Risk & Compliance (GRC) Consultant • San Donato Milanese, Lombardy, Italy

#J-18808-Ljbffr

📌 Cybersecurity Governance, Risk & Compliance (Grc) Consultant (Bardi)
🏢 Lifted, an Upwork
📍 Bardi

Candidati a questo annuncio

Mostra le tue capacità professionali all'azienda, compila il form e lascia un tocco personale nella lettera di presentazione, aiuterà il recruiter nella scelta del candidato.

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: cybersecurity governance, risk & compliance (grc) consultant (bardi) / bardi

Iscriviti a questa job alert:

Ricevi via email le nuove offerte di lavoro per: cybersecurity governance, risk & compliance (grc) consultant (bardi) / bardi