RAD Cyber Security
2 weeks ago
Cybersecurity Governance & Compliance Specialist
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- RAD Cyber Security
- Location
- Italia, Lombardia, Provincia di Milano, Milano Italy
- Posted
- 2 weeks ago
Job description
Rad is looking for a Cybersecurity Governance & Compliance Specialist to join our team dedicated to Security Governance and strategic consulting. We are looking for a motivated and passionate individual who will play a central role in overseeing corporate Governance & Compliance and supporting end clients in compliance and regulatory adaptation journeys in the cybersecurity field.
The main activities you will perform
- You will manage and maintain the corporate Information Security Management System (ISMS) in compliance with ISO/IEC 27001, coordinating its evolution and continuous improvement.
- You will coordinate the activities necessary for the maintenance and evolution of internal compliance with applicable regulations (e.g., NIS2, CRA, AI Act,...).
- You will support risk assessment and cyber risk management activities, defining and monitoring treatment and remediation plans.
- You will manage and maintain security governance system policies, procedures, and documentation.
- You will plan and coordinate internal audits, compliance checks, and assessments aimed at evaluating the effectiveness and conformity of the security system.
- You will monitor the evolution of reference regulations, standards, and frameworks, evaluating their applicability and impact on the organization and supporting the company in the related adaptation process.
- You will define and monitor KPIs, KRIs, and compliance and security indicators, preparing periodic reports for management.
- You will manage security assessments, gap analyses, and compliance activities with clients, analyzing regulatory requirements and reference frameworks.
- You will support clients in defining adaptation roadmaps and improving their security posture.
- You will contribute to presales activities and offering development in the Governance, Risk & Compliance field.
- You will contribute to the development and growth of the team.
Required skills
- Consolidated experience (5-8+ years) in Cybersecurity Governance & Compliance.
- Excellent knowledge of industry certifications such as ISO/IEC 27001 and ISO/IEC 27002 and major cybersecurity frameworks, such as NIST.
- Solid knowledge of major cybersecurity regulations, particularly NIS2, CRA, and GDPR.
- Experience in managing ISMS, risk assessment activities, audits, security assessments, and gap analyses.
- Ability to interpret regulatory requirements and translate them into controls, processes, and concrete actions.
- Excellent autonomous activity management, organization, and coordination skills.
- Excellent interpersonal and communication skills, with the ability to interact with management, business functions, and technical teams.
- Good knowledge of the English language.
- Strong interest in the evolution of the cybersecurity regulatory and technological landscape.
A plus would be: ISO/IEC 27001 Lead Auditor/Lead Implementer, CISM, CISSP certifications, or equivalent; experience in CISO/CISO as-a-Service and knowledge of further standards such as, for example, ISO/IEC 22301, 27701, and 42001.
What we offer
- Direct employment contract under CCNL Commercio
- Gross Annual Salary (RAL) €45,000 - €52,000
- Meal vouchers worth €10
- Annual review to assess growth and define your career goals
- Possibility of working remotely (Smart-Working)
Job offers are aimed at both sexes. (L. 903/77).
It is strongly recommended to attach a CV with authorization for personal data processing (D.Lgs. 196/03 and EU Regulation 2016/679).
Required skills
- audit
- kpi
- compliance
- governance
- reporting
- presales
- risk management
- gdpr
- english language
- risk assessment
- cybersecurity
- cissp
- nis2
- cism
- nist
- iso/iec 27001
- ciso
- cra
- policy management
- lead auditor
- gap analysis
- compliance audit
- cyber risk
- isms
- procedure management
- ai act
- iso/iec 42001
- lead implementer
- iso/iec 27701
- kri
- security assessment
- iso/iec 27002
- ciso as-a-service
- iso/iec 22301
Interested in this position?
Create your free account and tailor your CV to match this job.