IT Governance, Risk and Compliance Manager

3 settimane fa


Italy, IT SOMACIS A tempo pieno

The Mission Are you a GRC expert who sees compliance not as a checkbox, but as a competitive advantage? Are you driven to build, not just maintain? We are seeking an IT Governance, Risk and Compliance Manager to be the strategic owner of our global security trust and assurance program. This is not a typical GRC role. You will be the architect of the framework that secures our “license to operate” in the world’s most demanding markets, from Aerospace & Defense to Medical Technology. Reporting directly to the CISO, you will have the visibility and autonomy to build a world-class GRC function from a strong foundation, with direct visibility to our Board. Your mandate is to translate complex regulatory, client, and business requirements into a measurable and auditable control environment. While the title says IT, your scope is the entire digital landscape—from the corporate network to the factory floor’s Operational Technology (OT). What You’ll Do: Architect Our Compliance Advantage: You will own the strategy and lead the execution of our key compliance programs, including CMMC, NIS2, and ISO 27001 . You will be our single point of contact for clients and auditors, turning our security posture into a key sales enabler. Build an Investor-Grade Risk Program: Develop and manage the unified cyber risk register for both IT and OT environments. You will conduct rigorous risk assessments, define and track Key Risk Indicators (KRIs), and provide quantifiable risk insights directly to executive leadership and our board. Secure the Digital and Physical Worlds: You will extend our GRC framework into our manufacturing facilities, applying standards like ISA/IEC 62443 to manage the unique risks of Industrial Control Systems (ICS). Fortify Our Supply Chain: Design and implement our Third-Party Risk Management (TPRM) program. You will be responsible for assessing the security of our critical suppliers and mitigating one of our most significant attack vectors. Lead the Human Element of Security: Drive the strategy for our security awareness program, using data from phishing simulations and training campaigns to strengthen our human firewall and foster a culture of security. What You’ll Bring (Required Qualifications): A minimum of 5 years of experience in cybersecurity, with at least 3 years in a senior Governance, Risk, and Compliance (GRC) role. Demonstrable, hands-on experience building and managing an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 . Deep expertise in technology risk assessment methodologies and maintaining a corporate risk register. Proven experience developing, writing, and managing the lifecycle of corporate information security policies and standards. Excellent communication skills, with the ability to translate complex technical risks into clear business language for executive and board-level audiences. What Will Make You Stand Out (Preferred Qualifications): Direct experience implementing and managing compliance programs for CMMC or the NIS2 Directive . Experience with risk quantification frameworks for reporting to corporate management. Familiarity with modern GRC platforms (e.g., ServiceNow GRC, OneTrust, LogicGate). Relevant professional certifications (e.g., CISSP, CISM, CRISC). Experience with Operational Technology (OT) / Industrial Control Systems (ICS) security frameworks, particularly ISA/IEC 62443. Why This is a Unique Opportunity: Impact: This is a “builder” role. You will shape the future of our security program with a high degree of autonomy. Visibility: You will have a direct line to the highest levels of the organization, including our BoD. Your work will be critical to the company’s strategic goals. Challenge: The convergence of IT and OT security is one of the most complex and exciting challenges in cybersecurity. You will be at the forefront of securing a multinational manufacturing enterprise. If you are a strategic, results-driven GRC leader ready to make a tangible business impact, we encourage you to apply.



  • Rome, Latium, Italy, IT Syscons A tempo pieno

    Syscons è una boutique di System Integrator appartenente al Gruppo Impresoft. Syscons aiuta i clienti a creare soluzioni digitali su misura, guidandoli attraverso il concetto di Composable Enterprise e a un adattamento rapido alle dinamiche del mercato. Per la nostra sede di Roma , stiamo cercando una risorsa da inserire nella divisione Governance Risk &...


  • , Italy, IT SELTIN GROUP A tempo pieno

    SELTIN GROUP è una società di consulenza per il mondo Automotive / Aerospace / Logistica. Per importante commessa nel settore automotive siamo alla ricerca di un Project Manager – Cyber Security Governance. Ruolo: Coordina il progetto di implementazione del CSMS, garantendo la governance dei processi, il rispetto delle milestone e la comunicazione....

  • Senior Consultant

    2 settimane fa


    Rome, Latium, Italy, IT Protiviti Italia A tempo pieno

    Chi siamo Protiviti è un Gruppo multinazionale di consulenza direzionale, specializzato nel creare valore attraverso la capacità di analizzare e gestire il rischio e la nostra visione della Governance Aziendale. Siamo leader nell’analisi e progettazione di modelli di Governance, Organizzazione e Controllo; i nostri professionisti assistono i Clienti nel...


  • , Italy, IT Habasit A tempo pieno

    Habasit is seeking a Global Trade Compliance Manager to establish and support our organization in trade compliance topics. We are looking for a creative, highly proactive individual, with a hands-on attitutde and a problem solving mentality. General Tasks and Responsibilities Develop and maintain a comprehensive global trade compliance framework that aligns...

  • GRC Senior IT Consultant

    2 settimane fa


    Rome, Latium, Italy, IT Syscons A tempo pieno

    Syscons è una boutique di System Integrator appartenente al Gruppo Impresoft. Syscons aiuta i clienti a creare soluzioni digitali su misura, guidandoli attraverso il concetto di Composable Enterprise e a un adattamento rapido alle dinamiche del mercato. Per la nostra sede di Roma , stiamo cercando una risorsa da inserire nella divisione Governance Risk &...


  • Florence, Italy Metropolitan Area, IT Kon Group A tempo pieno

    Junior Consultant in ambito Compliance, Risk Management e Internal Audit Per il nostro team di Governance, Organizzazione, Risk & Compliance della sede di Firenze ricerchiamo una risorsa junior che si occuperà di quanto segue: sistemi di gestione della compliance aziendale ai sensi del D.Lgs. 231/2001; attività di Risk Management (ERM, mappatura dei...


  • Rome, Latium, Italy, IT Protiviti Italia A tempo pieno

    Chi siamo Protiviti è un Gruppo multinazionale di consulenza direzionale, specializzato nel creare valore attraverso la capacità di analizzare e gestire il rischio e la nostra visione della Governance Aziendale. Siamo leader nell’analisi e progettazione di modelli di Governance, Organizzazione e Controllo; i nostri professionisti assistono i Clienti nel...


  • Florence, Italy Metropolitan Area, IT Jimmy Choo A tempo pieno

    Role Purpose: The Manager, Sustainability & Compliance will lead and execute Jimmy Choo’s sustainability and compliance agenda, ensuring alignment with Capri Holdings objectives while delivering measurable results. This role combines strategic thinking with hands-on implementation across Social Compliance, Product Compliance, Environmental Sustainability,...

  • Chief Legal

    1 settimana fa


    , Italy, IT Primo Caredent Group S.p.A. A tempo pieno

    Primo Caredent Group è una realtà specializzata nella progettazione, nello sviluppo e nella gestione di centri odontoiatrici e ambulatori polispecialistici, attiva con i brand Centri Dentistici Primo, Caredent e Centri Medici Primo. Il Gruppo rappresenta oggi il secondo player odontoiatrico nazionale ed uno dei principali network sanitari italiani,...

  • Governance Officer

    3 settimane fa


    Rome, Latium, Italy, IT BNL BNP Paribas A tempo pieno

    Sei un/a professionista desideroso/a di intraprendere un percorso in un ambiente dinamico e stimolante? BNL BNP Paribas è alla ricerca di talenti come te per rafforzare il nostro team! Chi cerchiamo? Siamo alla ricerca di una/un Governance Officer che, all’interno della practice IT Area – XShoring Governance and Strategy, si occuperà delle attività di...