IT Risk
6 giorni fa
COMPANY PROFILE:
WHO WE ARE LOOKING FOR:
The position will be primarily responsible for implementing, coaching, and improving an integrated risk, compliance and security management system. The management system enables the IT teams globally to identify, document, measure and address its compliance requirements, including but not limited to data protection, privacy, 3rd party/vendor, information security and procurement. The Risk and Compliance Specialist's responsibilities include supporting teams to drive all their risk, compliance and security requirements ensuring they deliver and sustain compliant and secure products & platforms meeting the business risk appetite.
YOUR KEY RESPONSIBILITIES:
- Ensure ongoing compliance with the Group policies and procedures for information security and support key business initiatives by identifying security and compliance related risks.- Design and/or conduct security risk assessments.
- Maintain the risk management system through continuous review and evaluation of external frameworks and standards (e.g., ISO27001, COBIT, NIST, ITIL etc.), including Implementing tools and process to support an integrated Risk, Compliance & Security Framework.
- Provide guidance and support to business and IT teams in implementing by design the required IT compliance in their solutions to meet the desired level of compliance maturity.
- Assist and collaborate with internal and external Auditors, tracking and following up all IT audits, internal review or regulatory findings as corrective & preventative actions.
- Coach and support teams in managing Risk, Compliance & Security gaps through documented corrective & preventative actions, tracked through the management system.
- Support Security Risk and Compliance team in developing and maintaining the IT Security documentation: (policies, guidelines, standard, templates, training materials, etc.)
- Prepare compliance reports and status reports, identify issues, and report to senior management.
- Communicate to senior management, through reports, presentations, metrics and other documentation, any cyber-security risks identified.
YOUR KEY COMPETENCES AND QUALIFICATIONS:
- 5+ years of experience in a combination of risk management, compliance, information security and IS/IT jobs
- Strong experience with Governance, Risk, and Compliance tools and technology
- Strong technical experience in security or technology risk assessment, with proficiency in a risk management framework and the ability to assess administrative and technical controls
- Proven ability to develop risk management strategies that align with business goals and protect the confidentiality, integrity and availability of information systems and data
- A demonstrated practical, real world, collaborative approach to problem solving with the ability to make sound decisions and accept result accountability.
- Ability to understand and interpret regulatory requirements and the business implications, assessing risks and provide concise business-focused advice.
- Excellent verbal and written communication skills, with the ability to convey technology and security concepts to management
- Strong problem-solving and follow-up skills, along with excellent attention to detail
- The ability to work independently and multitask effectively to successfully manage projects in a diverse, project-oriented environment
- Master's Degree in Computer Science, Engineering, Information Systems Management, Information Security, or other related fields
- Experience with various security & compliance frameworks and requirements including NIST, ISO 27001, COBIT, SOC 2, etc.
- CISSP, CISA, CISM and/or other comparable certifications.
-
IT Security Risk Assessment
1 settimana fa
Torino, Italia Idata Group A tempo pieno**CHI SIAMO ?** **IDATA GROUP** è un _System Integrator_, nato nel 1979 e da oltre 40 anni lavora a supporto delle aziende in Italia e all’ Estero. Grazie alle competenze acquisite negli anni, offriamo servizi di: - Sviluppo software, web, mobile, embedded, IOT; - Assistenza sistemistica e Networking ; - Cloud Computing; - IT security e governance; -...
-
Torino, Italia UNIPOL GRUPPO A tempo pieno" **UNIPOLSAI ASSICURAZIONI SpA **, compagnia di assicurazione multi-ramo del Gruppo Unipol, leader in Italia nei rami Danni, a potenziamento della struttura **“RISK SELF ASSESSMENT **”, nell’ambito della Direzione Risk Management di Gruppo, è alla ricerca di un **RISK MANAGEMENT SPECIALIST **da inserire presso la sede di Torino. La risorsa si...
-
IT Audit Manager
1 settimana fa
torino, Italia Altro A tempo pienoPer nostro cliente, azienda di consulenza leader mondiale (Big Four), siamo alla ricerca di un Cyber & Tech Risk Manager .Sarai coinvolto su progetti sia nazionali che internazionali, collaborando con professionisti altamente qualificati, e lavorerai a stretto contatto con i nostri clienti, contribuendo alla gestione di rischi IT, governance, audit, privacy...
-
Risk Data Quality
14 ore fa
Torino, Italia UNIPOL GRUPPO A tempo pieno" **UnipolSai Assicurazioni S.p.A **, Compagnia di Assicurazione multi-ramo del Gruppo Unipol, per un potenziamento della funzione Risk Management di Gruppo è alla ricerca di un/a **Risk Data Quality & Operations Analyst** **Sede di Lavoro: Torino** Il profilo ricercato, inserito all’interno della funzione **Risk Data Quality and Operations **, avrà...
-
CyberSecurity Risk Engineer
1 settimana fa
torino, Italia Altro A tempo pienoOverview MSC Mediterranean Shipping Company is a global business engaged in the shipping sector. Present in 155 countries, MSC facilitates international trade between the world’s major economies, and among emerging markets across all continents. Headquartered in Geneva, Switzerland, since 1978, MSC is a privately-owned organisation driven by the Aponte...
-
Cybersecurity Risk Engineer
1 settimana fa
Torino, Italia Msc Technology Italia Srl A tempo pienoOverviewMSC Mediterranean Shipping Company is a global business engaged in the shipping sector.Present in 155 countries, MSC facilitates international trade between the world's major economies, and among emerging markets across all continents.Headquartered in Geneva, Switzerland, since ****, MSC is a privately-owned organisation driven by the Aponte...
-
CyberSecurity Risk Engineer
1 settimana fa
torino, Italia Altro A tempo pienoOverview MSC Mediterranean Shipping Company is a global business engaged in the shipping sector. Present in 155 countries, MSC facilitates international trade between the world’s major economies, and among emerging markets across all continents. Headquartered in Geneva, Switzerland, since 1978, MSC is a privately-owned organisation driven by the Aponte...
-
CyberSecurity Risk Engineer
2 settimane fa
Torino, Italia MSC TECHNOLOGY ITALIA SRL A tempo pienoOverview MSC Mediterranean Shipping Company is a global business engaged in the shipping sector. Present in 155 countries, MSC facilitates international trade between the world’s major economies, and among emerging markets across all continents. Headquartered in Geneva, Switzerland, since 1978, MSC is a privately-owned organisation driven by the Aponte...
-
CyberSecurity Risk Engineer
3 settimane fa
Torino, Italia MSC TECHNOLOGY ITALIA SRL A tempo pienoOverview MSC Mediterranean Shipping Company is a global business engaged in the shipping sector. Present in 155 countries, MSC facilitates international trade between the world’s major economies, and among emerging markets across all continents. Headquartered in Geneva, Switzerland, since 1978, MSC is a privately-owned organisation driven by the Aponte...
-
Risk Management Specialist data Quality
14 ore fa
Torino, Italia UNIPOL GRUPPO A tempo pieno" **UNIPOLSAI ASSICURAZIONI SpA **, Compagnia di Assicurazione multi-ramo del Gruppo Unipol, leader in Italia nei rami danni, a potenziamento della struttura “ **RISCHI OPERATIVI E DATA QUALITY RISK” **nell’ambito della Direzione Risk Management di Gruppo, è alla ricerca di un **RISK MANAGER SPECIALISTA NEL DATA QUALITY **da inserire presso la sede di...