ICT Governance Manager

4 giorni fa


Milano, Lombardia, Italia Scalapay A tempo pieno 80.000 € - 100.000 €

At Scalapay, we're shaping a culture with high standards, independent and critical thought, innovation, ownership, and continuous learning. We operate in a fast-moving, tech-driven environment, and we're looking for people who thrive in change, think boldly, and take initiative.

If you're ready to put your potential to the test in a hiring process designed to spotlight exceptional talent, this is your chance to stand out and grow with one of Europe's most ambitious fintech teams.

#MakeItHappen #PlayAsATeam #StayCurious #FocusOnCustomer.

The Mission

We're seeking an ICT Governance Manager to ensure our regulated financial services subsidiary maintains robust compliance with Italian and EU financial regulations. This is a hands-on, individual contributor role working horizontally across our engineering organization to implement governance frameworks, coordinate regulatory requirements, and maintain continuous audit readiness.

You'll be the subject matter expert who translates regulatory requirements (Bank of Italy, DORA, PCI-DSS, GDPR) into actionable technical requirements, working closely with engineering domain leads to ensure compliance is embedded into our delivery processes without creating bottlenecks.

This role is critical for maintaining our payment institution license while supporting our growth from 10M users to the next phase of scale.

What You'll Do
Regulatory Compliance Implementation
  • Translate regulatory requirements from Bank of Italy, ECB directives, DORA, PCI-DSS, and GDPR into concrete technical requirements
  • Work with engineering domain leads (Risk, Payments, Customer, Infrastructure) to implement compliance controls within their delivery cycles
  • Maintain comprehensive documentation of ICT systems, data flows, and security controls for regulatory inspections
  • Coordinate regulatory submissions and respond to information requests from Bank of Italy and external auditors
  • Track and report compliance status across all technical domains to CTO and IP CEO
Governance Framework Management
  • Implement and maintain ICT governance processes aligned with regulatory requirements
  • Establish monitoring mechanisms to ensure ongoing compliance across engineering teams
  • Create and maintain policy documentation, procedures, and evidence repositories
  • Coordinate vendor compliance assessments for critical third-party ICT services
  • Maintain ICT asset inventory, access control documentation, and security configurations
  • Support internal and external audit processes by preparing evidence and coordinating team responses
Business Continuity & Resilience Coordination
  • Coordinate development and testing of Business Continuity Plans with infrastructure and engineering teams
  • Ensure disaster recovery procedures are documented, tested, and meet regulatory requirements
  • Work with DevOps team to validate backup procedures and recovery time objectives
  • Organize and document regular DR testing exercises with post-test reporting
  • Maintain incident response procedures and coordinate incident management processes
Cross-Functional Collaboration
  • Partner with Risk Management team to assess and monitor ICT risks
  • Work with Legal/Compliance to align technical controls with regulatory interpretations
  • Coordinate with engineering managers to plan compliance work within agile sprint cycles
  • Act as technical liaison during regulatory inspections and auditor requests
  • Present compliance status updates to executive leadership

Why you should join Scalapay:

  • Attractive packages based on skills and experience - the salary band we have for this position is Euro
  • Opportunity to work with a team of Industry Leaders who are focused on delivering products that offer exceptional user experience.
  • Support to accelerate your professional growth and take ownership of the projects you deliver.
  • A lean, people focused Agile way of working that delivers marketable products.
  • Work with the latest technologies and be encouraged to bring your own flair to the role.
  • Professional training plan and career guidance.
Required Qualifications
Regulatory & Compliance Experience
  • 4-6 years of hands-on experience in IT governance, compliance, or risk management within regulated financial services (banking, payments, fintech)
  • Direct experience working with Bank of Italy requirements or similar EU financial regulators
  • Working knowledge of PCI-DSS and GDPR compliance requirements
  • Experience with DORA (Digital Operational Resilience Act) requirements
  • Experience preparing documentation for and responding to regulatory audits
Technical Background
  • Strong understanding of enterprise IT infrastructure, cloud services (AWS), and application architectures
  • Ability to read and understand technical documentation, API specifications, and system architecture diagrams
  • Experience with DevOps practices, CI/CD pipelines, and infrastructure-as-code concepts
  • Understanding of cybersecurity controls, access management, and vulnerability management
  • Familiarity with agile development methodologies and how to embed compliance work into sprints
Collaboration & Communication
  • Proven ability to work horizontally across technical teams without direct authority
  • Experience influencing engineering teams to prioritize compliance work alongside feature development
  • Ability to translate complex regulatory language into clear technical requirements
  • Strong documentation skills for creating policies, procedures, and audit evidence
  • Excellent Italian and English communication skills (written and verbal)
  • Comfortable working in a lean, fast-moving startup environment (~200 people)
Preferred Qualifications
  • Degree in Computer Science, Information Systems, or related technical field
  • Professional certifications: CISA, CRISC, ISO 27001 Lead Auditor, or similar
  • Previous experience in Big 4 consulting (audit/advisory) or regulatory compliance roles
  • Hands-on experience with BNPL, payments processing, or lending platforms
  • Experience with GRC (Governance, Risk, Compliance) tools
  • Background as a technical project manager or senior engineer who moved into governance
Recruitment process:
  1. Initial Chat: A brief conversation with our Talent Acquisition team to get to know you and understand your fit for the role.
  2. Hiring Manager Interview: First interview with the Hiring Manager  to deep dive into your experiences, better understand your motivation and explore your skills.
  3. Case Study: A skills-based exercise followed by a debriefing session with key stakeholders.
  4. A Meet the Team: to meet the Software Engineers that could potentially be part of your team.
  5. Final Chat with Simone (CEO): A chance to discuss Scalapay's values, company vision, and ensure strong cultural alignment. During this stage, we will also conduct reference checks to validate your experience and achievements.

Want to learn more? Don't hesitate to explore our Careers website, our LinkedIn and Glassdoor pages. 

Pro tip: send your CV in English

Super Pro tip: we know that application processes can be scary and frustrating but… we look for talent, not people that tick all our boxes.

We believe in the power of diversity: Scalapay is an Equal Opportunity Employer for any minority, disability, gender identity or sexual orientation.


  • ICT Governance Manager

    2 settimane fa


    Milano, Lombardia, Italia Banca AideXa A tempo pieno

    Il nostro scopo?Essere la fintech bank di riferimento per le micro e piccole imprese italiane, offrendo esperienze finanziarie digitali e innovativeCosa abbiamo fatto fino ad ora?Siamo una fintech bank che cresce velocissima In soli cinque anni abbiamo ottenuto la licenza bancaria, siamo stati tre volte tra LinkedIn Top Startups (al 1°, 2° e 3° posto),...


  • Milano, Lombardia, Italia Bolton A tempo pieno 60.000 € - 120.000 € all'ano

    HoldingInformation & Communication TechnologyPermanentMilano, ITICT Application Services ManagerWe are looking for an ICT Application Services Manager to join our Group ICT Team based in Milan.How you make the differenceAs an ICT Application Services Manager, you ensure high-quality Application Management Services (AMS) by overseeing vendor performance,...


  • Milano, Lombardia, Italia Energy Job Search A tempo pieno

    Isa Digital Consultingè una società indipendente che da oltre 30 anni opera nella consulenza, specializzata in ICT Strategy & Architecture, Digital Solution e Human Resources.Supportiamo le aziende nella trasformazione digitale e nel miglioramento della performance della Direzione ICT in Italia, Europa, Medio Oriente e Africa.Siamo alla ricerca diSenior...


  • Milano, Lombardia, Italia Sky Italia A tempo pieno

    In qualità di Manager - Data Governance, sarai al centro della strategia Data Driven di Sky, influenzando e guidando l'evoluzione del framework di Corporate Data Governance in linea con le priorità strategiche e con l'obiettivo di massimizzare il valore e la sicurezza del dato.Responsabilità principali:Definire e guidare la strategia di governance del...


  • Milano, Lombardia, Italia idealista A tempo pieno

    Ti appassionano le tematiche relative alla sicurezza informatica? Hai esperienza nella governance della sicurezza delle informazioni? Allora unisci a noi Stiamo cercando una nuova figura di Security Governance Expert che, riportando direttamente al CISO, si occuperà di:Garantire la governance della sicurezza delle informazioni:Sviluppare e mantenere...

  • Project Manager ICT

    2 giorni fa


    Milano, Lombardia, Italia agap2 Italia A tempo pieno

    AGAP2è un gruppo europeo di consulenza ingegneristica e operativa facente parte del Gruppo MoOngy. Presente in 14 paesi europei con oltre dipendenti, abbiamo aperto, da sette anni, la prima sede italiana a Milano e, vista la continua crescita, stiamo rafforzando e ampliando il nostro team con persone che condividano gli stessi valori della nostra...

  • ICT & Security Compliance

    2 settimane fa


    Milano, Lombardia, Italia Fineco Bank A tempo pieno

    aziendaFinecoBank è una banca multicanale che offre, in un unico conto, servizi di banking, credit, trading e investimento. E' leader in Europa nel brokerage e dispone di una delle maggiori reti di consulenti finanziari, con un network capillare di Fineco Center in tutta Italia. FinecoBank è una delle più importanti banche FinTech in Europa, oltre ad...


  • Milano, Lombardia, Italia Gruppo San Donato A tempo pieno

    Gruppo San Donatoè alla ricerca di una risorsa da inserire comeProgram & Project Manager Corporate Governance,desiderosa di entrare a far parte di un contesto sfidante e in crescita.La figura diProgram & Project Manager Corporate Governanceverrà inserita nel team di Segreteria di Presidenza con l'obiettivo di garantire il coordinamento, il monitoraggio e...


  • Milano, Lombardia, Italia Fineco Bank A tempo pieno

    Company DescriptionFineco Bank is a leading European bank with a 20 years history and a fully digital DNA with a branchless approach since the start. Fineco is one of the banks with the widest products range available. We have developed a truly one-stop-solution which includes trading, investment and payment services. We have developed a 100% proprietary...

  • ICT & Security Compliance

    1 settimana fa


    Milano, Lombardia, Italia Fineco Bank A tempo pieno

    Company DescriptionFineco Bank is a leading European bank with a 20 years history and a fully digital DNA with a branchless approach since the start. Fineco is one of the banks with the widest products range available. We have developed a truly one-stop-solution which includes trading, investment and payment services. We have developed a 100% proprietary...