It Governance, Risk And Compliance Manager

4 giorni fa


Padova, Italia Somacis A tempo pieno

The MissionAre you a GRC expert who sees compliance not as a checkbox, but as a competitive advantage?Are you driven to build, not just maintain?We are seeking an IT Governance, Risk and Compliance Manager to be the strategic owner of our global security trust and assurance program. This is not a typical GRC role. You will be the architect of the framework that secures our "license to operate" in the world's most demanding markets, from Aerospace & Defense to Medical Technology. Reporting directly to the CISO, you will have the visibility and autonomy to build a world-class GRC function from a strong foundation, with direct visibility to our Board.Your mandate is to translate complex regulatory, client, and business requirements into a measurable and auditable control environment. While the title says IT, your scope is the entire digital landscape—from the corporate network to the factory floor's Operational Technology (OT).What You'll Do:Architect Our Compliance Advantage: You will own the strategy and lead the execution of our key compliance programs, including CMMC, NIS2, and ISO *****. You will be our single point of contact for clients and auditors, turning our security posture into a key sales enabler.Build an Investor-Grade Risk Program: Develop and manage the unified cyber risk register for both IT and OT environments. You will conduct rigorous risk assessments, define and track Key Risk Indicators (KRIs), and provide quantifiable risk insights directly to executive leadership and our board.Secure the Digital and Physical Worlds: You will extend our GRC framework into our manufacturing facilities, applying standards like ISA/IEC ***** to manage the unique risks of Industrial Control Systems (ICS).Fortify Our Supply Chain: Design and implement our Third-Party Risk Management (TPRM) program. You will be responsible for assessing the security of our critical suppliers and mitigating one of our most significant attack vectors.Lead the Human Element of Security: Drive the strategy for our security awareness program, using data from phishing simulations and training campaigns to strengthen our human firewall and foster a culture of security.What You'll Bring (Required Qualifications):A minimum of 5 years of experience in cybersecurity, with at least 3 years in a senior Governance, Risk, and Compliance (GRC) role.Demonstrable, hands-on experience building and managing an Information Security Management System (ISMS) based on ISO/IEC *****:****.Deep expertise in technology risk assessment methodologies and maintaining a corporate risk register.Proven experience developing, writing, and managing the lifecycle of corporate information security policies and standards.Excellent communication skills, with the ability to translate complex technical risks into clear business language for executive and board-level audiences.What Will Make You Stand Out (Preferred Qualifications):Direct experience implementing and managing compliance programs for CMMC or the NIS2 Directive.Experience with risk quantification frameworks for reporting to corporate management.Familiarity with modern GRC platforms (e.g., ServiceNow GRC, OneTrust, LogicGate).Relevant professional certifications (e.g., CISSP, CISM, CRISC).Experience with Operational Technology (OT) / Industrial Control Systems (ICS) security frameworks, particularly ISA/IEC *****.Why This is a Unique Opportunity:Impact: This is a "builder" role. You will shape the future of our security program with a high degree of autonomy.Visibility: You will have a direct line to the highest levels of the organization, including our BoD. Your work will be critical to the company's strategic goals.Challenge: The convergence of IT and OT security is one of the most complex and exciting challenges in cybersecurity. You will be at the forefront of securing a multinational manufacturing enterprise.If you are a strategic, results-driven GRC leader ready to make a tangible business impact, we encourage you to apply.



  • Padova, Italia Altro A tempo pieno

    Per nostro cliente, azienda di consulenza leader mondiale (Big Four), siamo alla ricerca di un Cyber & Tech Risk Manager .Sarai coinvolto su progetti sia nazionali che internazionali, collaborando con professionisti altamente qualificati, e lavorerai a stretto contatto con i nostri clienti, contribuendo alla gestione di rischi IT, governance, audit, privacy...


  • Padova, Italia Altro A tempo pieno

    Manager Cyber Strategy e Tecnologia Risk - Assurance – Padova/TrevisoJoin to apply for the Manager Cyber Strategy e Tecnologia Risk - Assurance – Padova/Treviso role at EY .In questo ruolo, entrerai a far parte di un team multidisciplinare dedicato alla valutazione, gestione e mitigazione dei rischi IT in ambito audit, assurance e...


  • Padova, Italia Altro A tempo pieno

    Per nostro cliente, azienda leader mondiale di consulenza (Big Four), siamo alla ricerca di un Senior Cybersecurity Consultant specializzato in Risk, Governance & Compliance.In particolare, entrando a far parte del Team di Cyber&Tech Risk a Padova lavorerai con esperti di ICT security per aiutare i clienti ad affrontare i rischi informatici che minacciano il...


  • Padova, Italia Altro A tempo pieno

    At EY, we’re all in to shape your future with confidence.Ti aiuteremo a crescere in un mondo globale e connesso, portando la tua carriera dove desideri.Come possiamo collaborare al meglio per costruire insieme un mondo del lavoro migliore?Cosa dicono di noi : Questi sono i fattori più influenti che hanno spinto colleghe e colleghi a sceglierci negli...


  • Padova, Italia Yoursafe A tempo pieno

    Risk & Compliance Officer Locale (Italia) – Part-TimeYoursafe Fano, Marche, Italy (Hybrid)Risk & Compliance Officer Locale (Italia) – Part-Time (Freelance o Contratto di Lavoro)Sede: Remoto (ovunque in Italia), con viaggi periodici a Fano e ad AmsterdamImpegno: 5–10 ore a settimanaLingue: Italiano (madrelingua o fluente) & Inglese (fluente)Data di...


  • Padova, Italia Sintex Selezione Personale Srl A tempo pieno

    Per Azienda cliente, realtà strutturata e in forte crescita nel settore della cyber security, ricerchiamo e selezioniamo un / a Junior Cybersecurity Governance, Regulation & Compliance (categoria protetta Lg. *******) La posizione è rivolta a giovani neolaureati o candidati con un primo anno di esperienza interessati a intraprendere un percorso...


  • Padova, Italia Dedagroup A tempo pieno

    Identity Governance and Access Management ProfessionalJoin to apply for theIdentity Governance and Access Management Professionalrole atDedagroupLocation: Noventa Padovana, Veneto, ItalyCosa aspettartiDeda Tech è parte del Gruppo Deda, specializzata in Managed Cloud & Security Services, e porta evoluzione e semplificazione nelle aree infrastruttura,...

  • Junior Ict Risk

    2 settimane fa


    Padova, Italia Altro A tempo pieno

    Allitude S.P.A., società del Gruppo Bancario Cooperativo Cassa Centrale Banca specializzata in servizi di sviluppo software, outsourcing informatico e back-office per ilSettore bancario, sta selezionando una figura diJunior ICT Risk Specialistda inserire nell'ufficio di "Gestione Rischi e Controlli".Sei il/la candidato/a ideale sesei unneo laureato/ain...


  • Padova, Italia Sintex Selezione Personale Srl A tempo pieno

    Un'azienda nel settore cyber security sta cercando un Junior Cybersecurity Governance, Regulation & Compliance a Padova.La posizione è aperta a neolaureati o candidati con un anno di esperienza.Sarai coinvolto nella stesura di policy di sicurezza, valutazione dei rischi e supporto agli audit.Offriamo un ambiente di lavoro innovativo con formazione continua...


  • Padova, Italia Altro A tempo pieno

    Audit & Compliance Specialist - Ambito QHSE Join to apply for theAudit & Compliance Specialist - Ambito QHSErole atDedagroup3 days ago Be among the first 25 applicantsJoin to apply for theAudit & Compliance Specialist - Ambito QHSErole atDedagroupCosa aspettartiSiamo uno dei principali gruppi tecnologici in Italia e operiamo come Business & Technology...