Cybersecurity Compliance Specialist

3 ore fa

monzabrianza, lombardia, Italia MEERAB GROUP Tempo pieno
Key Responsibilities
  • Define and document cybersecurity compliance requirements for information-system controls in collaboration with system owners and system managers.
  • Develop and maintain templates covering security processes, controls and technical security solutions across digital services.
  • Support system owners and IT service providers with:
    • Business Impact Assessments (BIA).
    • Definition of security scope.
    • Risk assessments.
    • Security plans.
    • Secure system architecture designs.
    • Implementation plans.
    • Assist with cybersecurity remediation activities, including:
      • Tracking identified non-conformities.
      • Assigning corrective actions.
      • Monitoring remediation progress.
      • Verifying closure of corrective actions within agreed deadlines.
  • Contribute to the development and maintenance of security baselines for information systems and digital services.
  • Coordinate and review risk assessments, ensuring that identified risks are evaluated against established compliance criteria and that mitigation measures are properly documented.
  • Prepare compliance-status reports highlighting security gaps, risks and remediation progress.
  • Collaborate with system owners, IT service providers and other stakeholders to ensure consistent interpretation and implementation of cybersecurity policies.
  • Participate in technical and stakeholder meetings and communicate security requirements to both technical and non-technical audiences.
  • Produce clear, structured and high-quality security documentation, templates and guidance material.
  • Keep up to date with evolving technologies, particularly cloud services, AI-driven applications and other digital services, and their associated cybersecurity implications.
Required Qualifications
  • Minimum EQF Level 5 education, typically corresponding to at least two years of post-secondary education or higher.
  • Educational background in Cybersecurity, Information Security, Computer Science, IT, Risk Management, Governance, Audit or a related discipline.
  • Practical experience or demonstrable knowledge of information security and cybersecurity compliance.
  • Good knowledge of the ISO/IEC 27000 family of standards.
  • Knowledge of information-security governance, risk-management principles and security controls.
  • Understanding of Business Impact Assessments, Risk Assessments and Secure System Architecture.
  • Ability to review and assess security plans and related documentation.
  • Strong analytical and problem-solving capabilities.
  • Ability to produce clear, structured and professional technical documentation.
  • Good communication skills and the ability to explain cybersecurity concepts to technical and non-technical stakeholders.
  • Ability to work effectively in an international and multicultural environment.
  • Good level of written and spoken English.
Valuable

Professional certifications in cybersecurity, governance, risk, compliance, risk

Management Or Auditing Are Considered An Advantage, Such As
  • CGRC
  • CRISC
  • CISA
  • CISSP
  • CISM
  • Other relevant cybersecurity or GRC certifications
Technical Skills
  • Information security governance and compliance.
  • ISO 27001 / ISO 27000 standards.
  • Cybersecurity policies and security controls.
  • Risk assessment and risk treatment.
  • Business Impact Assessment methodologies.
  • Security planning and documentation.
  • Secure system architecture principles.
  • Security baselines and control frameworks.
  • Compliance monitoring and remediation tracking.
  • Cybersecurity requirements for cloud and modern digital services.
  • Emerging security considerations related to AI-driven applications.
Soft Skills
  • Strong analytical and problem-solving mindset.
  • Excellent written and verbal communication.
  • Ability to produce high-quality documentation.
  • Ability to present technical information clearly to different audiences.
  • Strong attention to detail.
  • Ability to work independently and take initiative.
  • Excellent team-player attitude.
  • Ability to work across multiple projects and stakeholders.
  • Comfortable working in multilingual and multicultural environments.
  • Ability to build trusted relationships with system owners, IT providers and institutional stakeholders.
  • High level of discretion, professionalism and integrity.
Ideal Candidate Profile

The ideal candidate is an early-career cybersecurity or information-security professional interested in developing a career in Governance, Risk & Compliance (GRC). You should have a solid foundation in information security standards and r