Cybersecurity Compliance Specialist
3 ore fa
monzabrianza, lombardia, Italia
MEERAB GROUP
Tempo pieno
Gratuito con email o Google
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Gratuito con email o Google
Key Responsibilities
- Define and document cybersecurity compliance requirements for information-system controls in collaboration with system owners and system managers.
- Develop and maintain templates covering security processes, controls and technical security solutions across digital services.
- Support system owners and IT service providers with:
- Business Impact Assessments (BIA).
- Definition of security scope.
- Risk assessments.
- Security plans.
- Secure system architecture designs.
- Implementation plans.
- Assist with cybersecurity remediation activities, including:
- Tracking identified non-conformities.
- Assigning corrective actions.
- Monitoring remediation progress.
- Verifying closure of corrective actions within agreed deadlines.
- Contribute to the development and maintenance of security baselines for information systems and digital services.
- Coordinate and review risk assessments, ensuring that identified risks are evaluated against established compliance criteria and that mitigation measures are properly documented.
- Prepare compliance-status reports highlighting security gaps, risks and remediation progress.
- Collaborate with system owners, IT service providers and other stakeholders to ensure consistent interpretation and implementation of cybersecurity policies.
- Participate in technical and stakeholder meetings and communicate security requirements to both technical and non-technical audiences.
- Produce clear, structured and high-quality security documentation, templates and guidance material.
- Keep up to date with evolving technologies, particularly cloud services, AI-driven applications and other digital services, and their associated cybersecurity implications.
- Minimum EQF Level 5 education, typically corresponding to at least two years of post-secondary education or higher.
- Educational background in Cybersecurity, Information Security, Computer Science, IT, Risk Management, Governance, Audit or a related discipline.
- Practical experience or demonstrable knowledge of information security and cybersecurity compliance.
- Good knowledge of the ISO/IEC 27000 family of standards.
- Knowledge of information-security governance, risk-management principles and security controls.
- Understanding of Business Impact Assessments, Risk Assessments and Secure System Architecture.
- Ability to review and assess security plans and related documentation.
- Strong analytical and problem-solving capabilities.
- Ability to produce clear, structured and professional technical documentation.
- Good communication skills and the ability to explain cybersecurity concepts to technical and non-technical stakeholders.
- Ability to work effectively in an international and multicultural environment.
- Good level of written and spoken English.
Professional certifications in cybersecurity, governance, risk, compliance, risk
Management Or Auditing Are Considered An Advantage, Such As- CGRC
- CRISC
- CISA
- CISSP
- CISM
- Other relevant cybersecurity or GRC certifications
- Information security governance and compliance.
- ISO 27001 / ISO 27000 standards.
- Cybersecurity policies and security controls.
- Risk assessment and risk treatment.
- Business Impact Assessment methodologies.
- Security planning and documentation.
- Secure system architecture principles.
- Security baselines and control frameworks.
- Compliance monitoring and remediation tracking.
- Cybersecurity requirements for cloud and modern digital services.
- Emerging security considerations related to AI-driven applications.
- Strong analytical and problem-solving mindset.
- Excellent written and verbal communication.
- Ability to produce high-quality documentation.
- Ability to present technical information clearly to different audiences.
- Strong attention to detail.
- Ability to work independently and take initiative.
- Excellent team-player attitude.
- Ability to work across multiple projects and stakeholders.
- Comfortable working in multilingual and multicultural environments.
- Ability to build trusted relationships with system owners, IT providers and institutional stakeholders.
- High level of discretion, professionalism and integrity.
The ideal candidate is an early-career cybersecurity or information-security professional interested in developing a career in Governance, Risk & Compliance (GRC). You should have a solid foundation in information security standards and r