Cyber Security Governance

2 ore fa

pavia, lombardia, Italia TeamSystem Tempo pieno
Overview

In this role you drive the secure software development lifecycle across the organization, shaping security practices, controls, and metrics. You partner with engineering and product teams to embed security by design and reduce risk, while leading initiatives that mature the company’s application security posture. You will engage with AI risk considerations and a fast-paced, cross-functional environment to deliver secure, high-quality software. This position offers impact in a growth-focused, innovation-driven company with hybrid work in Milan or Rome.

Retribuzione / Benefits
  • 4-day week
  • Wellbeing Digital Wallet
  • personal wellbeing budget (travel, medical, parental support, sports)
  • hybrid work model
  • tailored learning paths
  • global/international exposure
Responsabilità
  • Drive continuous improvement of the application security maturity across teams and products
  • Define, measure, and track security KPIs for vulnerability management and risk visibility
  • Lead application security initiatives and promote security-by-design from early development stages
  • Define and evolve security controls aligned with standards, regulations, and frameworks
  • Collaborate with Product Owners and development teams to align security with business priorities
  • Contribute to secure development lifecycle practices and guide engineering teams in security best practices
  • Read/review code and support SDLC with hands-on security expertise
Requisiti fondamentali
  • Knowledge of application security frameworks: SAMM, ASVS, NIST CSF
  • Understanding ISO 27000, NIS2, DORA, ACN, PCI-DSS and their impact on app security
  • Awareness of AI risk frameworks: NIST AI RMF, EU AI Act, ISO/IEC 23894, OWASP Top 10 for LLMs
  • Understanding AI-related risks and current AI landscape
  • Experience as software developer or security engineer; ability to read/review code (plus)
  • Familiarity with SAST, DAST, pen testing, dependency/vulnerability scanning (plus)
  • Strong knowledge of secure design principles: encryption, authentication/authorization, input filtering
  • Advanced English (C1)
  • collaboration
  • curiosity/continuous learning
  • proactive mindset
  • application security frameworks (SAMM, ASVS, NIST CSF)
  • AI risk and security concepts (NIST AI RMF, EU AI Act)
  • threat modeling