Information Security Expert

3 giorni fa

Cusano Milanino, Lombardy, Italia Experteer Italy Tempo pieno

Specialista Senior / Project Manager

As Information Security Manager at Kuehne+Nagel, you lead governance, risk, and compliance efforts to strengthen cybersecurity and regulatory posture. You will drive NIS2 implementation, partner with IT, Legal, Compliance, and regional security teams, and promote a resilient security culture across the organization. You tackle risk assessments, incident coordination, and third-party security, shaping secure operations for global logistics. This is an opportunity to impact how we protect critical systems and enable trustworthy service delivery.

  • safe and stable environment
  • international growth opportunities
  • teamwork that matters
  • flexible work environment
  • Lead the implementation of NIS2 requirements with gap assessments, remediation plans, and ongoing monitoring
  • Establish and maintain information security governance, policies, and controls aligned with Global and EMEA standards
  • Conduct security risk assessments, manage risk treatment plans, and monitor control effectiveness
  • Coordinate security incident management and regulatory reporting with IT, Legal, Compliance, and cybersecurity teams
  • Support internal and external audits and regulatory inspections with timely remediation of findings
  • Drive third-party and supply chain security risk management including supplier assessments and due diligence
  • Define, monitor, and report security KPIs and risk metrics to local leadership and EMEA Information Security
  • Deliver security awareness initiatives and promote a cybersecurity culture across the organization
  • Degree in Information Security, Computer Science, Engineering, Law/Compliance, or equivalent professional experience
  • Proven experience in Information Security Governance, Risk & Compliance (GRC) or related security functions
  • Experience implementing security frameworks and regulatory requirements (NIS2, ISO 27001, NIST CSF, or CIS Controls)
  • Strong knowledge of information security risk management, ISMS processes, and audit readiness
  • Good understanding of security domains: vulnerability management, IAM, SIEM, endpoint security, network security, backup and recovery, encryption
  • Excellent stakeholder management, communication, and project management skills for technical and non-technical audiences
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are advantageous
  • Fluent English and professional Italian required