Назад
Company hidden
3 часа назад

Security Governance Analyst (Cybersecurity)

40 000 - 50 000
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Italy
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Governance Analyst (Cybersecurity): Supporting and improving information security governance, cybersecurity risk management, control monitoring, audit readiness, and regulatory compliance with an accent on governance frameworks, risk treatment, and management reporting. Focus on implementing DORA, NIS2, ISO 27001, and NIST CSF requirements, building KPI/KRI dashboards, and coordinating remediation across technical, risk, legal, and business stakeholders.

Location: Milan, Italy; hybrid workplace

Gross annual salary: €40,000–€50,000, depending on experience, skills, and qualifications.

Company

hirify.global provides software, workflow automation, real-time data, business intelligence, and consultancy services to financial institutions, trading firms, central banks, governments, and corporations.

What you will do

  • Support the implementation and continuous improvement of the information security governance framework.
  • Develop, maintain, and review cybersecurity policies, standards, procedures, and governance documentation.
  • Support cybersecurity risk assessments, remediation tracking, exception management, and risk treatment planning.
  • Monitor security control effectiveness and maturity, maintaining evidence, ownership records, action plans, and remediation initiatives for audit readiness.
  • Prepare KPI/KRI dashboards covering control coverage, patching, asset and API inventories, SBOM/SCA coverage, exception aging, and action-plan closure.
  • Collaborate with Technology, Risk, Compliance, Legal, and Business stakeholders and support audits, regulatory assessments, and client due diligence.

Requirements

  • Master’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Law, Management Engineering, or a related field.
  • 2–5 years of experience in information security governance, ICT risk management, cybersecurity compliance, internal audit, or a related function.
  • Understanding of vulnerability management, patch management, incident response, secure SDLC, third-party risk, and operational resilience governance requirements.
  • Knowledge of ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, NIS2, and related standards.
  • Strong analytical, organizational, stakeholder management, and governance reporting skills, with advanced Microsoft Excel and PowerPoint knowledge.
  • Excellent knowledge of Italian and English is required.

Nice to have

  • ISO 27001, CISA, CRISC, Security+, or equivalent professional certification.

Culture & Benefits

  • Permanent employment contract.
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico).
  • Opportunity to work within an international technology group serving the financial services industry.
  • Exposure to enterprise-wide cybersecurity governance activities in a dynamic, international environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →