Compliance Specialist (It)

Changetheblock

Bardi

In loco

EUR 70.000 - 110.000

Tempo pieno

42 ore fa
Candidati tra i primi
Generatore di candidature

Una candidatura completa in un minuto — curriculum e lettera di presentazione personalizzati, pronti da inviare.

Supera i filtri ATS

Descrizione del lavoro

Changetheblock cerca un professionista esperto per supportare l’implementazione della policy di cybersecurity della EC all’interno del contesto JRC. Il candidato analizzerà processi e controlli, svilupperà basi e guide per la sicurezza e interagirà con responsabili di sistema e fornitori IT.

È richiesta capacità di comunicare con audience tecniche e non tecniche, gestione di documentazione di sicurezza e conoscenza di IA e cloud nel contesto europeo.

Competenze

  • Buona conoscenza della famiglia ISO 27000 e delle politiche di sicurezza EC.
  • Con esperienza nello sviluppo e revisione di metodologie di sicurezza.
  • Capacità di condurre valutazioni d’impatto e rischi (BIA/Risk Assessment).
  • Abilità nel redigere piani di sicurezza e architetture di sistemi sicuri.
  • Ottima capacità di presentare a soggetti tecnici e non tecnici in riunioni multilingual.
  • Conoscenza delle nuove tecnologie cloud, IA e servizi digitali nel contesto JRC.

Mansioni

  • Definire requisiti di conformità per i controlli dei sistemi informativi, in stretta collaborazione con System Owner e Manager.
  • Preparare modelli/templates per processi di sicurezza e soluzioni tecniche per servizi digitali.
  • Supportare owner e fornitori IT nelle attività di valutazione d’impatto, rischio e piano di sicurezza.
  • Gestire e monitorare piani di sicurezza, architetture di sistema e implementazione di misure di mitigazione.
  • Coordinare valutazioni di rischio e riferire lo stato di conformità al LISO JRC.

Conoscenze

ISO 27000 standard
EC Security Policies
Risk assessment techniques
Security methodology development
Business Impact Assessments
Security planning documentation
Clear technical writing
Multilingual stakeholder engagement

Formazione

Bachelor degree or higher

Descrizione del lavoro

Descrizione dell’offerta di lavoro

The JRC Local Informatics Security Officer (LISO) with in the directorate JRC.T (Digital Transformation, AI and Data), in partnership with other Commission services and stakeholders, has among his responsibilities to ensure that, in JRC, adequate security measures are in place and operational for the information systems and their supporting IT infrastructures, enabling the successful implementation of the Commission#39;s Digital Transformation and EU policies.

The Commission#39;s adopted comprehensive standards on Information Systems Security, established through Decision 2017/46, mandate that all critical information receives appropriate protection levels consistently across the European Commission. These standards require that suitable security controls are systematically identified and integrated into Commission Information Systems.

To support the JRC System Owners and IT service providers in being compliant with these requirements, the LISO requires specialized technical expertise to advise on the implementation of the EC cybersecurity policy within JRC, conduct reviews of processes and controls to assess their effectiveness and overall alignment with the EC regulatory frameworks and policies.

Description of the tasks

  • The external service provider will perform the following tasks:
    • Definition of compliance requirements for JRC information‑system controls, in close collaboration with the System owners and System managers
    • Preparation of templates covering security processes, controls and technical solutions across all JRC digital services
    • Support System Owners and IT service providers with the elaboration of their:
      • Business Impact Assessment and Scope of Security
      • Risk Assessment exercise
      • Security Plan
      • Secure System Architecture Design
      • Implementation Plan
      • Assistance with the management of remediation activities, including tracking of non‑conformities, assignment of corrective actions to system owners and verification of their closure within agreed time‑frames
      • Development and maintenance of security baselines for the JRC systems and services
      • Coordination and review of risk‑assessments, ensuring that identified risks are evaluated against the defined compliance criteria and that mitigation measures are documented
      • Reporting of compliance status to the JRC LISO, highlighting gaps and progress on remediation
      • Interaction with system owners and IT service providers and other relevant Commission services to ensure consistent interpretation and application of security policies
Level of education

As stated in section 5.1 of FREIA Specifications for the technical profiles for operational services the minimum educational qualification is a Level of education corresponding to Level 5 of the European Qualification Framework, which typically corresponds to 2 years of post-secondary education or higher, for the Junior and Confirmed seniority levels, and a Level of education corresponding to Level 6 of the European Qualification Framework, which typically corresponds to a Bachelor degree or higher, for the Senior seniority levels.

Specific knowledge, skills and expertise
  • Good knowledge of ISO 27000 family of standards, the EC Security Policies, the European Commission Risk‑management methodology and related risk‑assessment techniques
  • Good experience in the security domain, including the development and review of security methodologies, Business Impact Assessments, Risk Assessments and Secure System Architecture Design
  • Ability to review draft Security Plans and related security‑plan material efficiently and fast
  • Ability to give business and technical presentations to system owners, IT service providers
  • Ability to apply high quality standards in documentation, template creation and guidance material for security planning
  • Ability to cope with fast changing technologies used in cloud services, AI‑driven applications and other digital services within the JRC environment
  • Very good communication skills with technical and non-technical audiences to facilitate multilingual, multicultural meetings and stakeholder engagement
  • Analysis and problem solving skills
  • Capability to write clear and structured technical documents
  • Ability to participate in technical meetings and good communication skills
  • Relevant certifications in Governance, Risk and Compliance or Risk Management and Audit or broad Cybersecurity are an advantageous asset (CGRC, CRISC, CISA, CISSP, CISM, etc..)
Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cybersecurity Compliance Specialist
Cybersecurity Compliance Specialist

MEERAB GROUP • Agrate Brianza

In loco
EUR 40.000 - 65.000
Cybersecurity Compliance Specialist
Cybersecurity Compliance Specialist

Appsierra Group • Ispra, Agrate Brianza

In loco
EUR 32.000 - 52.000
JUNIOR ANALYST – COMPLIANCE & SECURITY
JUNIOR ANALYST – COMPLIANCE & SECURITY

AURIGA SPA • Bari

In loco
EUR 40.000 - 65.000
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)

4Shiva • Udine

Ibrido
EUR 70.000 - 110.000
Sede a Roma
Formazione continua e certificazioni
Cyber Security Compliance Consultant
Cyber Security Compliance Consultant

Hexywave • Treviso

In loco
EUR 35.000 - 45.000
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)

4Shiva • Napoli

Ibrido
EUR 70.000 - 100.000
Sede a Roma o remoto
Formazione continua
RAL commisurata all'esperienza
Junior Consultant, Technology Risk
Junior Consultant, Technology Risk

Jobtailor • Catania

In loco
EUR 40.000 - 60.000
Information Security Manager
Information Security Manager

CDS - La tua Casa della Salute • Genova

In loco
EUR 45.000 - 65.000
CYS _Cyber Security Service Manager_GCSC
CYS _Cyber Security Service Manager_GCSC

Leonardo SpA • Italia

In loco
EUR 45.000 - 65.000
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)
Security & Compliance Specialist (Iso 27001 | Nis2 | Grc)

4Shiva • Ancona

In loco
EUR 65.000 - 95.000
Formazione continua
Supporto certificazioni
Remote/Roma sede