Milano
In loco
EUR 55.000 - 80.000
Tempo pieno
Aumenta le tue possibilità di ottenere un colloquio
Crea un curriculum personalizzato per un lavoro specifico per avere più probabilità di riuscita.
Descrizione del lavoro
Une entreprise leader dans le secteur des technologies recherche un Cyber Risk Manager pour superviser les projets de gestion des risques cyber. Le candidat idéal aura une expérience solide dans le domaine, un diplôme en Informatique ou en Génie des Télécommunications, et sera capable de travailler en collaboration avec divers acteurs pour garantir une sécurité efficace. Ce rôle implique la surveillance des contrôles de sécurité, la gestion des exceptions et le reporting à la direction sur les enjeux de cybersécurité.
Competenze
- Expérience avérée en gestion des risques cyber dans des entreprises du secteur ICT.
- Certification CISSP, CISA, CISM ou équivalente est un atout.
- Excellente connaissance des services et architectures ICT.
Mansioni
- Mettre en œuvre une approche basée sur les risques pour prioriser le développement de modèles de sécurité.
- Soutenir la conformité en matière de GDPR, SOX et PCI / DSS.
- Faciliter les audits et remédiations des constatations en matière de cybersécurité.
Conoscenze
Gestion des risques informatiques
Connaissance des normes de sécurité
Compétences en communication
Utilisation des outils de gestion des risques
Formazione
Master en Informatique ou Génie des Télécommunications
Strumenti
Outils de gestion des risques informatiques
- Implement a risk-based approach to prioritize development of secure patterns for high-risk assets or activities.
- Update Sky risk management process in accordance with the industrial best practices and with Sky Policy.
- Cooperation with the group structures for cyber risk management activities.
- Use of the corporate cyber risk management platform to manage the cyber risk register.
- Continuously update the risk management process in accordance with the industrial best practices and with the company Policy.
- Management of Exceptions process to policies, standards and guidelines.
- Monitoring and reviewing security controls to identify their operational effectiveness.
- Facilitate audits and remediations of any findings noted in cyber security dept.
- Support on cyber security compliance on GDPR, SOX and PCI / DSS
- Provide reporting to management for all aspects of Cyber Risk as required.
- Metrics and Reporting :
- Creation of reports on the status of risks, KRIs and managing communication in the Enterprise Risk Committee meetings.
- Development of visual dashboards that board directors can use to monitor risks
- Control of the effectiveness of the metrics adopted.
Requirements :
- Proved experience in similar roles, gained in consulting companies and / or large companies in the ICT sector in relation to cyber risk management projects.
- Master degree in Computer Science or Telecommunication Engineering.
- Knowledge of the landscape of norms and standards in the privacy / information security field (HIPAA, NY DFS, GDPR, CCPA, ISO / IEC 27000, NIST, PCI DSS, etc.)
- Knowledge of the main Risk Management / Control Frameworks (COSO, COBIT, ISO, ITIL, NIST, FAIR, etc.).
- Able to articulate cyber risk management concepts to a wide range of recipients.
- Excellent knowledge of cyber risk management tools and experience in using some of them.
- Excellent understanding of ICT services and architectures
- The achievement of CISSP, CISA, CISM, SANS GIAC, SABSA certifications will be considered a preferential title.
- Excellent verbal and written communication skills
- Ability to constructively and proactively interact with all the stakeholders, respecting the work needs and the role of each.