Cybersecurity Compliance Specialist

Appsierra Group

Ispra, Agrate Brianza

In loco

EUR 32.000 - 52.000

Tempo pieno

7 giorni fa
Candidati tra i primi
Generatore di candidature

Una candidatura completa in un minuto — curriculum e lettera di presentazione personalizzati, pronti da inviare.

Supera i filtri ATS

Descrizione del lavoro

Appsierra Group in Lombardia, Italy seeks an early-career cybersecurity professional to develop governance, risk and compliance capabilities. You will work with system owners to define controls, prepare security documentation, and help align security practices across digital services.

The role emphasizes building secure architectures, risk assessment methodologies, and clear communication of security requirements to diverse stakeholders.

Competenze

  • Two years of post-secondary education or higher in a cybersecurity-related field.
  • Background in Cybersecurity, Information Security, Computer Science, IT, Risk Management, Governance, Audit or related discipline.
  • Practical knowledge of information security and cybersecurity compliance.
  • Solid understanding of ISO/IEC 27000 family standards.
  • Knowledge of governance, risk-management principles and security controls.
  • Ability to review security plans and documentation.
  • Strong analytical and problem-solving skills; detail-oriented.
  • Good written and spoken English.

Mansioni

  • Define and document cybersecurity compliance requirements with system owners/managers.
  • Develop and maintain templates for security processes and controls.
  • Assist with risk assessments, security scope, and secure architecture designs.
  • Support remediation activities: track non-conformities, assign actions, monitor progress.
  • Prepare compliance-status reports and document security guidance.
  • Coordinate with stakeholders to ensure consistent policy interpretation.
  • Communicate security requirements to technical and non-technical audiences.
  • Stay updated on cloud, AI-driven services and cybersecurity implications.

Conoscenze

Information security
Cybersecurity
ISO 27001
Risk assessment
Security governance
Documentation
Communication
Analytical thinking

Formazione

EQF Level 5 education
Cybersecurity-related degree

Descrizione del lavoro

Key Responsibilities
  • Define and document cybersecurity compliance requirements for information-system controls in collaboration with system owners and system managers.
  • Develop and maintain templates covering security processes, controls and technical security solutions across digital services.
  • Support system owners and IT service providers with:
    • Business Impact Assessments (BIA).
    • Definition of security scope.
    • Risk assessments.
    • Security plans.
    • Secure system architecture designs.
    • Implementation plans.
  • Assist with cybersecurity remediation activities, including:
    • Tracking identified non-conformities.
    • Assigning corrective actions.
    • Monitoring remediation progress.
    • Verifying closure of corrective actions within agreed deadlines.
  • Contribute to the development and maintenance of security baselines for information systems and digital services.
  • Coordinate and review risk assessments, ensuring that identified risks are evaluated against established compliance criteria and that mitigation measures are properly documented.
  • Prepare compliance-status reports highlighting security gaps, risks and remediation progress.
  • Collaborate with system owners, IT service providers and other stakeholders to ensure consistent interpretation and implementation of cybersecurity policies.
  • Participate in technical and stakeholder meetings and communicate security requirements to both technical and non-technical audiences.
  • Produce clear, structured and high-quality security documentation, templates and guidance material.
  • Keep up to date with evolving technologies, particularly cloud services, AI-driven applications and other digital services, and their associated cybersecurity implications.
Required Qualifications
  • Minimum EQF Level 5 education, typically corresponding to at least two years of post-secondary education or higher.
  • Educational background in Cybersecurity, Information Security, Computer Science, IT, Risk Management, Governance, Audit or a related discipline.
  • Practical experience or demonstrable knowledge of information security and cybersecurity compliance.
  • Good knowledge of the ISO/IEC 27000 family of standards.
  • Knowledge of information-security governance, risk-management principles and security controls.
  • Understanding of Business Impact Assessments, Risk Assessments and Secure System Architecture.
  • Ability to review and assess security plans and related documentation.
  • Strong analytical and problem-solving capabilities.
  • Ability to produce clear, structured and professional technical documentation.
  • Good communication skills and the ability to explain cybersecurity concepts to technical and non-technical stakeholders.
  • Ability to work effectively in an international and multicultural environment.
  • Good level of written and spoken English.
Valuable

Professional certifications in cybersecurity, governance, risk, compliance, risk management or auditing are considered an advantage, such as:

  • CGRC
  • CRISC
  • CISA
  • CISSP
  • CISM
  • Other relevant cybersecurity or GRC certifications
Technical Skills

The ideal candidate should demonstrate knowledge or exposure some of the next:

  • Information security governance and compliance.
  • ISO 27001 / ISO 27000 standards.
  • Cybersecurity policies and security controls.
  • Risk assessment and risk treatment.
  • Business Impact Assessment methodologies.
  • Security planning and documentation.
  • Secure system architecture principles.
  • Security baselines and control frameworks.
  • Compliance monitoring and remediation tracking.
  • Cybersecurity requirements for cloud and modern digital services.
  • Emerging security considerations related to AI-driven applications.
Soft Skills
  • Strong analytical and problem-solving mindset.
  • Excellent written and verbal communication.
  • Ability to produce high-quality documentation.
  • Ability to present technical information clearly to different audiences.
  • Strong attention to detail.
  • Ability to work independently and take initiative.
  • Excellent team-player attitude.
  • Ability to work across multiple projects and stakeholders.
  • Comfortable working in multilingual and multicultural environments.
  • Ability to build trusted relationships with system owners, IT providers and institutional stakeholders.
  • High level of discretion, professionalism and integrity.
Ideal Candidate Profile

The ideal candidate is an early-career cybersecurity or information-security professional interested in developing a career in Governance, Risk & Compliance (GRC).

You should have a solid foundation in information security standards and risk management, be comfortable working with security documentation and assessments, and have the communication skills required to interact with both technical and business stakeholders.

Experience with ISO 27001, risk assessments, security plans, security controls, compliance monitoring or cybersecurity audits would be particularly relevant.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.p.A. • Verona

Ibrido
EUR 48.000 - 56.000
Remote work up to 8 days/mo
Bonuses based on performance
Cafeteria and meal options
+1
Cyber Security Compliance Consultant
Cyber Security Compliance Consultant

Arsenalia • Mestre

In loco
EUR 35.000 - 50.000
Welfare Package
Worklife Kit
Career Path development program
Cyber Security Compliance Consultant
Cyber Security Compliance Consultant

Arsenalia • Venezia

In loco
EUR 35.000 - 50.000
Welfare Package
Worklife Kit
Career Path development program
+1
Cybersecurity Legal and Privacy Advisor
Cybersecurity Legal and Privacy Advisor

Cosmote Global • Varese

Ibrido
EUR 80.000 - 105.000
None
Cybersecurity Legal and Privacy Advisor
Cybersecurity Legal and Privacy Advisor

Cosmote Global Solutions • Ispra

In loco
EUR 80.000 - 110.000
Security Threat Assessment & Analysis Senior Professional
Security Threat Assessment & Analysis Senior Professional

Sgi • Bardi

Ibrido
EUR 65.000 - 105.000
Hybrid work model
CYBER SECURITY EXPERT
CYBER SECURITY EXPERT

De’ Longhi Appliances S.r.l. • Treviso

In loco
EUR 65.000 - 85.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Milano

Ibrido
EUR 90.000 - 110.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Roma

Ibrido
EUR 90.000 - 130.000
IT Security & Compliance Manager
IT Security & Compliance Manager

The Adecco Group • Turbigo

In loco
EUR 70.000 - 90.000