Cybersecurity Governance, Risk & Compliance (Grc) Consultant

Lifted, An Upwork Company

Bardi

In loco

EUR 60.000 - 90.000

Tempo pieno

14 giorni+
Generatore di candidature

Non inviare un curriculum generico — genera un curriculum e una lettera di presentazione personalizzati per questo specifico ruolo.

Supera i filtri ATS

Descrizione del lavoro

Lifted, An Upwork Company is seeking an experienced Information Security professional to lead governance, risk management, compliance, and incident response activities in Italy. The role is based on-site in San Donato Milanese, Lombardy, with collaboration across IT, Product Security, IAM, Legal, Procurement, Privacy and business teams.

You will run cybersecurity risk assessments for COET srl, maintain risk registers, monitor remediation, develop policies and controls, and support audits and

Competenze

  • Experience in Information Security governance, risk management, compliance, and incident response.
  • Knowledge of NIST, NIS2, ISO 27001, and GDPR.
  • CISSP, CISM or equivalent certification desirable.
  • Fluency in Italian and English.
  • Strong communication and stakeholder management skills.
  • Ability to work independently and collaborate with cybersecurity and business teams.
  • Cybersecurity risk assessments and updated risk registers.
  • Risk mitigation and remediation tracking.
  • Cybersecurity policies, standards, and control requirements.
  • Audit evidence, control assessments, and gap analysis support.
  • Governance review materials and cybersecurity reporting.

Mansioni

  • Conduct cybersecurity risk assessments for COET srl.
  • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
  • Maintain and update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through completion.
  • Recommend improvements to Information Security operations.
  • Develop and monitor cybersecurity policies, standards, and control requirements.
  • Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
  • Support cybersecurity governance forums and reporting activities.
  • Assist with internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.
  • Support control assessments and gap analyses.
  • Prepare materials for management and governance reviews.
  • Escalate significant cybersecurity risks and emerging trends.
  • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
  • Provide guidance on cybersecurity risk management processes and requirements.
  • Promote cybersecurity awareness and risk-informed decision-making.

Conoscenze

cybersecurity governance
risk management
compliance
incident response
stakeholder management
communication
policy development

Descrizione del lavoro

This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response.

What You’ll Do:
  • Conduct cybersecurity risk assessments for COET srl.
  • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
  • Maintain and update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through completion.
  • Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
  • Develop and monitor cybersecurity policies, standards, and control requirements.
  • Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
  • Support cybersecurity governance forums and reporting activities.
  • Assist with internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.
  • Support control assessments and gap analyses.
  • Prepare materials for management and governance reviews.
  • Escalate significant cybersecurity risks and emerging trends.
  • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
  • Provide guidance on cybersecurity risk management processes and requirements.
  • Promote cybersecurity awareness and risk-informed decision-making.
Nice to Haves:
  • Experience in Information Security governance, risk management, compliance, and incident response.
  • Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.
  • CISSP, CISM, or an equivalent certification is desirable.
  • Fluency in both Italian and English.
  • Strong communication and stakeholder management skills.
  • Ability to work independently and collaborate with cybersecurity and business teams.
  • Cybersecurity risk assessments and updated risk registers.
  • Risk mitigation and remediation tracking.
  • Cybersecurity policies, standards, and control requirements.
  • Audit evidence, control assessments, and gap analysis support.
  • Governance review materials and cybersecurity reporting.
Location Requirement
  • On-site presence at COET premises in San Donato Milanese, Italy, at least 3 times per month.
Additional Information
  • Category: Information Security & Compliance
  • Duration: September 14, 2026 to September 14, 2027
  • The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
  • Candidates should be comfortable proceeding under either engagement structure. If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.

Cybersecurity Governance, Risk & Compliance (GRC) Consultant • San Donato Milanese, Lombardy, Italy

Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cybersecurity Governance, Risk & Compliance (GRC) Consultant
Cybersecurity Governance, Risk & Compliance (GRC) Consultant

SmartRecruiters, Inc. • San Donato Milanese

In loco
EUR 40.000 - 65.000
GRC Security Consultant: Governance, Risk & Compliance
GRC Security Consultant: Governance, Risk & Compliance

SmartRecruiters, Inc. • San Donato Milanese

In loco
EUR 40.000 - 65.000
GRC Security Consultant: Risk, Compliance & Governance
GRC Security Consultant: Risk, Compliance & Governance

Lifted, An Upwork Company • Bardi

In loco
EUR 60.000 - 90.000
Cybersecurity Compliance Consultant
Cybersecurity Compliance Consultant

GRCteam • Villa d'Almè

In loco
EUR 42.000 - 64.000
Laptop aziendale
Cellulare aziendale
Governance Risk Compliance Consultant
Governance Risk Compliance Consultant

Dacomat srl • Roma

In loco
EUR 80.000 - 100.000
Security Governance Analyst, Italy
Security Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
IT Security & Compliance Manager
IT Security & Compliance Manager

The Adecco Group • Turbigo

In loco
EUR 70.000 - 90.000
Information Security Governance Analyst
Information Security Governance Analyst

Crif • Emilia-Romagna

In loco
EUR 34.000 - 42.000
Information Security Governance Analyst
Information Security Governance Analyst

Crif • Lazio

Remoto
EUR 34.000 - 42.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Roma

In loco
EUR 90.000 - 130.000