Cybersecurity Governance, Risk & Compliance (GRC) Consultant

SmartRecruiters, Inc.

San Donato Milanese

In loco

EUR 40.000 - 65.000

Part-time

3 giorni fa
Candidati tra i primi
Generatore di candidature

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Supera i filtri ATS

Descrizione del lavoro

COET srl is seeking an experienced Cybersecurity GRC Consultant to join a temporary, part-time engagement in Italy. You will support governance, risk management, compliance, and incident response across the organization, coordinating with IT, Legal, and Security teams.

The role focuses on risk assessments, control effectiveness, policy development, and reporting to management, with on-site presence at COET premises in San Donato Milanese as required, roughly three days per month.

Competenze

  • Experience in information security governance, risk management, and incident response.
  • Knowledge of NIST, NIS2, ISO 27001, and GDPR.
  • CISSP or CISM certification desirable; fluent in Italian and English.

Mansioni

  • Conduct cybersecurity risk assessments for COET srl.
  • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
  • Maintain and update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through completion.
  • Develop and monitor cybersecurity policies, standards, and control requirements.
  • Review risk assessments, mitigations, and risk acceptance requests.
  • Support cybersecurity governance forums and reporting activities.
  • Assist with internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with Energy cybersecurity standards and country regulations, including NIS2.

Conoscenze

GRC governance
Risk assessments
Regulatory knowledge
Stakeholder management

Formazione

CISSP
CISM

Descrizione del lavoro

Cybersecurity Governance, Risk & Compliance (GRC) Consultant
  • Contract

An enterprise technology client is seeking an experienced Information Security Professional to support the protection of COET srl’s information systems and data from cybersecurity threats.

The selected consultant will work closely with the company's Cybersecurity team to identify, assess, monitor, and report cybersecurity risks across the COET organization.

This is a temporary, part-time consulting opportunity based in Italy

This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response.

What You’ll Do:

  • Conduct cybersecurity risk assessments for COET srl.
  • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
  • Maintain and update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through completion.
  • Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
  • Develop and monitor cybersecurity policies, standards, and control requirements.
  • Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
  • Support cybersecurity governance forums and reporting activities.
  • Assist with internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with company's Energy cybersecurity standards and applicable country regulations, including NIS2.
  • Support control assessments and gap analyses.
  • Prepare materials for management and governance reviews.
  • Escalate significant cybersecurity risks and emerging trends.
  • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
  • Provide guidance on cybersecurity risk management processes and requirements.
  • Promote cybersecurity awareness and risk-informed decision-making.
  • Experience in Information Security governance, risk management, compliance, and incident response.
  • Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.
  • CISSP, CISM, or an equivalent certification is desirable.
  • Fluency in both Italian and English.
  • Strong communication and stakeholder management skills.
  • Ability to work independently and collaborate with cybersecurity and business teams.
  • Cybersecurity risk assessments and updated risk registers.
  • Risk mitigation and remediation tracking.
  • Cybersecurity policies, standards, and control requirements.
  • Audit evidence, control assessments, and gap analysis support.
  • Governance review materials and cybersecurity reporting.

Location Requirement

  • On-site presence at COET premises in San Donato Milanese, Italy, at least 3 times per month.
    • Category: Information Security & Compliance
    • Duration: September 14, 2026 to September 14, 2027
    • The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
    • Candidates should be comfortable proceeding under either engagement structure. If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.
Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cybersecurity Governance, Risk & Compliance (Grc) Consultant
Cybersecurity Governance, Risk & Compliance (Grc) Consultant

Lifted, An Upwork Company • Bardi

In loco
EUR 60.000 - 90.000
GRC Security Consultant: Governance, Risk & Compliance
GRC Security Consultant: Governance, Risk & Compliance

SmartRecruiters, Inc. • San Donato Milanese

In loco
EUR 40.000 - 65.000
GRC Security Consultant: Risk, Compliance & Governance
GRC Security Consultant: Risk, Compliance & Governance

Lifted, An Upwork Company • Bardi

In loco
EUR 60.000 - 90.000
Cybersecurity Compliance Consultant
Cybersecurity Compliance Consultant

GRCteam • Villa d'Almè

In loco
EUR 42.000 - 64.000
Laptop aziendale
Cellulare aziendale
Governance Risk Compliance Consultant
Governance Risk Compliance Consultant

Dacomat srl • Roma

In loco
EUR 80.000 - 100.000
Security Governance Analyst, Italy
Security Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Information Security Governance Analyst
Information Security Governance Analyst

Crif • Emilia-Romagna

In loco
EUR 34.000 - 42.000
INFORMATION SECURITY CONSULTANT – AMBITO IT-GRC
INFORMATION SECURITY CONSULTANT – AMBITO IT-GRC

NETGROUP • Roma

In loco
EUR 40.000 - 60.000
Ambiente di lavoro stimolante
Crescita professionale
Formazione continua
GRC Consultant – Cybersecurity & Data Protection
GRC Consultant – Cybersecurity & Data Protection

Gi Group SpA Filiale di Rovereto • Trentino-Alto Adige

In loco
EUR 30.000 - 35.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Roma

In loco
EUR 90.000 - 130.000