RINA is currently recruiting for a Cybersecurity GRC Consultant to join its office in GENOA, ROME, or MILAN within the Cyber Security and Management Consulting Division.
Mission
RINA is seeking a Cyber Security GRC Consultant to join our Cyber Team in GENOA, ROME, or MILAN.
Key Accountabilities
The person will be responsible for:
- Carrying out technical activities such as:
- Identifying security risks within organizations and complex systems/architectures.
- Designing security measures and providing recommendations to improve security postures.
- Verifying compliance with laws, regulations, and standards related to security and cybersecurity.
- Supporting Customers in cybersecurity-related activities.
- Drafting technical and procedural documents related to:
- IT Security Governance, Risk, and Compliance aspects (e.g., ISO/IEC 27001:2022, NIS/NIS2 directives, PSNC).
- INFOSEC aspects (e.g., National Scheme for IT products security evaluation, Common Criteria/ISO 15408, ENISA EUCC).
- Cybersecurity in Industrial Automation Control Systems (e.g., IEC 62443 requirements for risk assessment, systems, and components).
- Marine cybersecurity requirements from the International Association of Classification Societies (e.g., IACS Unified Requirements, IMO circulars).
- Maintaining and updating RINA cybersecurity guidelines and assessment methodologies.
- Supporting business development from a technical perspective, including drafting technical offers and detailing services (for senior personnel).
Education
Bachelor’s Degree in Engineering (General).
Qualifications
Requirements:
- Knowledge of laws, regulations, international standards, and best practices (e.g., ISO/IEC 27001, NIST Cybersecurity Framework, NIS/NIS2, ISA/IEC 62443, Common Criteria/ISO 15408, ISO 21434).
- Engineering academic background.
- Strong problem-solving skills.
- Excellent verbal and written communication skills in Italian and English.
- Flexibility and ability to multitask in a fast-paced environment.
- Willingness to travel within the country and abroad.
Desired Requirements:
- Experience with a wide range of computer systems and security tools.
- Security certifications such as ISO/IEC 27001 Lead Auditor, GIAC/GICSP, ISA/IEC 62443 certifications, CEH, OSCP, ISACA CISM/CISA/CRISC, ISC2 CISSP.
- Knowledge of programming languages (Java, C/C++, C#, VB.Net, Python), their interfaces with DBMS, and development environments.
- Understanding of networking concepts (segmentation, protocols, security), with experience in network administration/configuration appreciated.
- Ability to see the big picture and interpret situations from multiple perspectives.
- Ability to build trust and forge relationships across departments and outside the organization.
- Focus on client needs and expectations to ensure satisfaction.
- Trustworthiness and openness to diversity.
- Effective decision-making skills, prioritizing activities and managing resources.
- Emotional management and self-awareness.