Information Security Governance Analyst

CRIF

Bologna

In loco

EUR 34.000 - 42.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Descrizione del lavoro

CRIF is seeking a talented Information Security Analyst to join its Information Security Governance function at a global level, focusing on strengthening governance and managing technology-driven cyber risks with emphasis on security controls. The role reports to the Chief Information Security Officer and collaborates with IT Cybersecurity teams and business units.

The position involves audits, security assessments, and embedding security measures into core processes, while promoting a

Competenze

  • 3+ years of professional experience in Information Security Governance or Cybersecurity.
  • Experience in Security Advisory, Cybersecurity Project & Program Management, IT Control Evaluation or IT Governance is a plus.
  • Hands-on risk management experience focusing on vulnerabilities, misconfigurations and security gaps.
  • Understanding of vulnerability management processes (scanning, prioritization, remediation tracking).
  • Strong knowledge of information security principles, frameworks and standards (GDPR, ISO, NIST, CIS, NIS).
  • Experience authoring security policies, standards and risk posture measurement.
  • Solid understanding of security domains: infrastructure, cloud, application, endpoint, security operations, DevSecOps, data security.
  • Ability to relate Enterprise Architecture, processes and cybersecurity risks; strong communication and collaboration skills.

Mansioni

  • Contribute to identification, analysis and mitigation of information security risks, focusing on vulnerabilities and misconfigurations.
  • Assist in Vendor and Third-Party Cybersecurity Management through assessments and audits.
  • Support development and revision of Global Technologies Information Security policies and metrics.
  • Coordinate security requirements with Global Technologies functions.
  • Work with Cybersecurity teams worldwide to align strategy with business needs.
  • Provide input to embed security requirements into IT governance processes.
  • Engage with business units to provide cybersecurity guidance on initiatives.
  • Support customer relationships, audits and security questionnaires.
  • Support Internal Audit activities, coordinating remediation actions.

Conoscenze

InfoSec governance
Cybersecurity
Vulnerability management
Regulatory standards (GDPR, NIST, ISO,

Strumenti

Vulnerability scanners

Descrizione del lavoro

We are looking for a highly talented individual to join the CRIF Information Security Governance function at global level. The candidate will support the organization in strengthening information security governance and in improving the management of technology-driven cyber risks, with a specific focus on security controls effectiveness. Collaborating with the Chief Information Security Officer, IT Cybersecurity Team and Managers, the Information Security Analyst will work closely with Global Technologies functions and company departments, contributing to identify, assess and mitigate Information Security risks associated with infrastructure, applications and services.

This position is ideal for someone passionate about information security governance and operational risk management, with a strong interest in practical risk management linked to vulnerabilities, misconfigurations and security gaps, and who enjoys continuously learning and sharing knowledge.

Business Overview:

CRIF is a company specializing in credit bureau and business information, outsourcing and processing services, and credit solutions. Established in 1988 in Bologna (Italy), CRIF has an international presence, operating over four continents (Europe, America, Africa, and Asia). More than 10,500 financial institutions, 600 insurance companies, 82,000 business clients, and 1,000,000 consumers use CRIF services in 50 countries daily.

The Information Security Governance function is part of Global Technologies, the CRIF IT division, with over 1500 professionals distributed in 15 countries, managing 29 datacenters and 12 development hubs, committed to delivering value to businesses, driving corporate Digital Transformation through the planning, development, and implementation of end-to-end solutions, adopting leading technologies and methodologies.

Reporting to the Chief Information Security Officer and working closely with the Cybersecurity team, the Information Security Governance function helps shape a consistent and pragmatic approach to cybersecurity across the organization. It focuses on understanding and addressing technology-driven risks, ensuring they are properly managed and embedded into governance, processes and business initiatives. It also supports customer-facing activities, including audits and security assessments, acting as a trusted point of reference on information security matters. The role acts as a bridge between cybersecurity, IT and business, promoting a solid, risk-aware culture and supporting the organization in making informed and secure decisions.

Your Key Responsibilities:

Reporting to the CRIF Information Security Manager you will be responsible for the following:

  • Contribute to the identification, analysis and mitigation of information security risks, with a strong focus on technology-related risk drivers such as vulnerabilities, misconfigurations, patching gaps and exposure of IT assets, ensuring that remediation actions are effectively tracked and implemented.
  • Assist in Vendor and Third-Party Cybersecurity Management through assessments, audits, and periodic reviews, coordinating security assessments and remediation activities to closure, ensuring compliance with information security standards and contractual requirements.
  • Support the development, implementation, and revision of Global Technologies Information Security policies, controls, and metrics to ensure compliance with CRIF Corporate Policies.
  • Coordinate with Global Technologies functions to ensure security requirements and controls align with technical needs, constraints, and evolving technology landscape.
  • Work closely with Cybersecurity teams worldwide to build and maintain a unified cybersecurity strategy aligned with global business needs and regulatory requirements.
  • Provide expert input to Global Technologies IT Governance functions to embed security requirements into core IT processes.
  • Maintain proactive engagement with business and staff functions to provide cybersecurity guidance in key initiatives (e.g. Awareness programs, M&A integrations, new business initiatives).
  • Support customer relationships, facilitating audits and responding to client cybersecurity requests and questionnaires.
  • Support Internal Audit activities, coordinating cybersecurity remediation actions and monitoring control effectiveness.
Your Skills and Experience:

3+ years of professional experience in Information Security Governance or Cybersecurity.

Experience in roles such as Security Advisory, Cybersecurity Project & Program Management, IT Control Evaluation or IT Governance is a plus

Hands-on experience in managing Information Security risk from a technical perspective, with the ability to understand and evaluate risks related to vulnerabilities, system exposures, misconfigurations and weaknesses in security controls (rather than purely theoretical or compliance-driven risk assessments).

Basic understanding of vulnerability management processes (e.g. scanning, prioritization, remediation tracking) and their role in defining the organization's cyber risk posture.

Strong knowledge of information security principles, frameworks and best practices, and the ability to apply those principles in clear and articulate way; experience in understanding regulatory and industry standards such as DORA, ISO standards, CIS, NIST framework, NIS directive, GDPR , etc

Experience in authoring security policies, standards, and supporting the measurement of cyber risk posture.

Solid understanding of Information Security domains including Infrastructure & Network Security, Cloud Security, Application Security, Endpoint Security, Security Operations and Incident Response, DevSecOps, and Data Security.

Ability to understand relationships between Enterprise Architecture, business processes, and cybersecurity risks.

Strong communication and collaboration skills, with the ability to explain technical risks in a clear and structured way.

The candidate must be a self-starter comfortable with ambiguity, with strong attention to detail, ability to work in a fast-paced, high-energy, and ever-changing environment.

We offer a safe and inclusive environment where colleagues are encouraged to think outside the box. CRIF is committed to creating a diverse, inclusive work environment and promoting equal opportunities throughout the employee life cycle. We aim to attract and retain the best people and embracing gender, age, culture, religion and disability diversity.

What we offer:

Type of contract: permanent.

The Annual Salary for this position starts from €38,000 gross per year.

The level of classification will be determined during the selection process based on the candidate’s profile and in accordance with the National Collective Labour Agreement (CCNL) for the Tertiary, Distribution and Services sector.

The final compensation package, including any variable components (such as MBO) or additional benefits, will depend on the assessment of the candidate’s profile against the role requirements.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cyber Security Analyst Senior
Cyber Security Analyst Senior

CRIF • Bologna

In loco
EUR 45.000 - 55.000
Security Governance Analyst, Italy
Security Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Cyber Risk & Information Security Governance Analyst
Cyber Risk & Information Security Governance Analyst

CRIF • Bologna

In loco
EUR 34.000 - 42.000
Information Risk Governance & Data Security
Information Risk Governance & Data Security

CRIF • Bologna

In loco
EUR 40.000 - 60.000
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Milano

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
Senior Process Analyst
Senior Process Analyst

CRIF • Bologna

In loco
EUR 29.000 - 35.000
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Security Governance specialist
Security Governance specialist

Generali Italia • Italia

In loco
EUR 45.000 - 55.000
Smart working & flexible hours
Meal vouchers
Supplementary health insurance
+3
Internal Audit Analyst Senior
Internal Audit Analyst Senior

CRIF • Bologna

In loco
EUR 29.000 - 36.000
Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.p.A. • Verona

Ibrido
EUR 48.000 - 56.000
Remote work up to 8 days/mo
Bonuses based on performance
Cafeteria and meal options
+1