Security Governance Analyst, Italy

ION Group

Lombardia

In loco

EUR 40.000 - 50.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Vantaggi offerti da questo lavoro

Permanent contract
CCNL Metalmeccanico

Descrizione del lavoro

ION Group in Milan is seeking a Security Governance Analyst to strengthen the CISO function across the organization. You will contribute to governance, risk management, and compliance activities in a dynamic, international setting.

The role requires 2–5 years of relevant experience, a Master’s degree in a related field, and strong knowledge of ISO 27001, NIST CSF, and regulatory requirements. The position offers a permanent contract and exposure to enterprise-wide cybersecurity governance.

Competenze

  • Master's degree in Cybersecurity or related field preferred.
  • 2–5 years of experience in Information Security Governance, ICT Risk Management, or Cybersecurity Compliance.
  • Good understanding of governance principles for vulnerability management, patch management, incident response, secure SDLC, third-party risk, and operational resilience.
  • Familiarity with ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, and NIS2.
  • Experience supporting audit activities and governance reporting.

Mansioni

  • Assist in implementing and improving the Information Security Governance framework across the organization.
  • Develop and maintain cybersecurity policies, standards, procedures, and governance documents.
  • Support risk management activities including risk assessments and remediation tracking.
  • Monitor and report on security controls maturity and governance effectiveness.
  • Prepare KPI/KRI dashboards and governance reporting for stakeholders.
  • Collaborate with Technology, Risk, Compliance, Legal, and business units.

Conoscenze

Information Security Governance
ICT Risk Management
Cybersecurity Compliance
Internal Audit
Governance reporting
Analytical skills
Stakeholder management
Excel
PowerPoint
English language
Italian language

Formazione

Master's degree in Cybersecurity

Descrizione del lavoro

About us:

We are a community of visionary innovators, dedicated to providing pioneering software and consultancy services to financial institutions, trading firms, central banks, governments, and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software, as well as providing real-time data and business intelligence to help people make better decisions. We are 13,000+ employees, we operate globally with 80+ global offices, and we serve over 4,800+ customers worldwide.

For the strengthening of the Chief Information Security Office (CISO) function within Cedacri’s companies, part of ION Group, we are looking for talented professionals to grow their career as Security Governance Analyst. This position is targeted at candidates with 2–5 years of relevant experience in Information Security Governance, Cybersecurity Risk Management, or ICT Compliance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to support cybersecurity governance initiatives across the organization.

Learn more at www.iongroup.com.

Your role
Your key duties and responsibilities
  • Support the implementation and continuous improvement of the Information Security Governance framework
  • Support the implementation, maintenance, and continuous improvement of the Information Security Governance framework across the organization.
  • Develop, maintain, and review cybersecurity policies, standards, procedures, and governance documentation.
  • Support cybersecurity risk management activities, including risk assessments, remediation tracking, exception management, and risk treatment planning.
  • Monitor the effectiveness and maturity of security controls and ensure governance activities remain aligned with organizational objectives and regulatory requirements.
  • Maintain governance evidence, action plans, ownership records, dependencies, and remediation initiatives to support audit readiness and effective reporting.
  • Prepare KPI/KRI dashboards for management on coverage, timeliness and effectiveness of controls, including asset/API inventories, SBOM/SCA coverage, patching performance, exception aging and action-plan closure.
  • Collaborate with Technology, Risk, Compliance, Legal, and Business stakeholders to ensure alignment with security governance requirements.
  • Support internal audits, external audits, regulatory assessments, and client due diligence activities.
  • Contribute to the implementation of regulatory and industry frameworks, including DORA, NIS2, ISO 27001, NIST CSF, and related standards.
  • Support governance transformation initiatives and continuous improvement programs aimed at strengthening cybersecurity oversight capabilities.
Other duties

We might ask you to perform other tasks and duties as your role expands.

Your skills, experience, and qualifications required
  • Master's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Law, Management Engineering, or a related field (with honors).
  • At least 2-5 years of experience in Information Security Governance, ICT Risk Management, Cybersecurity Compliance, Internal Audit, or related functions.
  • Good understanding of cybersecurity governance principles, governance requirements for vulnerability management, patch management, incident response, secure SDLC, third-party risk and operational resilience.
  • Knowledge of international standards and frameworks such as ISO 27001, NIST CSF, COBIT, CIS Controls, DORA, and NIS2.
  • Experience supporting audit activities, compliance assessments, regulatory initiatives, or governance reporting processes.
  • Ability to translate complex technical topics into clear governance, risk, and management reporting outputs.
  • Strong analytical, organizational, and stakeholder management skills.
  • Advanced knowledge of Microsoft Excel and PowerPoint.
  • Excellent knowledge of Italian and English.
  • Professional certifications such as ISO 27001, CISA, CRISC, Security+, or equivalent would be considered a plus.
What we offer:
  • Permanent employment contract
  • Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
  • Gross Annual Salary (RAL) ranging from €40,000 to €50,000, depending on experience, skills, and qualifications
  • Job grade to be determined upon completion of the selection process, with final assessment between B2 and B3 level
  • Opportunity to join a leading international technology group operating in the financial services industry
  • Exposure to enterprise-wide cybersecurity governance activities in a dynamic and international environment
Location:

Milan.

Important notes:

According to the Italian Law (L.68/99), candidates belonging to the protected categories list will be given priority.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Milano

In loco
EUR 40.000 - 50.000
Permanent employment contract
CCNL Metalmeccanico
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Information Security Governance Analyst
Information Security Governance Analyst

CRIF • Bologna

In loco
EUR 34.000 - 42.000
Security Governance specialist
Security Governance specialist

Generali Italia • Italia

In loco
EUR 45.000 - 55.000
Smart working & flexible hours
Meal vouchers
Supplementary health insurance
+3
Cyber Security Analyst Senior
Cyber Security Analyst Senior

CRIF • Bologna

In loco
EUR 45.000 - 55.000
Senior Legal Specialist, Italy
Senior Legal Specialist, Italy

ION Group • Lombardia

In loco
EUR 55.000 - 75.000
Permanent contract under CCNL Credito
Competitive compensation and benefits
Internationally oriented technology &
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Milano

Ibrido
EUR 90.000 - 110.000
Senior Cybersecurity Advisor
Senior Cybersecurity Advisor

NTT DATA Europe & Latam • Roma

Ibrido
EUR 90.000 - 130.000
Security Threat Assessment & Analysis Senior Professional
Security Threat Assessment & Analysis Senior Professional

Source Technology Limited • Milano

Ibrido
EUR 70.000 - 110.000
Chief Information Security Officer
Chief Information Security Officer

Datalogic • Bologna

In loco
EUR 55.000 - 70.000
Welfare package
Permanent contract