Security Governance & Risk Analyst — Tech Risk Focus

Crif

Emilia-Romagna

In loco

EUR 34.000 - 42.000

Tempo pieno

5 giorni fa
Candidati tra i primi
Generatore di candidature

Una candidatura completa in un minuto — curriculum e lettera di presentazione personalizzati, pronti da inviare.

Supera i filtri ATS

Descrizione del lavoro

CRIF is seeking an Information Security Governance Analyst to strengthen technology-driven cyber risk management and governance across the organization. You will collaborate with CIO, IT Cybersecurity and global teams to identify, assess and mitigate information security risks within infrastructure, applications and services.

The role emphasizes governance, policy development, audits, and alignment with regulatory standards.

Competenze

  • 3+ years of professional experience in Information Security Governance or Cybersecurity.
  • Experience in roles such as Security Advisory, Cybersecurity Project & Program Management, IT Control Evaluation or IT Governance is a plus
  • Hands-on experience in managing Information Security risk from a technical perspective, with the ability to understand and evaluate risks related to vulnerabilities, system exposures, misconfigurations and weaknesses in security controls
  • Basic understanding of vulnerability management processes (e.g. scanning, prioritization, remediation tracking) and their role in defining the organization's cyber risk posture
  • Strong knowledge of information security principles, frameworks and best practices, and the ability to apply those principles in clear and articulate way; experience in understanding regulatory and industry standards such as DORA, ISO standards, CIS, NIST framework, NIS directive, GDPR, etc
  • Experience in authoring security policies, standards, and supporting the measurement of cyber risk posture
  • Solid understanding of Information Security domains including Infrastructure & Network Security, Cloud Security, Application Security, Endpoint Security, Security Operations and Incident Response, DevSecOps, and Data Security
  • Ability to understand relationships between Enterprise Architecture, business processes, and cybersecurity risks
  • Strong communication and collaboration skills, with the ability to explain technical risks in a clear and structured way
  • The candidate must be a self-starter comfortable with ambiguity, with strong attention to detail, ability to work in a fast-paced, high-energy, and ever-changing environment.

Mansioni

  • Contribute to the identification, analysis and mitigation of information security risks, focusing on vulnerabilities, misconfigurations, patching gaps and exposure of IT assets.
  • Assist in Vendor and Third-Party Cybersecurity Management through assessments, audits, and periodic reviews, coordinating security assessments and remediation activities to closure.
  • Support the development, implementation, and revision of Global Technologies Information Security policies, controls, and metrics to ensure compliance with CRIF Corporate Policies.
  • Coordinate with Global Technologies functions to ensure security requirements and controls align with technical needs.
  • Work closely with Cybersecurity teams worldwide to build and maintain a unified cybersecurity strategy aligned with global business needs and regulatory requirements.
  • Provide expert input to Global Technologies IT Governance functions to embed security requirements into core IT processes.
  • Maintain proactive engagement with business and staff functions to provide cybersecurity guidance in key initiatives.
  • Support customer relationships, facilitating audits and responding to client cybersecurity requests and questionnaires.
  • Support Internal Audit activities, coordinating cybersecurity remediation actions and monitoring control effectiveness.

Conoscenze

Information security governance
Risk management
Regulatory awareness
Communication
Vendor management

Formazione

Bachelor's degree in a relevant field

Strumenti

NIST framework
ISO standards
GDPR

Descrizione del lavoro

CRIF is seeking an Information Security Governance Analyst to strengthen technology-driven cyber risk management and governance across the organization. You will collaborate with CIO, IT Cybersecurity and global teams to identify, assess and mitigate information security risks within infrastructure, applications and services.

The role emphasizes governance, policy development, audits, and alignment with regulatory standards.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

InfoSec Governance Specialist
InfoSec Governance Specialist

CRIF • Bologna

In loco
EUR 34.000 - 42.000
Information Security Governance Analyst
Information Security Governance Analyst

Crif • Emilia-Romagna

In loco
EUR 34.000 - 42.000
Information Security Governance Analyst
Information Security Governance Analyst

CRIF • Bologna

In loco
EUR 34.000 - 42.000
Cybersecurity GRC Strategist: Governance & Risk
Cybersecurity GRC Strategist: Governance & Risk

BIP • Palermo

Ibrido
EUR 28.000 - 34.000
Crescita e Formazione
Flessibilità e Work-Life Integration
Salute & Benefits
+2
Security Governance Analyst in Milan — Risk & Compliance
Security Governance Analyst in Milan — Risk & Compliance

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
Permanent contract
CCNL Metalmeccanico
Senior Cyber GRC & BCM Analyst
Senior Cyber GRC & BCM Analyst

Arup • Milano

In loco
EUR 85.000 - 115.000
Profit sharing
Competitive benefits package
Global profit share scheme
ICT & Cyber Risk Leader: Flexible Hours & Growth
ICT & Cyber Risk Leader: Flexible Hours & Growth

Generali • Mogliano Veneto

In loco
EUR 55.000 - 65.000
Smart working
Corporate welfare
Health insurance
ICT Risk Analyst | Hybrid & Growth in FinTech
ICT Risk Analyst | Hybrid & Growth in FinTech

Capco • Milano

Ibrido
EUR 26.000 - 32.000
Comprehensive health benefit coverage
Meal Vouchers
Welfare allowance
+1
Remote Cyber Security Governance & Risk Specialist
Remote Cyber Security Governance & Risk Specialist

Helloprima • Milano

Ibrido
EUR 60.000 - 85.000
Remote work
Private healthcare
Gym discounts
+5
GRC Cybersecurity Analyst: ICT Risk, Controls & Remediation
GRC Cybersecurity Analyst: ICT Risk, Controls & Remediation

Linkedin • Lazio

In loco
EUR 55.000 - 75.000