For a first-class company, we are looking for a Security GRC Officer:
Requirements / Skills
The SGRC Officer is part of the team responsible for delivering governance, risk management, and compliance elements of the information security strategy. This includes creating information security policies, managing information security risks, providing training, and reviewing information security procedures.
Typical Duties and Responsibilities
Implement security controls, risk assessment frameworks, and programs that align with regulatory requirements, ensuring documented and sustainable compliance that supports the company's business objectives.
The Security GRC Officer will develop, implement, and maintain security governance, risk management, and compliance strategies to protect the organization's information assets. This role requires expertise in regulatory frameworks, risk assessments, and policy enforcement to ensure compliance with industry standards and cybersecurity best practices.
Key Responsibilities :
This position is typically office-based with options for remote work (homeworking). It may require on-call availability for incident response.
Qualifications & Experience :
Bachelor's or Master's degree in Cybersecurity, Information Security, Risk Management, or a related field.
Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor / Implementer are highly preferred.
Strong knowledge of regulatory requirements, risk frameworks, and control methodologies.
Experience with third-party/vendor risk assessments and audit processes.
Excellent analytical, communication, and problem-solving skills.
Languages : Italian, English (German is a plus).