About this role
About the Role The role sits within the Cybersecurity Verifications & Certifications structure and is part of the Operational Risk Management & Remediations team. You will support ICT risk and security governance by coordinating self-diagnosis, reporting, and guiding owners in methodologies and tools; you will analyze information sources to identify issues, contribute to remediation plans and monitor them, curate metrics and reporting, and promote risk culture within your scope. What You'll Do
- Coordinate the ICT Operational Risk and Security self-diagnosis process and related risk exposure reporting, involving Process Owner/Control Owner and supporting adoption of methodologies and tools per Risk function rules
- Analyze corporate information sources to identify issues exposing the Cybersecurity & Business Continuity structure to risk; contribute to defining the remediation plan and its monitoring
- Collect operational events and potential loss data, and derive metrics for monitoring the Risk Appetite Framework (RAF)
- Prepare appropriate managerial reporting
- Monitor compliance with Legislative Decree 231/2001 within Cybersecurity & Business Continuity scope, contributing to remediation plan and its monitoring
- Support second-line controls activities conducted by Risk Management
- Contribute to reporting of cyber and continuity risk exposure to the Supervisory Authority
- Promote the culture of operational risk within your area What We're Looking For
- 5-10 years of experience in Cybersecurity and/or Business Continuity
- Degree in Computer Science/Scientific field
- Experience in governance of ICT operational risk and security
- Knowledge of frameworks (NIST Cybersecurity Framework, COBIT 2019, ISO 27001, ISO 22301) and cybersecurity and business continuity regulations (e.g., L.133 on cyber perimeter, Circolare 285, NIS Directive, PSD2, DORA, Basel III)
- Good command of English
- Proficiency with Office Suite (Word, PowerPoint, Excel)
- Certifications considered a plus: CISM, CISSP, ISO 27001, ISO 22301, CSX Fundamentals, NIST, COBIT Nice to Have
- The following certifications and mappings are preferred: CISM, CISSP, ISO 27001, ISO 22301, CSX Fundamentals, NIST, COBIT Compensation & Benefits
- Annual gross salary starting from €50,000 with a variable remuneration component tied to performance