Security Governance Analyst, Italy
Job Summary
About us:
We are a community of visionary innovators dedicated to providing pioneering software and consultancy services to financial institutions trading firms central banks governments and corporations around the world. We strive to simplify the way people work. We do that by providing workflow and process automation software as well as providing real-time data and business intelligence to help people make better decisions. We are 13000 employees we operate globally with 80 global offices and we serve over 4800 customers worldwide.
For the strengthening of the Chief Information Security Office (CISO) function within Cedacri companies part of ION Group we are looking for talented professionals to grow their career as Security Governance Analyst. This position is targeted at candidates with 25 years of relevant experience in Information Security Governance Cybersecurity Risk Management or ICT Compliance. Selected candidates will be placed in a dynamic and innovative environment and will collaborate with cross-functional teams to support cybersecurity governance initiatives across the organization.
Learn more at .
Your role
Your key duties and responsibilities
- Support the implementation and continuous improvement of the Information Security Governance framework
- Support the implementation maintenance and continuous improvement of the Information Security Governance framework across the organization.
- Develop maintain and review cybersecurity policies standards procedures and governance documentation.
- Support cybersecurity risk management activities including risk assessments remediation tracking exception management and risk treatment planning.
- Monitor the effectiveness and maturity of security controls and ensure governance activities remain aligned with organizational objectives and regulatory requirements.
- Maintain governance evidence action plans ownership records dependencies and remediation initiatives to support audit readiness and effective reporting.
- Prepare KPI/KRI dashboards for management on coverage timeliness and effectiveness of controls including asset/API inventories SBOM/SCA coverage patching performance exception aging and action-plan closure.
- Collaborate with Technology Risk Compliance Legal and Business stakeholders to ensure alignment with security governance requirements.
- Support internal audits external audits regulatory assessments and client due diligence activities.
- Contribute to the implementation of regulatory and industry frameworks including DORA NIS2 ISO 27001 NIST CSF and related standards.
- Support governance transformation initiatives and continuous improvement programs aimed at strengthening cybersecurity oversight capabilities.
Other duties
We might ask you to perform other tasks and duties as your role expands.
Your skills experience and qualifications required
- Masters degree in Cybersecurity Computer Science Computer Engineering Information Technology Law Management Engineering or a related field (with honors).
- At least 2-5 years of experience in Information Security Governance ICT Risk Management Cybersecurity Compliance Internal Audit or related functions.
- Good understanding of cybersecurity governance principles governance requirements for vulnerability management patch management incident response secure SDLC third-party risk and operational resilience.
- Knowledge of international standards and frameworks such as ISO 27001 NIST CSF COBIT CIS Controls DORA and NIS2.
- Experience supporting audit activities compliance assessments regulatory initiatives or governance reporting processes.
- Ability to translate complex technical topics into clear governance risk and management reporting outputs.
- Strong analytical organizational and stakeholder management skills.
- Advanced knowledge of Microsoft Excel and PowerPoint.
- Excellent knowledge of Italian and English.
- Professional certifications such as ISO 27001 CISA CRISC Security or equivalent would be considered a plus.
What we offer:
- Permanent employment contract
- Italian National Collective Labour Agreement for the Metalworking Industry (CCNL Metalmeccanico)
- Gross Annual Salary (RAL) ranging from 40000 to 50000 depending on experience skills and qualifications
- Job grade to be determined upon completion of the selection process with final assessment between B2 and B3 level
- Opportunity to join a leading international technology group operating in the financial services industry
- Exposure to enterprise-wide cybersecurity governance activities in a dynamic and international environment
Location:
Milan.
Important notes:
According to the Italian Law (L.68/99) candidates belonging to the protected categories list will be given priority.
Required Experience:
IC
About Company
ION financial software improves decision making, simplifies complicated processes and empowers you by providing the right tools.