Vista previa de la oferta
ICT & Cyber Risk Manager
manager · Risk & Compliance
GOSP Enterprise Risk Management Team guarantees an integrated risk management system through the definition of the risk strategy including risk appetite, limits and risk mitigation and through the identification, monitoring and reporting of risk and a forward-looking approach on risks to which GOSP is exposed to in the performance of its activity.
GOSP Team strictly collaborates with the Group Risk Management function to support risk management across the whole Group.
Within this context, we are looking for an ICT & Cyber Risk Manager, a professional with strong ICT/Security background aimed at supporting the GOSP Enterprise Risk Management unit and the Group in its journey of increasing ICT/Cyber resilience posture.
The ideal candidate has strong governance skills and experience to support technical activities of the ICT & Cyber Risk Management function, aimed at achieving and maintaining a top-level ICT & Cyber resilience posture to support GOSP and the Group business strategy. The profile we are looking for has a broad knowledge of the most relevant and suitable regulations and market best practices related to ICT & Cyber security to support the definition of new risk assessment methodologies and frameworks, granting compliance with the current and future regulations and supporting ICT & Cyber resilience posture against evolving threats landscape. He/She has the capability to report to Senior Management technical topics to support risk-based decisions.
Job practice domains:
- Support the Head Enterprise Risk Management function in performing 2LoD activities to verify, challenge and support risk responses
- Coordinate activities of the Enterprise Risk Management function
- Foster ICT & Cyber resilience culture across the Group in coordination with BU/Local CRO Functions
- Strengthen the collaboration between Chief Security Officer and Chief Information Officer function to foster a common journey to improve Group’s resilience posture
- Reporting capabilities up to Board of Directors and other relevant committees
Key responsibilities of the role will include:
- Steer the definition of Group frameworks and best practices in terms of ICT & Cyber risk management
- Define Group Level regulations to fulfil Regulator’s requirements and to improve Group resilience posture
- Execute Risk Assessment on ICT and Cyber topics
- Assess, challenge and monitor Risk Mitigation Actions
- Assess and Report ICT & Cyber Risk Exposure
- Being always up to date to implement new internal/external regulations involving proper stakeholders
Our ideal candidate will meet the following requirements:
- Degree in technical subjects as Computer Engineering, Computer Science, Cyber Security, or equivalent
Knowledge of the following topics:
- Main Operative Systems and network protocols
- ICT and Network architecture
- Cyber Security Operations: IAM, VAPT, Vulnerability analysis and prioritization
- Knowledge of at least 2 of the following IT and Cyber Security frameworks:
- NIST CSF and SP800-53
- ISO 27000
- C2M2
- MITRE ATT&CK
- Cloud CCM
- Experience in at least two of the following areas:
- Sys/Network Admin
- Security operations
- Penetration tester
- Developer
- Cloud engineer
- AI technologies
- The achievement of one or more of the following professional certifications is a plus: CISA, CISM, CGEIT, CRISC, ISO27001 LA, COBIT 5 Foundation, CSX Fundamentals, CSX Practitioner, CCAK, ITIL v3 Foundation, CIA, CRMA
Soft Skills:
- Senior Stakeholders management
- Proactivity
- Problem Solving
- Teamwork
- Fluency in English
What we offer:
We offer employment at the manager level with the relevant salary, in accordance with the CCNL ANIA for non-executive employees and the Generali Group Company Agreement.
Gross annual salary ranging between 55K€ and 65K€. The final offer will be aligned with the candidate’s professional experience, technical and soft skills relevant to the role, and may include an individual variable component.
We also offer:
- Smart working and flexible hours
- Corporate welfare system
- Meal vouchers
- Supplementary health insurance and discounted insurance policies
- Well-being initiatives
- Training and development
- Structured continuous learning paths (technical and managerial)
- Career development programs within the Group
- Access to learning platforms and internal mobility opportunities, including international