Cybersecurity Governance, Risk & Compliance (GRC) Consultant

Posted 4 Hours Ago
Be an Early Applicant
San Donato Milanese, Milano, ITA
Hybrid
Entry level
Enterprise Web • HR Tech • Professional Services • Software
The Role
Conduct cybersecurity risk assessments, maintain risk registers, track remediation, develop policies and controls, support audits and gap analyses, monitor compliance with NIST, NIS2, ISO 27001, GDPR, and prepare risk metrics and governance reports. The consultant will collaborate with cybersecurity, IT, legal, procurement, privacy, and business teams, working part-time with on-site presence in San Donato Milanese at least three times monthly.
Summary Generated by Built In
Company Description

An enterprise technology client is seeking an experienced Information Security Professional to support the protection of COET srl’s information systems and data from cybersecurity threats.

The selected consultant will work closely with the Hitachi Energy Cybersecurity team to identify, assess, monitor, and report cybersecurity risks across the COET organization.

This is a temporary, part-time consulting opportunity based in Italy

    Job Description

    This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response.

    What You’ll Do:

    • Conduct cybersecurity risk assessments for COET srl.
    • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
    • Maintain and update cybersecurity risk registers.
    • Track risk mitigation and remediation activities through completion.
    • Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
    • Develop and monitor cybersecurity policies, standards, and control requirements.
    • Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
    • Support cybersecurity governance forums and reporting activities.
    • Assist with internal and external cybersecurity audits.
    • Coordinate evidence collection and remediation tracking.
    • Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2.
    • Support control assessments and gap analyses.
    • Develop risk metrics, dashboards, and management reports.
    • Prepare materials for management and governance reviews.
    • Escalate significant cybersecurity risks and emerging trends.
    • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
    • Provide guidance on cybersecurity risk management processes and requirements.
    • Promote cybersecurity awareness and risk-informed decision-making.

    Qualifications

    • Experience in Information Security governance, risk management, compliance, and incident response.
    • Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.
    • CISSP, CISM, or an equivalent certification is desirable.
    • Fluency in both Italian and English.
    • Strong communication and stakeholder management skills.
    • Ability to work independently and collaborate with cybersecurity and business teams.

    Deliverables

    • Cybersecurity risk assessments and updated risk registers.
    • Risk mitigation and remediation tracking.
    • Cybersecurity policies, standards, and control requirements.
    • Audit evidence, control assessments, and gap analysis support.
    • Risk metrics, dashboards, and management reports.
    • Governance review materials and cybersecurity reporting.

    Location Requirement

    • On-site presence at COET premises in San Donato Milanese, Italy, at least 3 times per month.

    Additional Information

    • Category: Information Security & Compliance
    • Engagement Type: Independent Contractor
    • Duration: September 14, 2026 to September 14, 2027
    • Country: Italy
    • Engagement: Temporary, part-time consulting opportunity
    • The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
    • Candidates should be comfortable proceeding under either engagement structure. If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.

    Skills Required

    • Experience in information security governance, risk management, compliance, and incident response
    • Knowledge of cybersecurity frameworks and regulations, including NIST, NIS2, ISO 27001, and GDPR
    • Fluency in Italian and English
    • Strong communication and stakeholder management skills
    • Ability to work independently and collaborate with cybersecurity and business teams
    • CISSP, CISM, or equivalent certification
    • On-site presence at COET premises in San Donato Milanese, Italy, at least three times per month
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    283 Employees
    Year Founded: 2025

    What We Do

    Lifted, an Upwork Company, is a B2B SaaS platform that helps enterprise organizations source, contract, manage, and pay contingent talent globally and compliantly. It supports multiple engagement models, including independent contractors, staff augmentation, and employer-of-record, while integrating with MSPs and VMSs to provide centralized visibility, spend control, and audit-ready compliance, delivering a white-labeled talent experience for hiring managers and contingent workforce programs.

    Similar Jobs

    Pfizer Logo Pfizer

    Sustainability Senior Manager

    Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
    Remote or Hybrid
    30 Locations
    121990 Employees
    112K-207K Annually

    SRAM, LLC Logo SRAM, LLC

    Technical Support

    Fitness • Hardware • Mobile • Software • Sports • Transportation • Esports
    In-Office
    Varese, ITA
    3800 Employees

    InterSystems Logo InterSystems

    Application Analyst

    Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Database • Analytics
    Easy Apply
    In-Office
    Milano, ITA
    2100 Employees
    40K-49K Annually

    Pfizer Logo Pfizer

    Sr. Director, Product Intelligence & Marketing Lead

    Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
    In-Office or Remote
    30 Locations
    121990 Employees
    215K-358K Annually

    Similar Companies Hiring

    Onshore Thumbnail
    Artificial Intelligence • Fintech • Software • Financial Services
    New York, New York
    60 Employees
    Revel Thumbnail
    Aerospace • Hardware • Robotics • Software
    Marina Del Rey, California
    60 Employees
    Blee Thumbnail
    Artificial Intelligence • Marketing Tech • Software
    New York, New York
    30 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account