EU remote
Cybersecurity Governance, Risk & Compliance (GRC) Consultant
About this role
This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response . What You’ll Do: Conduct cybersecurity risk assessments for COET srl. Analyze threats, vulnerabilities, control effectiveness, and residual risks. Maintain and update cybersecurity risk registers. Track risk mitigation and remediation activities through completion.
Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations. Develop and monitor cybersecurity policies, standards, and control requirements. Review risk assessments, mitigation plans, exceptions, and risk acceptance requests. Support cybersecurity governance forums and reporting activities. Assist with internal and external cybersecurity audits. Coordinate evidence collection and remediation tracking.
Assess compliance with Hitachi Energy cybersecurity standards and applicable country regulations, including NIS2. Support control assessments and gap analyses. Develop risk metrics, dashboards, and management reports. Prepare materials for management and governance reviews. Escalate significant cybersecurity risks and emerging trends. Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
Provide guidance on cybersecurity risk management processes and requirements. Promote cybersecurity awareness and risk-informed decision-making. Qualifications Nice to Haves: Experience in Information Security governance, risk management, compliance, and incident response. Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR. CISSP, CISM, or an equivalent certification is desirable.
Fluency in both Italian and English. Strong communication and stakeholder management skills. Ability to work independently and collaborate with cybersecurity and business teams. Deliverables Cybersecurity risk assessments and updated risk registers. Risk mitigation and remediation tracking. Cybersecurity policies, standards, and control requirements. Audit evidence, control assessments, and gap analysis support. Risk metrics, dashboards, and management reports.