Lifted (an Upwork Company)

Cybersecurity Governance, Risk & Compliance (GRC) Consultant

San Donato Milanese, Lombardy, it · Posted 1h ago

salary not listedDept: Other

Job Description

This opportunity is ideal for an experienced Information Security professional with knowledge of cybersecurity governance, risk management, compliance, and incident response.

What You’ll Do:

  • Conduct cybersecurity risk assessments for COET srl.
  • Analyze threats, vulnerabilities, control effectiveness, and residual risks.
  • Maintain and update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through completion.
  • Recommend ways to improve the efficiency, consistency, and effectiveness of Information Security operations.
  • Develop and monitor cybersecurity policies, standards, and control requirements.
  • Review risk assessments, mitigation plans, exceptions, and risk acceptance requests.
  • Support cybersecurity governance forums and reporting activities.
  • Assist with internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with company's Energy cybersecurity standards and applicable country regulations, including NIS2.
  • Support control assessments and gap analyses.
  • Develop risk metrics, dashboards, and management reports.
  • Prepare materials for management and governance reviews.
  • Escalate significant cybersecurity risks and emerging trends.
  • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
  • Provide guidance on cybersecurity risk management processes and requirements.
  • Promote cybersecurity awareness and risk-informed decision-making.
  • Experience in Information Security governance, risk management, compliance, and incident response.
  • Knowledge of common cybersecurity frameworks and regulations, such as NIST, NIS2, ISO 27001, and GDPR.
  • CISSP, CISM, or an equivalent certification is desirable.
  • Fluency in both Italian and English.
  • Strong communication and stakeholder management skills.
  • Ability to work independently and collaborate with cybersecurity and business teams.

Deliverables

  • Cybersecurity risk assessments and updated risk registers.
  • Risk mitigation and remediation tracking.
  • Cybersecurity policies, standards, and control requirements.
  • Audit evidence, control assessments, and gap analysis support.
  • Risk metrics, dashboards, and management reports.
  • Governance review materials and cybersecurity reporting.

Location Requirement

  • On-site presence at COET premises in San Donato Milanese, Italy, at least 3 times per month.
  • Category: Information Security & Compliance
  • Engagement Type: Independent Contractor
  • Duration: September 14, 2026 to September 14, 2027
  • Country: Italy
  • Engagement: Temporary, part-time consulting opportunity
  • The client is still evaluating the appropriate engagement structure. The selected talent may ultimately be engaged through an Employer of Record (EOR) arrangement rather than as an Independent Contractor.
  • Candidates should be comfortable proceeding under either engagement structure. If EOR is selected, additional onboarding requirements and timelines may apply before the engagement begins.