RINA is currently recruiting for a Cybersecurity GRC Consultant to join its office in GENOA, ROME OR MILAN within the Cyber Security and Management Consulting Division.
Mission
RINA is currently recruiting for a Cyber Security GRC consultant to join our Cyber Team in GENOA, ROME or MILAN
Key Accountabilities
The persons will be in charge of:
1. Carry out technical activities such as:
2. Identify security risks within organizations and complex systems/architectures.
3. Design security measures and provide recommendations or suggestions to improve security postures.
4. Verify compliance versus laws, regulations and standards pertaining security and cybersecurity.
5. Provide support to Customers in cybersecurity related activities.
6. Draft technical/procedural documents related to:
7. IT Security Governance, Risk and Compliance aspects (wrt ISO/IEC 27001:2022, NIS/NIS2 directives, PSNC, etc.)
8. INFOSEC aspects (wrt National Scheme for IT products security evaluation, Common Criteria/ISO 15408, ENISA EUCC)
9. Cybersecurity in Industrial Automation Control Systems (wrt IEC 62443 requirements families for risk assessment, systems and components)
10. Marine cybersecurity requirements from International Association of Classification Societies (wrt IACS Unified Requirements, IMO circulars, Flag Administrations requests, etc.)
11. Maintain and update the RINA cybersecurity guidelines and assessment methodologies.
12. Support the business development from a technical point of view, drafting technical offers and detailing services (for senior personnel).
#LI-MM2
Education
Bachelor’s Degree in Engineering General
Qualifications
Requirements:
13. Knowledge of laws, regulations, international standards and best practices (e.g. ISO/IEC 27001 and 27000 family, NIST Cybersecurity Framework and National Framework for Cyber Security and Data Protection, NIS/NIS2 Directives, ISA/IEC 62443, Common Criteria/ISO15408, ISO21434, etc.).
14. Engineering academic background.
15. Strong problem-solving ability.
16. Excellent verbal and written communication skills - Italian and English as a minimum.
17. Flexibility and ability to multi-task in a fast-paced atmosphere.
18. Availability to travel within the Country and abroad.
Desired Requirements:
19. Experience with a wide range of computer systems and security tools.
20. Security Certifications: e.g. ISO/IEC 27001 Qualified Lead Auditor, GIAC/GICSP or ISA/IEC 62443 related certifications, CEH, OSCP, ISACA CISM/CISA/CRISC, ISC2 CISSP.
21. Adequate knowledge of programming languages (Java, C/C++/C#, VB.Net, Python), their interfaces with principal DBMS, and their development environments.
22. Adequate knowledge of networking (in terms of segmentation, used protocols, security, etc.). Past experiences in network administration/configuration will be appreciated.
Competencies
23. ADDRESS THE WAY - Have a big picture of different situations and reinterpret it in a perspective way
24. BUILD NETWORK - Forge trust relationships, across departments, and outside the organization
25. CLIENT INTIMACY - Embrace internal and external client needs, expectations, and requirements to ensure maximum satisfaction
26. EARN TRUST - Take everyone's opinion into account and remain open to diversity
27. MAKE EFFECTIVE DECISIONS - Structure activities according to priorities, actions, resources and constraint
28. MANAGE EMOTIONS - Recognise one's