Overview
In this role you strengthen the company’s cybersecurity posture by leading governance, risk, and compliance efforts with a focus on NIS2. You collaborate with IT, Legal, Compliance, and regional security teams to ensure regulatory alignment and a resilient security culture. You’ll drive security improvements across the organization, including third-party risk and incident management, while supporting audits and KPI reporting. This is a chance to shape security programs at a global logistics leader, with impact across global operations.
Retribuzione / Benefits
- safe and stable environment
- focus on well-being
- professional growth and development
- international opportunities
- supportive teamwork
- innovative culture and continuous improvement
Responsabilità
- Lead the implementation of NIS2 requirements including gap assessments, remediation plans, and ongoing compliance monitoring
- Establish and maintain information security governance, policies, and controls aligned with Global and EMEA standards
- Conduct security risk assessments, manage risk treatment plans, and monitor control effectiveness
- Coordinate security incident management and regulatory reporting with IT, Legal, Compliance, and cyber teams
- Support internal and external audits, regulatory inspections, and timely remediation of findings
- Drive third-party and supply chain security risk management including supplier due diligence
- Define, monitor, and report security KPIs and risk metrics to local leadership and EMEA Information Security
- Deliver security awareness initiatives and promote cybersecurity and compliance culture across the organization
Requisiti fondamentali
- Degree in Information Security, Computer Science, Engineering, Law/Compliance, or equivalent professional experience
- Proven experience in Information Security Governance, Risk & Compliance (GRC) or related security functions
- Experience implementing security frameworks and regulatory requirements (ideally NIS2, ISO 27001, NIST CSF, or CIS Controls)
- Strong knowledge of information security risk management, ISMS processes, and audit readiness
- Understanding of cybersecurity domains such as vulnerability management, IAM, SIEM, endpoint security, network security, backup and recovery, and encryption
- Excellent stakeholder management, communication, and project management skills
- Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are advantageous
- Fluent English and professional Italian
- Stakeholder management
- Clear communication
- Project management
- Vulnerability management
- IAM
- SIEM
Information Security Manager datore di lavoro: Kühne + Nagel
Kuehne+Nagel è un datore di lavoro eccezionale, offrendo un ambiente di lavoro stabile e orientato alle persone, con opportunità di crescita professionale e sviluppo internazionale. La nostra cultura aziendale promuove il benessere e l'equilibrio sul posto di lavoro, incoraggiando l'innovazione continua e il lavoro di squadra in un contesto logistico dinamico nella provincia di Pavia.