Talent.com
Ariston Group
Ict Governance & RiskAriston Group • milan, Lombardy, Italy
Ict Governance & Risk

Ict Governance & Risk

Ariston Group • milan, Lombardy, Italy
11 giorni fa
Descrizione dell’offerta di lavoro

Ariston Group is a global leader in sustainable climate and water comfort listed on Euronext 2025 the group reported 2.7 billion-euro revenues with almost 11000 employees direct presence in 41 countries in 5 continents 32 production sites and 31 research and development centers. The group demonstrates its commitment to sustainability through renewable and high-efficiency solutions including heating heat pumps water heating heat pumps hybrids domestic ventilation air handling electric components and solar thermal systems while continuously investing in technological innovation digitalization and advanced connectivity solutions. The group operates under global strategic brands Ariston Wolf and Elco and brands such as Calorex NTI Atag Domotec Brink Chromagen Racold as well as Thermowatt and Ecoflam in the components and combustion technologies business.

ICT Governance & Risk

Department: ICT Security

Reports to: Governance Risk and Compliance

Location: Fabriano or Milan / Hybrid

About the Role

We are looking for a a professional to support Group-level ICT Security governance ITGC compliance IT risk management and SAP/ERP access governance.

The role focuses on ensuring effective control execution supporting audit activities coordinating evidence collection and monitoring remediation plans with relevant control owners.

It also includes the management of Identity Access Management processes for SAP and ERP environments with a focus on authorization procedures Segregation of Duties periodic access reviews ticket management and escalation of access-related risks.

Key Responsibilities

  • Support IT General Control compliance & IT Controls according to best practice by verifying control implementation and effectiveness across relevant ICT processes and systems.
  • Support external and internal audit activities by coordinating evidence control owners findings and remediation actions.
  • Conduct an initial comprehensive IT risk assessment and maintain the Group ICT risk register.
  • Monitor remediation plans follow up with action owners track deadlines and escalate delays or risks where appropriate.
  • Manage SAP and ERP Identity Access Management processes including access requests role assignments and authorization changes.
  • Support Segregation of Duties governance including conflict analysis mitigating controls exception management and remediation follow-up.
  • Coordinate periodic access review campaigns ensuring completion evidence collection and follow-up on revoked or modified accesses.
  • Manage access-related tickets and privilege-change requests verifying approvals and alignment with applicable procedures.
  • Monitor anomalous accounts privileged users and access exceptions escalating relevant risks to IT Security for assessment and follow-up.
  • Maintain documentation related to ITGC controls SAP/ERP access procedures audit evidence remediation plans and governance processes.
  • Prepare and present periodic activity risk control and remediation status updates to IT leaders highlighting key achievements open issues priorities and required decisions

Required Qualifications

  • 4-5 years of experience in ICT Governance Risk & Compliance IT General Controls (ITGC) IT Audit IT Risk Management Identity Governance or similar roles.
  • Solid understanding of IT General Controls control testing audit evidence management remediation tracking and risk assessment methodologies.
  • Experience with SAP/ERP access management authorization processes role-based access controls (RBAC) user access reviews Segregation of Duties (SoD) and related governance activities.
  • Familiarity with Identity and Access Management (IAM) lifecycle processes including provisioning privilege changes revocations access reviews exception management and access request workflows; knowledge of SAP GRC SAP authorization analysis tools user revalidation platforms or similar IAM solutions is considered an advantage.
  • Good knowledge of IT governance risk management and cybersecurity frameworks such as ISO 27001 COBIT NIS2 GDPR-related IT controls or equivalent standards.
  • Experience operating in complex ERP environments multi-country organizations or multi-entity ICT landscapes is a plus.
  • Proven ability to coordinate activities with control owners application owners auditors IT Security teams and external service providers ensuring effective execution of controls and remediation plans.
  • Strong analytical skills to identify assess and prioritize IT risks evaluate business impacts and provide practical risk-based recommendations.
  • Experience preparing audit reports control evidence packages remediation status reports dashboards and management updates for internal and external stakeholders is considered a plus.
  • Excellent organizational skills accuracy attention to detail accountability and a proactive approach to managing follow-up activities across multiple stakeholders.
  • Good command of written and spoken English with the ability to create clear documentation status updates and professional communications.

Equal opportunity pay transparency & fairness

The compensation package will be determined based on the candidates experience skills and the scope of the role applying objective and gender-neutral criteria. We believe that transparency and fairness are essential to building trust fostering inclusion and ensuring equal opportunities for everyone. As a reference for such position we offer a salary ranging starting from 40.000 . This position is covered by the CCNL Metalmeccanici Industria.

We are committed to the principle of equal employment opportunity for all people. We strive to provide a work environment that is accessible welcoming and inclusive in full compliance with applicable legal line with this commitment we promote fair transparent and equitable reward practices. The compensation package will be determined based on the experience skills and the scope of the role applying objective and genderneutral criteria. We believe that transparency and fairness are essential to building trust fostering inclusion and ensuring equal opportunities for everyone.


Employment Type : Full Time
Experience: years
Vacancy: 1

Creare un avviso di lavoro per questa ricerca

Ict Governance & Risk • milan, Lombardy, Italy

Offerte simili

Ict Risk Manager...

Generali ItaliaMilano - Italy, IT

Questa posizione è in Generali Italia Riassunto dell'opportunità da parte della Joinrs AI: Generali Italia cerca un ICT Risk Manager esperto con almeno 5 anni di esperienza in information security... Mostra di più

 • In evidenza

Compliance, Governance & Risk Manager

Edenred Italia S.r.l.Milano, lombardia, Italy

Compliance, Governance & Risk ManagerApplylocations: Italy - Milanotime type: Full timeposted on: Posted Todaytime left to apply: End Date: October 12, 2026 (30+ days left to apply)job requ... Mostra di più

 • In evidenza

Senior Compliance, Governance & Risk Leader (Hybrid)

Edenred Italia S.r.l.milano, lombardia, Italy

Compliance, Governance Risk Manager da inserire a Milano.Il candidato ideale avrà responsabilità strategiche nel garantire l'efficacia del framework di compliance e gestione dei rischi, fornendo s... Mostra di più

 • In evidenza

Strategic Compliance, Governance & Risk Lead

Ticket Servicos SAMilano, lombardia, Italy

A Ticket Servicos SA em Milão está à procura de um Compliance, Governance & Risk Manager para liderar o framework de compliance e risco.O profissional atuará como referência para a gestão de riscos... Mostra di più

 • In evidenza

Associate - Risk & Resilience

Banca Sella SpaMilano, IT

OverviewEntrerai nella Direzione Risk Management di Intesa Sanpaolo Assicurazioni, all'interno dell'ufficio Enterprise Risk, dove ti occuperai di identificazione, valutazione, monitoraggio ... Mostra di più

 • In evidenza

BNL – Inspection Générale – IT Senior Auditor Milano...

BNP ParibasMilano - Italy, IT

Questa posizione è in BNP Paribas Riassunto dell'opportunità da parte della Joinrs AI: BNP Paribas cerca un **Senior Auditor con competenze IT e preferibilmente esperienza in Cybersecurity** e g... Mostra di più

 • In evidenza

ICT & Cyber Risk Management Specialist appartenente alle categorie protette (art.1 - L.68/99)

ManpowerGroupMilano, Lombardia

La Divisione Beyond di Manpower, specializzata nella ricerca e selezione di profili appartenenti alle Categorie Protette, per importante azienda cliente operante in ambito insurance e servizi digit... Mostra di più

 • In evidenza

AI Governance Specialist...

Bip ItaliaMilano - Italy, IT

Questa posizione è in Bip Italia Riassunto dell'opportunità da parte della Joinrs AI: Bip Italia cerca un AI Governance Specialist con laurea magistrale in Giurisprudenza, Economia, Business Adm... Mostra di più

 • In evidenza

Hybrid Cyber Strategy & Risk Governance Manager

Ernst & Young Advisory Services Sdn BhdMilano, lombardia, Italy

EY Milano cerca un Manager, Cyber Strategy & Governance per supportare i clienti nell’IT risk management e nella definizione di governance e compliance.Farai parte di un team multidisciplinare in r... Mostra di più

 • In evidenza

Senior Associate, Banking Risk Advisory & Governance

CervedMilano, lombardia, Italy

Cerved, la tech company italiana, ricerca un Senior Associate per la Practice Banking (Risk Advisory) di MBS Consulting, la società italiana di Management Consulting che opera per grandi clienti na... Mostra di più

 • In evidenza

SOC Strategy & Vendor Governance Lead (Hybrid)

MatchtechMilano, lombardia, Italy

Matchtech is seeking a skilled cybersecurity professional in Bollate (Milano) for a permanent position.This role focuses on leading Security Operations Center (SOC) functions and ensuring high-qual... Mostra di più

 • In evidenza

Senior Compliance, Governance & Risk Leader

Edenred Finland Oy.Milano, lombardia, Italy

Compliance, Governance & Risk Manager per guidare il framework di compliance e gestione dei rischi.Il candidato ideale avrà una laurea in Giurisprudenza e una solida esperienza in contesti compless... Mostra di più

 • In evidenza

Lead Auditor ICT Sector

DNVMilano, lombardia, Italy

We are the independent expert in assurance and risk management.Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts an... Mostra di più

 • In evidenza

BNL – Area IT – ITDME Governance – Governance Officer...

BNP ParibasRome - Italy, Milan - Italy, IT

Questa posizione è in BNP Paribas Riassunto dell'opportunità da parte della Joinrs AI: BNP Paribas cerca un/a **Governance Officer** con **laurea in discipline STEM o affini** per il team IT Are... Mostra di più

 • In evidenza

Security Governance, Risk & Compliance Consultant

AvanadeMilano, lombardia, Italy

Parteciperai e/o condurrai workshop con stakeholder di business e IT (HR, IT, Security, Application Owners).Security Governance, Risk & Compliance.Per la Practice Security di Avanade, cerchiamo pro... Mostra di più

 • In evidenza

Compliance, Governance & Risk Manager

Ticket Servicos SAMilano, lombardia, Italy

Compliance, Governance & Risk ManagerIr para o conteúdo principal# OportunidadesCompliance, Governance & Risk Manager page is loaded## Compliance, Governance & Risk ManagerCandidatar-selocations: ... Mostra di più

 • In evidenza

Investment Governance Specialist - Internship...

Generali ItaliaMilan, IT

Questa posizione è in Generali Italia Riassunto dell'opportunità da parte della Joinrs AI: Generali Italia cerca un intern con laurea in Business, Finance, Risk Management o discipline correlate, ... Mostra di più

 • In evidenza

Strategic Cyber Risk & Governance Leader

EYMilano, lombardia, Italy

EY Milano cerca un Manager per Cyber Strategy & Governance nel Technology Risk & Assurance.Entrerai nel team Cyber Strategy, Risk & Governance per definire modelli di governance, risk management e ... Mostra di più

 • In evidenza

ICT Service Manager - Appartenente alle categorie protette L.68/99

ManpowerGroupMilano, Lombardia

Manpower Beyond  - divisione categorie protette - in collaborazione con un primario gruppo industriale multinazionale operante nel settore manifatturiero e della tecnologia per beni durevoli, ricon... Mostra di più

 • In evidenza

Cybersecurity - Governance & Resilience - Associate - Milano [OTS]...

PwCMilano - Italy, IT

Questa posizione è in PwC Riassunto dell'opportunità da parte della Joinrs AI: PwC cerca un Cybersecurity & Resilience professional con 2-3 anni di esperienza e una laurea in ingegneria o sicurezz... Mostra di più