JobConnect

Security Threat Assessment Consultant

Information Security Professional – External Consultant

Location: San Donato Milanese, Italy
Working Arrangement: Temporary External Consultancy
On-site Requirement: Minimum 3 days per month

About the Role

Our Client is seeking an experienced Information Security Professional to strengthen the protection of its information systems and data against cybersecurity threats.

Working closely with the Client’s wider Cybersecurity team, the successful candidate will be responsible for identifying, assessing, monitoring, and reporting cybersecurity risks across the organization. This is an external consulting opportunity on a temporary, part-time basis, offering the opportunity to contribute to cybersecurity governance, risk management, compliance, and continuous improvement initiatives.

Key Responsibilities

Cybersecurity Risk Management

  • Conduct cybersecurity risk assessments across the organization.
  • Analyse threats, vulnerabilities, and control effectiveness to determine residual risk.
  • Maintain and regularly update cybersecurity risk registers.
  • Track risk mitigation and remediation activities through to closure.
  • Recommend improvements to the efficiency, consistency, and effectiveness of Information Security operations in collaboration with the wider Cybersecurity team.

Governance & Oversight

  • Develop and maintain cybersecurity policies, standards, and control requirements.
  • Monitor adherence to established cybersecurity requirements.
  • Review and challenge the completeness and accuracy of risk assessments and mitigation plans.
  • Support exception management and risk acceptance reviews.
  • Contribute to cybersecurity governance forums and reporting activities.

Compliance & Audit Support

  • Support internal and external cybersecurity audits.
  • Coordinate evidence collection and remediation tracking.
  • Assess compliance with the Client’s cybersecurity standards and applicable regulatory requirements, including NIS2.
  • Support cybersecurity control assessments and gap analyses.
  • Help identify areas requiring improvement to strengthen overall compliance and security maturity.

Risk Reporting & Metrics

  • Develop cybersecurity risk metrics, dashboards, and management reports.
  • Prepare materials for management and governance reviews.
  • Identify and escalate significant cybersecurity risk exposures and emerging trends.
  • Support broader cybersecurity reporting activities.

Stakeholder Engagement

  • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business stakeholders.
  • Provide guidance on cybersecurity risk management processes, controls, and requirements.
  • Promote cybersecurity awareness and risk-informed decision-making across the organization.
  • Build effective relationships with both technical and non-technical stakeholders.

Candidate Profile

The ideal candidate will have:

  • Proven professional experience in Information Security, Cybersecurity, Security Governance, Risk Management, or a related field.
  • Strong knowledge of Information Security governance, cybersecurity risk management, and incident response.
  • Practical experience conducting security risk assessments and managing risk registers and remediation activities.
  • Good understanding of cybersecurity frameworks and regulatory requirements, such as NIST, ISO 27001, NIS2, and GDPR.
  • Experience supporting cybersecurity audits, compliance assessments, and control gap analyses.
  • Strong analytical, organizational, and reporting skills.
  • The ability to communicate complex cybersecurity risks clearly to both technical and business stakeholders.
  • A proactive and structured approach, with the ability to work independently as an external consultant.
  • Fluency in both Italian and English.
  • Relevant professional certification such as CISSP, CISM, or equivalent is desirable.

Working Conditions

  • On-site presence required at the Client’s premises in San Donato Milanese at least 3 times per month.

Apply

If you are an experienced Information Security professional with strong expertise in cybersecurity risk, governance, and compliance, and are interested in a flexible consulting assignment within an international environment, we would be pleased to hear from you.

Skills

  • Risk assessment
  • Cybersecurity Governance
  • NIST CSF
  • ISO 27001
  • Vulnerability Management
  • Security Controls
  • Risk Register Management

Related jobs

Infotree Global SolutionsApply for this job