HSEQ and Sustainability - Saipem S.p.A

IT System Architect - Cybersecurity Third-Party Risk Management Specialist

Join Saipem and engineer a sustainable future.

We are a global leader in engineering and construction for the energy and infrastructure sectors, delivering complex onshore and offshore projects worldwide. Driven by technological innovation as “One Company”, our 30,000 people from over 130 nationalities in more than 50 countries work every day to enable the energy transition toward Net Zero. At Saipem, we embrace diversity as a driver of innovation and inclusion, while prioritizing people’s safety and environmental sustainability, even in the most challenging conditions.

Purpose of the position: As Cybersecurity Third-Party Risk Management Specialist you will be part of the Cyber Security Governance Department.

How can you support us? Here below your responsibilities:

  • Perform cybersecurity risk assessments of third-party engagements, evaluating suppliers’ cybersecurity posture through the review of questionnaires, security documentation, governance arrangements, certifications and supporting evidence.
  • Assess cybersecurity risks, gaps, non-compliance, exception requests and compensating controls, driving remediation activities and risk treatment plans with suppliers and internal stakeholders.
  • Contribute to the maintenance and continuous improvement of cybersecurity third-party risk management processes, methodologies, control frameworks and supplier monitoring activities.
  • Prepare risk reporting, dashboards and management presentations to provide visibility of third-party cyber risk exposure, key risk trends and remediation status.
  • Support audits, compliance initiatives and regulatory programmes relating to supply-chain security and third-party cybersecurity risk management, providing subject matter expertise to internal and external stakeholders.

What are we looking for?

Education: Bachelor's or Master's degree in Cybersecurity, Information Security, Computer Science, Engineering, Risk Management or related disciplines.

Experience: 5+ years of experience in Cybersecurity, Information Security, ICT Risk Management or Third-Party Risk Management.

Languages:

  • Italian: native or at least C1 proficiency.
  • English: at least B2 level (written and spoken).

Technical/IT Skills:

  • Information Security & Cybersecurity Governance
  • Third-Party Risk Management & Supplier Due Diligence
  • Cybersecurity Regulations (NIS2, DORA)
  • Risk Assessment & Risk Treatment Methodologies
  • TPRM / GRC / Supplier Management Platforms
  • Cybersecurity Contractual Requirements & Supplier Compliance
  • Data Analysis, Risk Monitoring & Reporting
  • ISO 27001, NIST Cybersecurity Framework & NIST SP 800-161 Knowledge

What else should you know? This role offers the opportunity to work in an international environment and collaborate with stakeholders across different geographies and functions worldwide.

What can we offer to you:

  • Permanent Contract – CCNL Energia e Petrolio
  • For home office contract: Pay not lower than 43.000 €
  • Corporate Benefits We offer a comprehensive benefits package, including health insurance, internal gym, discounts and partnerships, services related to health, family, well-being, and in-house cafeteria.
  • Hybrid working model Smart Working options and flexible hours to help you achieve a better work-life balance.
  • Location: Milan, italy

Transparency Note

At the end of the selection process, the Company reserves the right to offer a different job level and/or salary package compared to what is indicated in this job posting, in line with the candidate’s professional experience, technical and soft skills.

Any deviation shall be duly justified and documented in accordance with internal procedures and the Non-Discrimination Statement. Such deviation shall in no way be related to:

  • the remuneration received by the candidate in previous employment relationships;
  • any subjective or discriminatory factors, including but not limited to gender or other personal characteristics.

Regulatory Compliance

The decision:

• is made in compliance with the principle of equal pay for the same work or work of equal value;

• complies with the pay transparency requirements set out in EU Directive 2023/970 and the relevant national implementing legislation.

Additional Information

We support your development! Do you feel you might not fit this role perfectly? If you think you can contribute to our business development in the future, don’t hesitate to apply anyway through our spontaneous application form!

PRIVACY POLICY

All interested candidates (L. 903/03) are invited to consult the privacy policy (art 13, 14, D.Lgs 196/03 and art 13 GDPR 679/16).

Loading...

Apply now

Please start your application process.

IMPORTANT: Please upload a pdf version of your CV

(the system support also other format but pdf will enhance additional functionality which will support the Recruitment)

Select file Change Remove
Information Notice on the Processing of Personal Data of Candidates