CYS_Security Manager_GCSC
// Role Summary
Leonardo is seeking an experienced Security Manager for their Cyber & Security Solutions unit, focusing on OT/IoT Security Consultancy, to support clients in defining and implementing cyber strategies and ensuring regulatory compliance.
// Key Responsibilities
- Define and implement OT cyber strategies and regulatory compliance (PSNC, NIS2).
- Analyze and assess infrastructure cyber posture against international frameworks.
- Re-engineer Cyber Security OT processes and define security baselines for ICS.
- Conduct audits to verify compliance with OT standards and regulations.
- Develop and implement Cyber Risk Management models for OT environments.
// Role Specification
Leonardo, a global industrial group and a leader in Aerospace, Defence, and Security, is seeking a Security Manager to join their Cyber & Security Solutions unit, specifically within the OT/IoT Security Consultancy team. This role is based in Rome (Laurentina) with potential for assignment in Milan (Nerviano).
Responsibilities:
- Support top management clients in defining and implementing cyber strategies for OT environments and regulatory compliance (e.g., PSNC, NIS2).
- Analyze and evaluate the cyber posture of infrastructures through assessments against international Frameworks and Standards.
- Re-engineer Cyber Security OT processes by analyzing and drafting guidelines, policies, and procedures.
- Define the baseline for the correct management of cyber security for ICS systems.
- Analyze and define Cybersecurity Requirements Specifications and Security High-Level Designs for ICS/OT systems (Green Field and Brown Field) compliant with IEC 62443.
- Verify, through appropriate audits, the degree of compliance with procedures, policies, OT sector standards (ISA62443), and mandatory regulations.
- Define and implement Cyber Risk Management models (based on standards like ISO/IEC 27005) to assess and manage cyber risks in OT environments and all areas impacted by current legislation.
- Define appropriate remediation plans based on action types and the degree of mitigation for cyber threats.
- Support clients in the correct analysis and management of cyber risks in the supply chain.
- Support clients in monitoring cyber processes and defining actions for continuous improvement.
Qualifications:
- Degree, preferably in STEM, or equivalent education.
- Expert/Senior seniority with at least 5 years of experience in the role.
- Knowledge of key IT and OT cybersecurity Standards and Frameworks (FNCS, ISO/IEC 27001, ISO 27005, ISA 62443, ISA 99, ENISA Technical Guidelines for Security Measures, NIST Cybersecurity Framework).
- Knowledge of key sector regulations (NIS and NIS2, PSNC, etc.).
- Knowledge of main IT and OT architectural security solutions.
- Experience in conducting IT and OT Security Assessments to evaluate cyber posture and define improvement actions.
- Knowledge of cyber risk analysis methodologies.
- Experience in defining and drafting cybersecurity policies and procedures.
- English language proficiency at B2 level.
- Behavioral Competencies: Ability and autonomy in managing complex activities; customer orientation; excellent teamwork skills; excellent organizational and deadline management skills.
Preferred Qualifications:
- Certifications such as ICS/SCADA Security Essentials, CISSP, CISM, Lead Auditor 27001 and 22301.
What We Offer:
- Reference collective labor contract: CCNL for Private Mechanical Industry and Plant Installation.
- Working Model: Hybrid.
- Contract Category: Employee/Manager.
- Contract Type: Permanent.
- 13th month salary.
- Variable incentive based on company procedures.
- Welfare vouchers worth €250 annually.
- Company canteen.
- Continuous training and professional development opportunities.
- Focus on employee well-being (economic, physical, social, and psychological).
The company reserves the right to assess the level of inclusion and economic proposal based on objective criteria and candidate seniority.
Submit your CV within three weeks of the job posting.