Information Security - Identity Lifecycle Management
Luxottica
Information Security - Identity Lifecycle Management
Contract: Permanent/Full time
Location: Milano, IT
Main responsibilities:
- Information Security Planning – Plan and estimate budget and time schedule for activities to be included into Information Security Master Plan.
- Oversight on maintenance and implementation of Information Security policies / procedures – Ensure the oversight of the implementation of the activities, identifying and reporting issues, risks and opportunities to the CISO / relevant stakeholders.
- Design and deliver awareness campaigns, workshops, and training initiatives tailored to different audiences.
- Support the selection and evaluation of training content and platforms, in collaboration with HR, Communication and other providers.
- Contribute to the definition and review of Identity Lifecycle models and controls and Segregation of Duties (SoD) in collaboration with Business owners, IT, HR, Risk Management, Privacy and Compliance, Internal Control and Internal Audit.
- Lead and coordinate the Identity Lifecycle and SoD projects for non-finance areas (i.e. SAP modules MM and SD), ensuring the extension of Identity Management governance to all business applications and data repositories.
- Collaborate with HR Business Partners (HRBP), Business Process Owners (BPO), and IT to define, implement, and maintain a centralized Role-Based Access Control (RBAC) library.
- Map, monitor, and evaluate application profiles (especially administrative roles) for non-finance departments, identifying anomalies and enforcing segregation of duties.
- Supervise and execute risk assessments for access requests outside the standard RBAC library, defining exception workflows and compensating controls.
- Validate new access or function requests against the approved role library and assess risks for exceptions or non-standard assignments.
- Define and enforce control processes for access provisioning, exception handling, and periodic reviews, including onboarding, role/function changes, and offboarding.
- Collaborate on the design and implementation of automated processes for onboarding, role changes, and offboarding, ensuring integration with HRIS and target systems.
- Support the periodic review and maintenance of the RBAC role library, working closely with HRBP and BPOs to refine roles and ensure SoD is maintained.
- Participate in incident investigations related to identity and access management, analyzing root causes and recommending improvements to lifecycle and SoD controls.
- Promote awareness and training on SoD principles and identity governance among business stakeholders, HR, and IT.
- Act as a governance and control point within the Identity Lifecycle Management process, ensuring that access delegation requests are appropriate, risk‑assessed, and aligned with the RBAC model and SoD process.
- Contribute to the definition and review of SoD models and controls in collaboration with IT, Internal Control, HR, Risk Management and Internal Audit.
- Define and maintain a comprehensive KPI framework for RBAC lifecycle governance, including the design of automated dashboards and anomaly‑detection metrics, the setup of threshold‑based alerts and escalation workflows, and the regular reporting of access‑governance performance and identified risks to the appropriate security and risk committee.
Main requirements:
- Bachelor’s degree in information security, Information Technology, Computer Science, Engineering, Statistical or similar.
- At least 2 years of experience gained in the ICT Risk Management or Security area with particular focus on the Identity Management and Segregation of Duties.
- Knowledge of SAP Basis especially on User Profile & Security Management.
- Knowledge of SAP GRC tool for risk analysis.
- Knowledge of relevant business processes (i.e. Make ‑ to ‑ Deliver, Procure to Pay, Hire to Retire).
- Knowledge of international standards and best practices in domain of Information Security, Data Protections and Business Continuity (e.g. GDPR, ISO 27001, NIST 800‑53, NIS2 etc.).
- Knowledge of relevant Information Security / Data Protection laws and regulations (e.g. Privacy, Health sensitive information, PCI DSS).
- Understanding of regulatory requirements for AI systems (ISO/IEC 42001:2023).
- Good project management skills, teamwork and individual accountability.
- Adequate data analytic fundamental skills.
- Proven ability to communicate to all levels in a technical and non‑technical manner.
- Knowledge about most common IT Security solutions.
- Excellent oral and written English language skills.
Optional requirements:
- Professional information security certifications (such as CISM, ISO 27001 Lead Auditor, CISSP, CISA).
What’s in it for you:
- Access to our cutting‑edge learning platform, Leonardo, and personalized development programs to help you grow professionally and personally.
- Enjoy flexible work conditions, health insurance coverage, ticket restaurants, internal rooftop canteen.
- Access special offers for employees on a vast range of eyewear, eye care products, and fashion apparel, so you can enjoy our world‑class brands firsthand.
- Enjoy our “Disconnect Program” a holistic approach to work‑life balance, including initiatives for mental health, yoga, jogging sessions, and more, designed to help you recharge and stay healthy.
Salary Package:
- Supplementary Health insurance coverage.
- Supplementary Pension Plan.
- Access to the EssilorLuxottica Corporate Welfare Catalog.
- Transportation – Discounted pass.
- Meal Vouchers as per company guidelines.
- Exclusive employee discounts on company products.
- Company‑provided laptop and mobile phone.
Our Diversity, Equity and Inclusion commitment
We are committed to creating an inclusive environment for all employees. We celebrate diversity and provide equal opportunities to all, regardless of race, gender, ethnicity, religion, disability, sexual orientation, or any other characteristic that makes us unique.
#J-18808-LjbffrOfferta di lavoro pubblicata 4 ore fa
Offerte di lavoro simili
- ...Luxottica in Milano is seeking an Information Security professional with expertise in Identity Lifecycle Management. The successful candidate will oversee the planning, implementation, and governance of identity and access management processes, collaborating with multiple...ConsigliatoOrario flessibile
- ...servizi in ambito cyber & information security e privacy a favore di... ...in Digital Identity con la missione di supportare... ...la gestione delle identità digitali, in conformità... ...IGA e Access Management sia su piattaforme cloud... ...premise - Gestione lifecycle identità, certificazioni...ConsigliatoLavoro ibrido
80.000 € - 85.000 €
....00 To €85,000.00 Annually Responsibilities Ensuring management of facilities services through third party contractors, or... ...infrastructure Supporting ISO14001 (Environmental) ISO27001 (Information Security Management System) Day to day site running....ConsigliatoTempo pienoOrario flessibile- ...Cybersecurity & Privacy Management Level Senior... ...con focus su Identity & Access Management... ...protezione delle identità digitali e il corretto... ...identity-centric security.... ...Informatica, Scienze dell’Informazione o campi affini... ...identità (Identity Lifecycle Management) Conoscenza...Consigliato
- ...This leadership role involves governance of security and implementation of IT risk controls. Key responsibilities include managing teams, developing training programs, and... ...candidate should have extensive experience in information security governance, strategic planning,...ConsigliatoLavoro ibrido
- ...on taking responsibility for security governance, ensuring... ...controls to deliver a safe, secure and compliant IT environment... ...expertise in governing and managing information security activities Recognized... ...analytical skills and the ability to manage multiple projects under...Smart workingTempo pienoImpiego permanenteLavoro ibridoOrario flessibile
- ...Unified Customer Experience Management platform that helps... ...artifacts such as security compliance documentation... ...the configuration lifecycle. Support project delivery... ...experience. Stay informed about Managed Services... ..., sex, gender identity, age, disability, citizenship...
33.000 € - 38.500 €
..., nella protezione di informazioni e asset digitali, nella... ..., tra cui Chief Information Officer (CIO), Chief Information Security Officer (CISO), General... ...personale del Cliente (management, personale specialistico... ...vulnerabilità, network security, identity & access management,...Impiego permanenteOrario flessibile33.000 € - 39.000 €
...a costruire un mondo del lavoro migliore. Team Product Lifecycle Management (PLM) Siamo alla ricerca di giovani talenti appassionati... ...e/o consulenziali con interazione con i principali sistemi informativi aziendali (ERP, MES, PLM, ecc). Capacità di raccolta requisiti...- ...out. The project management and central controls... ...Engineering Data Manager will serve as a... ...to the Project Information and Document Controls... ...& Inspection. Manage the transfer of... ...backup and data security processes. Participate... .... ~5 years of lifecycle information...Tempo pienoDisponibilità immediataDal lunedì al venerdì
- ...world. The EY Global Information Security team is looking for new members helping manage security risk using... ...business process lifecycles. The EY RTH-EW Hub InfoSec... ...the integration of identity & access management,... ...recruitment process, please inform us as soon as...Disponibilità immediataOrario flessibile
- ...Led by an experienced management team and supported by a strong... ...Cloud customers. The Security Design and Integration Manager will drive efforts in... ...Engineering, Construction, Information Technology, and Security... ...ability to prioritize and manage multiple projects and responsibilities...Orario flessibile
- ...client's challenges of today and tomorrow. Informed and validated by science and data.... ...ROLEAs a/an Digital Engineering & Product Lifecycle Senior Consultant at Capgemini Invent, you... ...to enhance client performance and manage R&D projects in Product Development, New...RemotoOrario flessibile
- ...Client Security Specialist Assistant Director The... ...Assurance team within Information Security is opening a... ...for communication to management. Engage with technology... ...and assist project managers and operational staff... ...recruitment process, please inform us as soon as possible...Disponibilità immediataTurniOrario flessibile
- ...transformation goals. Drive end-to-end security solutions from conceptual... ...Engagement and Project Management : Manage and oversee complex... ...strategies to include aspects of identity & access governance, data... ...degree in cyber security, information technology, or a related...
- ...Opportunità professionali: IT MANAGER (2707) Chiomenti è primario Studio Legale italiano a vocazione internazionale, con oltre 450... ...Cybersecurity e protezione dei dati: Competenze in sicurezza informatica, identity & access management, Data Loss Prevention, business continuity...Lavoro ibrido
- ...Cyber Security Analyst Stipendio: In base all'esperienza Location... ..., incluse gestione delle identità (IAM) e la configurazione di... ...rischi di sicurezza informatica (Information Security Risk Assessment);... ...System Center Configuration Manager) è un plus; Competenze di...Part-timeTempo pienoImpiego permanenteContratto con partita IVALungo termineOrario flessibileDal lunedì al venerdì
42.000 €
...Definizione dell’architettura target (processi, data model, security, integrazioni, scalabilità, performance) e delle scelte tecnologiche... ...data strategy: acquisizione dati, data migration, master data management. Coinvolgimento nelle fasi di design, sviluppo e test (unit...Smart working- ...gestione dei programmi di sicurezza delle informazioni, resilienza operativa e governance... ...: Progettazione e gestione dell’Information Security Management System (ISMS) Conduzione della... ...basata sul rischio, controlli di lifecycle e post-market monitoring # ISO/...Stage/TirocinioRemoto
- ...success. As a member of the GPQSS Management Team, you will own the long‑term... ...edge‑driven solutions. You will manage offerings across their full lifecycle to ensure alignment with market... ...website. Please include your contact information and specific details about your...Stage/TirocinioTurniOrario flessibile
- ...This role reports to Head of Cyber Security in Europe and protects sensitive data and systems... ...appropriate. Identify and document information security risks and propose mitigating... ...solutions to solve the organisations needs. Manage solution development and deployment that...
- ...opportunities and lead indication launches and lifecycle management. Hold full accountability for... ..., and collaboration. Build and manage strategic relationships with key external... ..., marital status, disability, gender identity or any other legally protected...
- ...Reckitt Benckiser LLC is seeking a RAS Intern in Milan to support the lifecycle management of Selfcare products. Responsibilities include preparing regulatory documents, revising artworks, and ensuring compliance with applicable laws. The ideal candidate will hold...Stage/Tirocinio
- ...inserire nel ruolo di Senior Manager – Security, Compliance & Internal IT... ...responsabilità di: Sicurezza delle Informazioni Sistema di Gestione Integrato (Qualità, Information Security, Continuità... ..., iOS, Linux, Android Identity & Admin: Active Directory,...Tempo pienoOrario flessibile
- ...their businesses and effectively manage operations in the areas of:... ...across the Data Lifecycle - from collection and storage... .... Collaborate with IT and Security teams to ensure data access controls... ...Collaborate with Legal and Information Security teams to ensure alignment...Tempo pieno
- ...Qualifications Additional Information Soft Skill Richieste:... ...You'll be working on our Managed Cloud Compliance product, a... ...collects, transforms and reports security and compliance data from Azure... ...for the end-to-end testing lifecycle—from defining acceptance criteria...WeekendTurno di notte
50.000 € - 55.000 €
..., analytics e innovazione di prodotto. Responsabilità principali Guidare le strategie di user registration, identity management e customer lifecycle management, aumentando la conoscenza delle audience e il valore generato dai dati proprietari. Collaborare con...- ...tecnologiche per la gestione delle identità digitali. Il candidato... ...esperienza in progetti di Identity Governance. Le responsabilità... ...IGA e gestione del lifecycle delle identità, mentre le competenze... ..., capacità di project management e conoscenze di vari strumenti...
- ...Responsibilities Manage and coordinate project technical safety interfaces between... ...management firms in the world. For more information on Hill, please visit our website at .... ...throughout the entire construction project lifecycle and adapt to the needs of each assignment...
- ...age. All personal information will be collected under... ...for the entire software lifecycle, ensuring our... ...stable, scalable, and secure. Who You Are You... ...Requirements Infrastructure Management: Design and deploy... ...CI/CD & Delivery: Manage deployment pipelines and...
Ricerche correlate
