ICT GOVERNANCE & RISK
ARISTON GROUP
Ariston Group is a global leader in sustainable climate and water comfort, listed on Euronext Milan. In 2025 the group reported 2.7 billion-euro revenues, with almost 11,000 employees, direct presence in 41 countries in 5 continents, 32 production sites and 31 research and development centers. The group demonstrates its commitment to sustainability through renewable and high-efficiency solutions, including heating heat pumps, water heating heat pumps, hybrids, domestic ventilation, air handling, electric components, and solar thermal systems, while continuously investing in technological innovation, digitalization, and advanced connectivity solutions. The group operates under global strategic brands Ariston, Wolf and Elco, and brands such as Calorex, NTI, Atag, Domotec, Brink, Chromagen, Racold, as well as Thermowatt and Ecoflam in the components and combustion technologies business.ICT Governance & RiskDepartment: ICT SecurityReports to: Governance Risk and ComplianceLocation: Fabriano or Milan / HybridAbout the RoleWe are looking for a a professional to support Group-level ICT Security governance, ITGC compliance, IT risk management and SAP/ERP access governance.The role focuses on ensuring effective control execution, supporting audit activities, coordinating evidence collection and monitoring remediation plans with relevant control owners.It also includes the management of Identity Access Management processes for SAP and ERP environments, with a focus on authorization procedures, Segregation of Duties, periodic access reviews, ticket management and escalation of access-related risks.Key ResponsibilitiesSupport IT General Control compliance & IT Controls according to best practice by verifying control implementation and effectiveness across relevant ICT processes and systems.Support external and internal audit activities by coordinating evidence, control owners, findings and remediation actions.Conduct an initial comprehensive IT risk assessment and maintain the Group ICT risk register.Monitor remediation plans, follow up with action owners, track deadlines and escalate delays or risks where appropriate.Manage SAP and ERP Identity Access Management processes, including access requests, role assignments and authorization changes.Support Segregation of Duties governance, including conflict analysis, mitigating controls, exception management and remediation follow-up.Coordinate periodic access review campaigns, ensuring completion, evidence collection and follow-up on revoked or modified accesses.Manage access-related tickets and privilege-change requests, verifying approvals and alignment with applicable procedures.Monitor anomalous accounts, privileged users and access exceptions, escalating relevant risks to IT Security for assessment and follow-up.Maintain documentation related to ITGC controls, SAP/ERP access procedures, audit evidence, remediation plans and governance processes.Prepare and present periodic activity, risk, control and remediation status updates to IT leaders, highlighting key achievements, open issues, priorities and required decisionsRequired Qualifications4-5 years of experience in ICT Governance, Risk & Compliance, IT General Controls (ITGC), IT Audit, IT Risk Management, Identity Governance, or similar roles.Solid understanding of IT General Controls, control testing, audit evidence management, remediation tracking, and risk assessment methodologies.Experience with SAP/ERP access management, authorization processes, role-based access controls (RBAC), user access reviews, Segregation of Duties (SoD), and related governance activities.Familiarity with Identity and Access Management (IAM) lifecycle processes, including provisioning, privilege changes, revocations, access reviews, exception management, and access request workflows; knowledge of SAP GRC, SAP authorization analysis tools, user revalidation platforms, or similar IAM solutions is considered an advantage.Good knowledge of IT governance, risk management, and cybersecurity frameworks such as ISO 27001, COBIT, NIS2, GDPR-related IT controls, or equivalent standards.Experience operating in complex ERP environments, multi-country organizations, or multi-entity ICT landscapes is a plus.Proven ability to coordinate activities with control owners, application owners, auditors, IT Security teams, and external service providers, ensuring effective execution of controls and remediation plans.Strong analytical skills to identify, assess, and prioritize IT risks, evaluate business impacts, and provide practical risk-based recommendations.Experience preparing audit reports, control evidence packages, remediation status reports, dashboards, and management updates for internal and external stakeholders is considered a plus.Excellent organizational skills, accuracy, attention to detail, accountability, and a proactive approach to managing follow-up activities across multiple stakeholders.Good command of written and spoken English, with the ability to create clear documentation, status updates, and professional communications.Equal opportunity, pay transparency & fairnessThe compensation package will be determined based on the candidate’s experience, skills and the scope of the role, applying objective and gender-neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone. As a reference, for such position we offer a salary ranging starting from 40.000 . This position is covered by the CCNL Metalmeccanici Industria.We are committed to the principle of equal employment opportunity for all people. We strive to provide a work environment that is accessible, welcoming and inclusive, in full compliance with applicable legal requirements. In line with this commitment, we promote fair, transparent and equitable reward practices. The compensation package will be determined based on the experience, skills and the scope of the role, applying objective and gender‑neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone.
- ...in the components and burners business.As ICT Manufacturing Manager, you will... ...You will be accountable for the evolution, governance, and lifecycle of digital manufacturing platforms... ...delivery, quality, cost control and risk managementCollaborate with the Digital Manufacturing...ConsigliatoLavoro ibrido
26.000 € - 30.000 €
Smart Skills Center – Agenzia per il Lavoro , filiale di Osimo, sta ricercando per azienda cliente operante nel settore della progettazione elettronica e dello sviluppo firmware , un/una: PROGETTISTA FIRMWARE La figura si dovrà occupare di: Sviluppo e manutenzione...ConsigliatoTempo pieno- ...internazionale strutturata, siamo alla ricerca di un/una IT Project Manager / Product Owner da inserire nel team Group Infrastructures & ICT Services. La figura avrà un ruolo chiave nel collegare le esigenze di business con l’esecuzione tecnica, garantendo la corretta...ConsigliatoImpiego permanenteLavoro ibrido
- ...Per una realtà internazionale strutturata, siamo alla ricerca di un/una ICT Service Manager – Business Intelligence & Reporting da inserire nel team Group Infrastructures & ICT Services. Posizione: La figura sarà responsabile della gestione e del miglioramento...ConsigliatoImpiego permanenteLavoro ibrido
- ...such as Calorex, NTI, HTP, Atag, Brink, Chromagen, Racold, as well as Thermowatt and Ecoflam in the components and burners business.ICT Microsoft Platform Services LeaderDepartment: ICTReports To: ICT Telecommunication&InfrastructureLocation: Fabriano, ItalyPosition OverviewWe...ConsigliatoLavoro ibrido
27.000 €
Descrizione azienda Our expertise has led us to revolutionise the traditional image of kitchen hoods. We have transformed them from simple accessories into unique design items capable of improving the quality of life of those who choose our products. We have managed...Tempo pienoStage/TirocinioRemotoOrario flessibile35.000 € - 40.000 €
SMART SKILLS CENTER – Agenzia per il Lavoro, filiale di Ancona, ricerca per azienda del settore metalmeccanico in forte espansione una risorsa da inserire nel ruolo di: PROGETTISTA MECCANICO Attività previste La risorsa verrà inserita all'interno dell'Uffico...Tempo pienoImpiego permanenteTempo determinato
- ricerca selezione profili ict Fabriano (AN)
- ict team Fabriano (AN)
- informatori IT Fabriano (AN)
- it Fabriano (AN)
- laureati in informatica categorie protette Fabriano (AN)
- aziende ict Fabriano (AN)
- diplomati informatica stage Fabriano (AN)
- rapido it Fabriano (AN)
- information technology Fabriano (AN)
- it system Fabriano (AN)