ICT GOVERNANCE & RISK
Ariston Group is a global leader in sustainable climate and water comfort, listed on Euronext Milan. In 2025 the group reported 2.7 billion-euro revenues, with almost 11,000 employees, direct presence in 41 countries in 5 continents, 32 production sites and 31 research and development centers. The group demonstrates its commitment to sustainability through renewable and high-efficiency solutions, including heating heat pumps, water heating heat pumps, hybrids, domestic ventilation, air handling, electric components, and solar thermal systems, while continuously investing in technological innovation, digitalization, and advanced connectivity solutions. The group operates under global strategic brands Ariston, Wolf and Elco, and brands such as Calorex, NTI, Atag, Domotec, Brink, Chromagen, Racold, as well as Thermowatt and Ecoflam in the components and combustion technologies business.
ICT Governance & Risk
Department: ICT Security
Reports to: Governance Risk and Compliance
Location: Fabriano or Milan / Hybrid
Â
About the Role
We are looking for a a professional to support Group-level ICT Security governance, ITGC compliance, IT risk management and SAP/ERP access governance.
The role focuses on ensuring effective control execution, supporting audit activities, coordinating evidence collection and monitoring remediation plans with relevant control owners.
It also includes the management of Identity Access Management processes for SAP and ERP environments, with a focus on authorization procedures, Segregation of Duties, periodic access reviews, ticket management and escalation of access-related risks.
Â
Key Responsibilities
- Support IT General Control compliance & IT Controls according to best practice by verifying control implementation and effectiveness across relevant ICT processes and systems.
- Support external and internal audit activities by coordinating evidence, control owners, findings and remediation actions.
- Conduct an initial comprehensive IT risk assessment and maintain the Group ICT risk register.
- Monitor remediation plans, follow up with action owners, track deadlines and escalate delays or risks where appropriate.
- Manage SAP and ERP Identity Access Management processes, including access requests, role assignments and authorization changes.
- Support Segregation of Duties governance, including conflict analysis, mitigating controls, exception management and remediation follow-up.
- Coordinate periodic access review campaigns, ensuring completion, evidence collection and follow-up on revoked or modified accesses.
- Manage access-related tickets and privilege-change requests, verifying approvals and alignment with applicable procedures.
- Monitor anomalous accounts, privileged users and access exceptions, escalating relevant risks to IT Security for assessment and follow-up.
- Maintain documentation related to ITGC controls, SAP/ERP access procedures, audit evidence, remediation plans and governance processes.
- Prepare and present periodic activity, risk, control and remediation status updates to IT leaders, highlighting key achievements, open issues, priorities and required decisions
Â
Required Qualifications
- 4-5 years of experience in ICT Governance, Risk & Compliance, IT General Controls (ITGC), IT Audit, IT Risk Management, Identity Governance, or similar roles.
- Solid understanding of IT General Controls, control testing, audit evidence management, remediation tracking, and risk assessment methodologies.
- Experience with SAP/ERP access management, authorization processes, role-based access controls (RBAC), user access reviews, Segregation of Duties (SoD), and related governance activities.
- Familiarity with Identity and Access Management (IAM) lifecycle processes, including provisioning, privilege changes, revocations, access reviews, exception management, and access request workflows; knowledge of SAP GRC, SAP authorization analysis tools, user revalidation platforms, or similar IAM solutions is considered an advantage.
- Good knowledge of IT governance, risk management, and cybersecurity frameworks such as ISO 27001, COBIT, NIS2, GDPR-related IT controls, or equivalent standards.
- Experience operating in complex ERP environments, multi-country organizations, or multi-entity ICT landscapes is a plus.
- Proven ability to coordinate activities with control owners, application owners, auditors, IT Security teams, and external service providers, ensuring effective execution of controls and remediation plans.
- Strong analytical skills to identify, assess, and prioritize IT risks, evaluate business impacts, and provide practical risk-based recommendations.
- Experience preparing audit reports, control evidence packages, remediation status reports, dashboards, and management updates for internal and external stakeholders is considered a plus.
- Excellent organizational skills, accuracy, attention to detail, accountability, and a proactive approach to managing follow-up activities across multiple stakeholders.
- Good command of written and spoken English, with the ability to create clear documentation, status updates, and professional communications.
Â
Equal opportunity, pay transparency & fairness
The compensation package will be determined based on the candidate’s experience, skills and the scope of the role, applying objective and gender-neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone. As a reference, for such position we offer a salary ranging starting from 40.000 €. This position is covered by the CCNL Metalmeccanici Industria.
Â
We are committed to the principle of equal employment opportunity for all people. We strive to provide a work environment that is accessible, welcoming and inclusive, in full compliance with applicable legal requirements. In line with this commitment, we promote fair, transparent and equitable reward practices.  The compensation package will be determined based on the experience, skills and the scope of the role, applying objective and gender‑neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone.
Ariston Group is a global leader in sustainable climate and water comfort, listed on Euronext Milan. In 2025 the group reported 2.7 billion-euro revenues, with almost 11,000 employees, direct presence in 41 countries in 5 continents, 32 production sites and 31 research and development centers. The group demonstrates its commitment to sustainability through renewable and high-efficiency solutions, including heating heat pumps, water heating heat pumps, hybrids, domestic ventilation, air handling, electric components, and solar thermal systems, while continuously investing in technological innovation, digitalization, and advanced connectivity solutions. The group operates under global strategic brands Ariston, Wolf and Elco, and brands such as Calorex, NTI, Atag, Domotec, Brink, Chromagen, Racold, as well as Thermowatt and Ecoflam in the components and combustion technologies business.
ICT Governance & Risk
Department: ICT Security
Reports to: Governance Risk and Compliance
Location: Fabriano or Milan / Hybrid
Â
About the Role
We are looking for a a professional to support Group-level ICT Security governance, ITGC compliance, IT risk management and SAP/ERP access governance.
The role focuses on ensuring effective control execution, supporting audit activities, coordinating evidence collection and monitoring remediation plans with relevant control owners.
It also includes the management of Identity Access Management processes for SAP and ERP environments, with a focus on authorization procedures, Segregation of Duties, periodic access reviews, ticket management and escalation of access-related risks.
Â
Key Responsibilities
- Support IT General Control compliance & IT Controls according to best practice by verifying control implementation and effectiveness across relevant ICT processes and systems.
- Support external and internal audit activities by coordinating evidence, control owners, findings and remediation actions.
- Conduct an initial comprehensive IT risk assessment and maintain the Group ICT risk register.
- Monitor remediation plans, follow up with action owners, track deadlines and escalate delays or risks where appropriate.
- Manage SAP and ERP Identity Access Management processes, including access requests, role assignments and authorization changes.
- Support Segregation of Duties governance, including conflict analysis, mitigating controls, exception management and remediation follow-up.
- Coordinate periodic access review campaigns, ensuring completion, evidence collection and follow-up on revoked or modified accesses.
- Manage access-related tickets and privilege-change requests, verifying approvals and alignment with applicable procedures.
- Monitor anomalous accounts, privileged users and access exceptions, escalating relevant risks to IT Security for assessment and follow-up.
- Maintain documentation related to ITGC controls, SAP/ERP access procedures, audit evidence, remediation plans and governance processes.
- Prepare and present periodic activity, risk, control and remediation status updates to IT leaders, highlighting key achievements, open issues, priorities and required decisions
Â
Required Qualifications
- 4-5 years of experience in ICT Governance, Risk & Compliance, IT General Controls (ITGC), IT Audit, IT Risk Management, Identity Governance, or similar roles.
- Solid understanding of IT General Controls, control testing, audit evidence management, remediation tracking, and risk assessment methodologies.
- Experience with SAP/ERP access management, authorization processes, role-based access controls (RBAC), user access reviews, Segregation of Duties (SoD), and related governance activities.
- Familiarity with Identity and Access Management (IAM) lifecycle processes, including provisioning, privilege changes, revocations, access reviews, exception management, and access request workflows; knowledge of SAP GRC, SAP authorization analysis tools, user revalidation platforms, or similar IAM solutions is considered an advantage.
- Good knowledge of IT governance, risk management, and cybersecurity frameworks such as ISO 27001, COBIT, NIS2, GDPR-related IT controls, or equivalent standards.
- Experience operating in complex ERP environments, multi-country organizations, or multi-entity ICT landscapes is a plus.
- Proven ability to coordinate activities with control owners, application owners, auditors, IT Security teams, and external service providers, ensuring effective execution of controls and remediation plans.
- Strong analytical skills to identify, assess, and prioritize IT risks, evaluate business impacts, and provide practical risk-based recommendations.
- Experience preparing audit reports, control evidence packages, remediation status reports, dashboards, and management updates for internal and external stakeholders is considered a plus.
- Excellent organizational skills, accuracy, attention to detail, accountability, and a proactive approach to managing follow-up activities across multiple stakeholders.
- Good command of written and spoken English, with the ability to create clear documentation, status updates, and professional communications.
Â
Equal opportunity, pay transparency & fairness
The compensation package will be determined based on the candidate’s experience, skills and the scope of the role, applying objective and gender-neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone. As a reference, for such position we offer a salary ranging starting from 40.000 €. This position is covered by the CCNL Metalmeccanici Industria.
Â
We are committed to the principle of equal employment opportunity for all people. We strive to provide a work environment that is accessible, welcoming and inclusive, in full compliance with applicable legal requirements. In line with this commitment, we promote fair, transparent and equitable reward practices.  The compensation package will be determined based on the experience, skills and the scope of the role, applying objective and gender‑neutral criteria. We believe that transparency and fairness are essential to building trust, fostering inclusion and ensuring equal opportunities for everyone.
Fabriano, IT, 60044