Alfasigma is a privately held global healthcare company founded over 75 years ago in Italy, where it remains headquartered today in Bologna and Milan. The Group operates in over 100 markets spanning Europe, North and South America, Asia, and Africa.
Over three years ago, we embarked on a transformative journey to become a truly global innovative healthcare company with a leading focus on Gastrointestinal (GI) health. We have experienced remarkable growth, nearly doubled our revenues, expanding geographically, and integrating several key acquisitions. We have also evolved our portfolio, expanded into rare and specialty segments, and strengthened our pipeline and people's capabilities.
But our journey is far from complete! In fact, this is just the beginning of a bold new chapter in Alfasigma's history. We are committed to advancing innovation and leveraging our deep expertise to provide better health and a better quality of life for patients and consumers worldwide and expand our reach across diverse markets.
Scope of the role:
As Cybersecurity Governance Senior Manager, you will maintain and evolve Alfasigma's Cyber Governance, Risk & Compliance (GRC) framework across the Group, supporting the CISO in steering cyber risk management, regulatory compliance (NIS2, GDPR, GxP) and security maturity. A senior, high-visibility role spanning cyber risk assessment, ISO/IEC 27001 and NIST CSF, third-party risk, OT risk governance, AI Act and security awareness in a global, regulated pharmaceutical environment.
Your role:
Maintain and evolve the Group's Cyber Governance, Risk & Compliance framework (ISO/IEC 27001, NIST CSF, NIS2).
Support the CISO in reporting cyber risk to committees and top management, translating technical risk into business priorities.
Steer NIS2, GDPR and GxP-related compliance across all Group companies and coordinate remediation plans.
Lead enterprise cyber risk assessments and third-party / supply-chain risk assessments.
Oversee OT risk governance, AI governance (AI Act) and Business Continuity / Operational Resilience.
Design KPI/KRI reporting and dashboards for management and the Board, and run Security Awareness and security-culture programmes.
Who are you:
8+ years in Cybersecurity Governance, Risk Management or GRC, including experience supporting senior management.
In-depth knowledge of NIS2, ISO/IEC 27001 and NIST CSF, and of cyber risk-assessment methodologies.
ISO/IEC 27001 Lead Auditor certification; GRC certifications (CISM, CISA, CRISC) are a plus.
Experience in complex regulated environments (Pharma / Life Sciences or Financial Services).
Excellent ability to communicate cyber risk clearly and concisely.
Excellent command of English.
What's in it for you:
A high-visibility role reporting directly to the CISO, shaping cyber governance for a growing global pharmaceutical group.
Rome-based with hybrid working and a permanent, full-time contract.
Real impact on the resilience and compliance posture of the entire Group.
Location: Pomezia, Rome
Salary Pay Range: 75.000€ - 95.000€
The compensation range indicated in this job posting represents an estimated average range for the position. The final remuneration will be determined based on the selected candidate’s experience, skills, and qualifications, in accordance with applicable EU pay transparency and pay equity requirements
Why Join Alfasigma:
At Alfasigma, we foster a culture where the courage to innovate is key to our success.
We offer a competitive salary, comprehensive benefits, and extensive opportunities for professional growth and development.
Our commitment to people and patients is at the heart of everything we do. We value diversity and welcome individuals with unique perspectives and experiences. We believe that open-mindedness, collaboration, and a shared passion for innovation are essential to achieving meaningful progress.
Join Alfasigma and become part of a forward-thinking team dedicated to shaping the future of the pharmaceutical industry.