3 postings · 3 open
Docebo · Milan, Italy
midfull time501-1000E-learningitalianenglishArtificial Intelligence. Actual Impact. At Docebo, we’re using AI to change how people learn at work—and we mean actually change it. We’re an AI-powered learning platform that helps organizations create, deliver, and manage training all in one place. But our real mission goes deeper: we help teams move faster, work smarter, and focus on the work that truly matters. Our platform is built with intelligent, time-saving tools that personalize learning, eliminate busywork, and turn training from a checkbox into a superpower. The result? Better experiences for learners and real results for businesses. We’re shaping the future of learning with a team that isn’t afraid to challenge the status quo. If you're excited by the idea of using AI to make work-life better for real people–you’ll feel right at home here. And it’s not just what we build, it’s how we show up. At Docebo, our values aren’t just posters on the wall—they guide how we work every day. We call it the Docebo Heart: trust by default, assume positive intent, and create space for different perspectives to thrive. So… what are you waiting for? Join 900+ Docebians around the world and help us reinvent the way people learn, because learning never stops. 🚀 THE ADVENTURE AHEAD As our Cybersecurity Compliance Analyst, you will be the front-line champion and strategist safeguarding Docebo's security posture and driving customer trust. You will bridge the gap between technical rigor and client confidence, translating complex compliance frameworks (like NIS2, NIST, GDPR, ISO, SOC, and FedRAMP) into competitive advantages. In this role, your work directly accelerates deal cycles, empowers our sales and legal teams, and ensures our global SaaS ecosystem remains fortress-secure. ⚡ THE DAY-TO-DAY - Champion Customer Trust: Respond to prospect and customer security requests, review RFIs/RFQs, and deliver flawless responses regarding Docebo's compliance and security posture. - Drive Compliance & CAPs: Tackle customer security questionnaires head-on and collaborate internally to establish Corrective Action Plans (CAPs) for outstanding requirements. - Power Legal Alignment: Partner with the Docebo legal team to review Customer Agreements, Terms & Conditions, and Data Processing Addendums, seamlessly mapping client requirements to standard processes. - Spearhead Audit Readiness: Lead and support annual customer audits while partnering with the GRC team during SOC2, ISO (27001, 9001, 42001), and NIS2 assessments. - Automate for Efficiency: Leverage AI tools and basic programming capabilities to automate internal processes and optimize compliance workflows. - Publish & Curate Insights: Organize internal compliance documentation and publish up-to-date materials directly to Docebo’s "trust pages" using platforms like Vanta. - Evaluate Vendor Risk: Support third-party vendor risk assessments, monitor security controls, and maintain management reporting dashboards to mitigate external supplier risks. 🦸 YOUR SUPERPOWERS - Proven SaaS Expertise: 4+ years of hands-on experience supporting security activities, audits, and compliance in SaaS environments, backed by a Bachelor's degree in Computer Science or a related field. - Cloud & Privacy Mastery: Solid working knowledge of cloud environments (AWS, Azure, GCloud) alongside data privacy regulations like GDPR, CCPA, and PIPEDA. - Framework Fluent: Deep familiarity with security and compliance standards including ISO/IEC (27001, 27017, 27018, 27701, 9001, 42001), SOC 2, PCI, NIS2, and CFR21 Part 11. - Technical Savvy & Automation Mindset: Basic coding skills and hands-on experience with modern security governance platforms like Vanta and 1UP. - Articulate Communicator: Exceptional written and verbal English communication skills, with a knack for translating complex technical concepts into clear customer answers. - Problem-Solver Extraordinaire: Proactive, adaptable, and deeply passionate about the intersection of technology, business, and enterprise learning. 🌟 BONUS POINTS - Certified Specialist: Holding certifications such as CISA, CIPP (or CIPT), or CompTIA Security+. - FedRAMP Familiarity: Basic understanding and exposure to the FedRAMP framework. - Advanced Academic Background: Specialized degree focus in Information Security or Auditing. 🧭 OUR INTERVIEW PROCESS Step 1: We’ll kick things off with a 30-minute video call with a member of our Talent team. We’ll get to know you, share more about the role and team, and make sure we’re aligned. Step 2: A 60-minute video call with the hiring manager, where they’ll dig deeper into your experience, approach, and what excites you most about this opportunity. Step 3: A 45-minute practical case study/technical discussion with key members of the Compliance & GRC team. Step 4: A final 30-minute chat with our Security Leadership team to discuss long-term vision, growth, and team alignment. OUR HYBRID WORK PHILOSOPHY 🤝 Great work can happen anywhere but coming together helps us go further. Our team spends three days a week in the office (Tuesday-Thursday) to collaborate, solve problems, and learn from each other. With flexibility the rest of the week, it’s a balance designed to help everyone do their best work and keep growing. OUR TOTAL REWARDS PHILOSOPHY 🎉 Our Total Rewards Philosophy centers around three core areas to reward and care for our People: - Rewarding Impact: We lead with competitive pay to reward the impact, skills and traits that fuel our success. - Fostering Holistic Wellbeing: We care deeply about and invest in the whole person with programs that support our people’s physical, mental, and financial well-being. - Empowering Our Talent Culture: We build a culture of trust and empowerment by designing our rewards and benefits with transparency, equity, and flexibility, enabling our people to do their best work and stay for the long haul. OUR PROMISE TO YOU 😍 - Financial Wellness: Own a piece of Docebo through our Employee Share Purchase Plan (ESPP) at a 15% discount, plus a competitive compensation package. - Your Well-Being, Covered: You’ll get access to health benefits, so you can get the care you need when you need it. - Rest, Relax, Repeat: Rest and recharge with paid vacation days, two company-wide Docebo Days, floating holidays for cultural celebrations, and your birthday off! - Family First: We provide coverage offering you time with your little one(s) so you can soak up all those precious moments. Fun fact: we had 30 Docebian babies join the family in 2025! - Fuel for Your Day: Receive a meal voucher for every working day, so you can focus on doing your best work while enjoying a meal that keeps you energized. - Connections That Count: Connect with global communities through our Employee Resource Groups (including PRIDE, DWA, BIDOC, and Green Ambassadors) and company-wide events that keep the fun rolling all year long.
Posted 1 month agoView detailsSTMicroelectronics · Napoli, IT
seniorfull time10001+SemiconductorsOUR STORY At STMicroelectronics, we believe in the power of technology to drive innovation and make a positive impact on people, businesses, and society. As a global semiconductor company, our advanced technologies and chips form the hidden foundation of the world we live in today. When you join ST, you will be part of a global business with more than 115 nationalities, present in 40 countries, and comprising over 50,000 diverse and dedicated creators and makers of technology around the world. Developing technologies takes more than talent: it takes amazing people who understand collaboration and respect. People with passion and the desire to disrupt the status quo, drive innovation, and unlock their own potential. Embark on a journey with us, where you can innovate for a future that we want to make smarter and greener, in a responsible and sustainable way. Our technology starts with you. YOUR ROLE We are seeking a Senior Expert in Embedded Software Security and Security Architectures to define, oversee, and strengthen all software security development activities for the RFOC subgroup products across automotive and non-automotive markets. This role is responsible for leading security-by-design practices throughout the software lifecycle, from requirements definition through design, implementation, integration, validation, and release support. The ideal candidate combines deep expertise in embedded software development, cybersecurity standards, secure coding, and security architecture, with the ability to guide engineering teams and collaborate effectively with quality, project management, and product stakeholders. The position requires a strong background in automotive quality processes such as ASPICE, knowledge of ISO/SAE 21434 and cybersecurity requirements for automotive products as well as Common Criteria and SESIP for IT and IoT applications. It has to support internal and external audits related to security, quality, and process compliance. Prepare and provide evidence, documentation, and technical justification during reviews and audits. It is key the ability to operate effectively in complex, fast-paced, and demanding development environments. * Security Leadership and Architecture Define and supervise the software security strategy for RFOC subgroup products. Lead the design of secure embedded software architectures for automotive and non-automotive applications. Establish security requirements, security controls, and architectural principles aligned with product and market needs. Review and approve security-related design decisions, ensuring compliance with internal standards and external regulations. Support threat analysis, risk assessment, and security concept activities for embedded systems. End-to-End Security Development Oversigh * Drive software security activities across the full development lifecycle: Requirements management, architecture and detailed design, implementation, integration, verification and testing. Ensure security features are implemented consistently and robustly across software components. Guide engineering teams in adopting secure development practices and maintaining traceability from security requirements to validation evidence. * Secure Coding and Secure Development Practices Promote and enforce secure coding practices across embedded software teams. Perform or lead secure code reviews, vulnerability assessments, and remediation planning. Define security development guidelines, coding rules, and defensive programming practices. Contribute to the analysis and mitigation of software vulnerabilities and security weaknesses. * Team Guidance and Cross-Functional Collaboration Work closely with software engineering teams to drive execution and quality across security-related activities. Provide technical leadership and coaching to engineers involved in security requirements, design, implementation, integration, and testing. Collaborate with project management, quality assurance, product management, system engineering, and other stakeholders. Help teams make practical, risk-based decisions when ideal solutions are constrained by technical, timing, cost, or program realities. * Program Execution in Complex Environments Adapt to changing priorities, evolving planning, and shifting technical constraints. Sustain performance during workload peaks and operate effectively under pressure in large and challenging projects. Manage trade-offs and compromises when the optimal path is not feasible, while preserving security integrity as much as possible. Support issue resolution and escalation management for security-related risks and execution blockers. * Innovation and Continuous Improvement Stay current with emerging trends in embedded security, automotive cybersecurity, and secure development methodologies. Champion innovation in development workflows, including the use of AI-driven tools and methodologies to improve productivity, quality, and efficiency. Identify opportunities to simplify processes, automate repetitive tasks, and improve the effectiveness of security engineering practices. Contribute to continuous improvement of tools, methods, templates, and best practices. YOUR SKILLS & EXPERIENCES Experience * Extensive experience in embedded software design and development. * Proven experience in software security, security architecture, or cybersecurity engineering for embedded products. * Experience working in automotive development environments and applying ASPICE-based processes. * Hands-on knowledge of ISO/SAE 21434, automotive cybersecurity engineering practices, Common Criteria and SESIP. * Demonstrated experience with secure coding, code review, and security vulnerability mitigation. * Experience supporting technical audits, quality reviews, and customer-facing security assessments. Technical Skills * Strong understanding of embedded software architecture, real-time constraints, and system integration. * Solid knowledge of software security concepts, including: * secure boot and trust chains * authentication and authorization * cryptography fundamentals and secure key handling * firmware integrity protection * secure update mechanisms * attack surface reduction * secure communication principles * Understanding of testing and validation approaches for security functions. * Familiarity with security analysis techniques such as threat modeling and risk assessment. Behavioral and Leadership Skills * Strong ability to work collaboratively in a multidisciplinary team. * Capable of influencing and guiding engineering teams without necessarily having direct line management authority. * Excellent communication skills, with the ability to explain complex security topics clearly to technical and non-technical audiences. * High adaptability and resilience in dynamic project environments. * Strong sense of ownership, accountability, and initiative. * Open-minded, innovation-oriented, and comfortable using modern tools and AI-assisted methodologies. MDRF perimeter only. ST is proud to be one of the 17 companies certified as a 2025 Global Top Employer and the first and only semiconductor company to achieve this distinction. ST was recognized in this ranking thanks to its continuous improvement approach and stands out particularly in the areas of ethics & integrity, purpose & values, organization & change, business strategy, and performance. At ST, we endeavor to foster a diverse and inclusive workplace, and we do not tolerate discrimination. We aim to recruit and retain a diverse workforce that reflects the societies around us. We strive for equity in career development, career opportunities, and equal remuneration. We encourage candidates who may not meet every single requirement to apply, as we appreciate diverse perspectives and provide opportunities for growth and learning. Diversity, equity, and inclusion (DEI) is woven into our company culture. To discover more, visit st.com/careers.
Posted 3 months agoView detailsSTMicroelectronics · TW
midfull time10001+SemiconductorsOUR STORY At ST, we believe in the power of technology to drive innovation and make a positive impact on people, business, and society. We are a global semiconductor company, and our advanced technology & chips forms the hidden part of the world we live in today. When you join ST, you will be part of a global business of more than 115+ nationalities and present in 40 countries, 50,000+, diverse and dedicated creators & makers of technology around the world! Developing technologies takes more than talent: it takes amazing people who understands collaboration and respect. People with passion and desire to disrupt the status quo, push boundaries and drive innovation – whilst unlocking your own potential. YOUR ROLE • Primary interface between ST Divisions and subcontractor(OSAT) to ensure timely respond to quality issues & enquires from all stakeholders • Accountable and drive subcontractor for internal & external customer complaints including investigation and 8D write up. • Quality continuous improvement activity including weekly gemba walk in osat production, program cascade from central, and etc • Responsible for audit (internal & external) and ensure open action closure • Responsible for quality disposition on non-conformance lots in OSAT. • Responsible for spec review and ensure subcontractor comply to ST’s quality requirement & quality tools. • Responsible for read across of quality incidence from other plant and deployment of special quality and requirement from customers and Division. • Accountable for ORT (on-going rel) failure. • Involvement in NPI quality related discussion. YOUR SKILLS & EXPERIENCES • Min. Bachelor Degree of Mechanical/Electrical Engineering or any relevant. • Certified or familiar with international standard VDA6.3 & IATF 16949 & ISO. • Good command in English & Mandarin • Strong semiconductor process knowledges such as Bump, Assembly & Test, and WLCSP, BGA, FC, etc. package technologies • Familiar with tester platform & control is a plus Working at ST means innovating for a future that we want to make smarter, greener, in a responsible and sustainable way. Our technology starts with you. Join us and start the future! To discover more, visit st.com/careers
Posted 3 months agoView details