Cybersecurity Risk Analyst

🔥 11 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Yopeso

Yopeso

201 - 500 employees

🤝 B2B

🏢 Enterprise

☁️ SaaS

B2B • Enterprise • SaaS

Yopeso is a company specializing in crafting bespoke software products that drive business forward. With over 19 years of experience and more than 300 successful projects, Yopeso provides comprehensive services in web and mobile development, UX/UI design, DevOps & cloud, and quality assurance, among others. They cater to diverse industries and pride themselves on their customized approach, ensuring collaboration from ideation to execution. Yopeso's team of over 250 professionals is dedicated to delivering innovative, reliable, and high-performance digital solutions worldwide.

📋 Description

• Providing threat & risk analysis as a service: Planning and performing Cybersecurity Threat and Risk Analyses for IT and OT systems and products across Grid Solutions projects. • Identifying and prioritizing risks: Identifying, evaluating, and prioritizing cybersecurity risks across projects and systems; assessing risk scenarios, attack vectors, and attacker types along exposure, exploitability, impact, inherent and residual risk. • Moderating TRA workshops: Facilitating threat and risk analysis workshops together with senior project members and security specialists as TRA moderator. • Tracking mitigation and residual risk: Recommending risk-based measures, tracking mitigation, and ensuring residual risks are formally reviewed and accepted. • Maintaining risk transparency: Producing and maintaining the Threat and Risk Analysis, Security Risk Register and risk treatment documentation to ensure traceability, compliance and audit readiness. • Strengthening the methodology: Continuously improving the TRA process, templates, workflows and tooling (e.g., the PSS Threat and Risk Tool). • Supporting projects and engineering teams: Sharing identified risks and possible countermeasures with project and engineering teams as input for their decisions. • Ensuring compliance: Translating relevant standards and regulations into practical risk work (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).

🎯 Requirements

• Completed studies: Bachelor or Master in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or a comparable qualification with relevant professional experience. • Expertise in risk analysis: Experience in cybersecurity threat and risk assessment, threat modeling and risk prioritization in OT or product security. • Knowledge of standards: Familiarity with ISA/IEC 62443 (especially risk assessment, 62443-3-2/-3-3), and others such as CRA, NIS-2, NERC CIP, BDEW Whitepaper, ISO 27001/27005. • OT/ICS understanding: Understanding of industrial control systems, network architectures and protocols, and how security risks manifest in operational environments. • Workshop facilitation: Ability to moderate TRA workshops and align multidisciplinary stakeholders from project, engineering, and security. • Analytical mindset: Strong analytical and structured way of working; able to translate technical detail into clear, prioritized risk statements. • Communication skills: Proficient in English, with a high level of initiative and the ability to communicate risk to technical and non-technical stakeholders (German is a plus). • Desirable certifications: Certifications such as ISA/IEC 62443, CEH, CySA+, or similar are a plus (no hard requirement).

🏖️ Benefits

• Competitive remuneration • Remote work • Sports/leisure benefit • 20 sick leave days paid at 100% • 32 calendar days of vacation • Team events, online, at the office, or outside • Professional development plan with guidance and mentorship • Training and development opportunities with an allocated budget • Professional Certifications • Optional medical insurance

Apply Now