Cybersecurity Risk Analyst

🕒 July 28

🇷🇴 Romania – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 17%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Yopeso

Yopeso

201 - 500 employees

🤝 B2B

🏢 Enterprise

☁️ SaaS

B2B • Enterprise • SaaS

Yopeso is a company specializing in crafting bespoke software products that drive business forward. With over 19 years of experience and more than 300 successful projects, Yopeso provides comprehensive services in web and mobile development, UX/UI design, DevOps & cloud, and quality assurance, among others. They cater to diverse industries and pride themselves on their customized approach, ensuring collaboration from ideation to execution. Yopeso's team of over 250 professionals is dedicated to delivering innovative, reliable, and high-performance digital solutions worldwide.

📋 Description

• Providing threat & risk analysis as a service: Planning and performing Cybersecurity Threat and Risk Analyses for IT and OT systems and products across Grid Solutions projects. • Identifying and prioritizing risks: Identifying, evaluating, and prioritizing cybersecurity risks across projects and systems; assessing risk scenarios, attack vectors, and attacker types along exposure, exploitability, impact, inherent and residual risk. • Moderating TRA workshops: Facilitating threat and risk analysis workshops together with senior project members and security specialists as TRA moderator. • Tracking mitigation and residual risk: Recommending risk-based measures, tracking mitigation, and ensuring residual risks are formally reviewed and accepted. • Maintaining risk transparency: Producing and maintaining the Threat and Risk Analysis, Security Risk Register and risk treatment documentation to ensure traceability, compliance and audit readiness. • Strengthening the methodology: Continuously improving the TRA process, templates, workflows and tooling (e.g., the PSS Threat and Risk Tool). • Supporting projects and engineering teams: Sharing identified risks and possible countermeasures with project and engineering teams as input for their decisions. • Ensuring compliance: Translating relevant standards and regulations into practical risk work (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).

🎯 Requirements

• Completed studies: Bachelor or Master in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or a comparable qualification with relevant professional experience. • Expertise in risk analysis: Experience in cybersecurity threat and risk assessment, threat modeling and risk prioritization in OT or product security. • Knowledge of standards: Familiarity with ISA/IEC 62443 (especially risk assessment, 62443-3-2/-3-3), and others such as CRA, NIS-2, NERC CIP, BDEW Whitepaper, ISO 27001/27005. • OT/ICS understanding: Understanding of industrial control systems, network architectures and protocols, and how security risks manifest in operational environments. • Workshop facilitation: Ability to moderate TRA workshops and align multidisciplinary stakeholders from project, engineering, and security. • Analytical mindset: Strong analytical and structured way of working; able to translate technical detail into clear, prioritized risk statements. • Communication skills: Proficient in English, with a high level of initiative and the ability to communicate risk to technical and non-technical stakeholders (German is a plus). • Desirable certifications: Certifications such as ISA/IEC 62443, CEH, CySA+, or similar are a plus (no hard requirement).

🏖️ Benefits

• Competitive remuneration • Remote work • 24 days off per year and floating days • Private clinic health services, Regina Maria Medical Insurance • Flexible benefits through Up multibenefits platform • Referral bonus scheme • Team events, online or at the office • Training and development opportunities with allocated budget • Professional Certifications • Knowledge sharing context

Apply Now

Similar Jobs

🕒 July 9

ESA - Electronic Security Association

11 - 50

🔐 Security

📋 Compliance

Lead Cyber Security Architect driving innovation in security architecture at Resideo. Collaborating with teams to embed security across technology landscape and monitor emerging threats.

Cyber Security

🕒 June 25

Sophos

1001 - 5000

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

Senior Incident Response Analyst supporting Managed Detection and Response customers at Sophos. Leading investigation efforts on active cyber incidents with a fast-paced decision-making focus.

Cyber Security

Linux

MacOS

SQL

🕒 May 6

meteocontrol

201 - 500

💼 Consulting

📦 Logistics

⚡ Energy

OT Security Architect designing security architectures for renewable energy power plants. Supporting customer projects and compliance with international security standards and regulations.

Cyber Security

🕒 May 6

meteocontrol

201 - 500

💼 Consulting

📦 Logistics

⚡ Energy

OT Security Engineer implementing security solutions for renewable energy projects. Collaborating across technical teams to enhance security measures and discuss security topics with customers and suppliers.

Cyber Security

Firewalls

🕒 April 23

Smart Working

51 - 200

💼 Consulting

🏥 Healthcare

📣 Marketing

Senior Security Engineer designing and implementing security controls across applications and services. Collaborating with teams to enhance security practices in a remote-first environment.

Cloud

Docker

Kubernetes

SDLC