Senior Cybersecurity Risk Analyst

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Yopeso

Yopeso

201 - 500 employees

🤝 B2B

🏢 Enterprise

☁️ SaaS

B2B • Enterprise • SaaS

Yopeso is a company specializing in crafting bespoke software products that drive business forward. With over 19 years of experience and more than 300 successful projects, Yopeso provides comprehensive services in web and mobile development, UX/UI design, DevOps & cloud, and quality assurance, among others. They cater to diverse industries and pride themselves on their customized approach, ensuring collaboration from ideation to execution. Yopeso's team of over 250 professionals is dedicated to delivering innovative, reliable, and high-performance digital solutions worldwide.

📋 Description

• Plan and perform Cybersecurity Threat and Risk Analyses for IT and OT systems and products across Grid Solutions projects. • Identify, evaluate, and prioritize cybersecurity risks, including risk scenarios, attack vectors, attacker types, exposure, exploitability, impact, inherent risk, and residual risk. • Facilitate threat and risk analysis workshops with senior project members and security specialists as TRA moderator. • Recommend risk-based measures, track mitigation, and ensure residual risks are formally reviewed and accepted. • Produce and maintain Threat and Risk Analyses, Security Risk Registers, and risk treatment documentation for traceability, compliance, and audit readiness. • Improve TRA processes, templates, workflows, and tooling such as the PSS Threat and Risk Tool. • Share identified risks and countermeasures with project and engineering teams. • Translate relevant standards and regulations into practical risk work, including IEC 62443, CRA, NIS-2, NERC CIP, and the BDEW Whitepaper. • Contribute to project execution, security compliance, and market readiness for Grid Solutions projects, including R&D, hardware and software products, and critical infrastructure systems.

🎯 Requirements

• At least 5 years in cybersecurity, with a minimum of 3 years focused on threat and risk assessment, threat modeling, and risk prioritization • End-to-end ownership of risk assessments • Hands-on experience applying a structured risk assessment standard such as IEC 62443, ISO 21434, ISO 27005, or EN 50701 • Understanding of embedded, safety-critical, or operational environments where availability and integrity take precedence over confidentiality • Ability to moderate TRA workshops and align multidisciplinary project, engineering, and security stakeholders • Demonstrated rigour in maintaining a security risk register with full traceability from risk to treatment to formally accepted residual risk • Strong, structured analytical approach and ability to translate technical detail into clear, prioritized risk statements • Proficient in English • High level of initiative and ability to communicate risk to technical and non-technical stakeholders • A technical degree in IT Security, Computer Science, Electrical Engineering, or a related field, or equivalent professional experience • Direct ICS/OT experience is preferred; automotive, rail, medical device, or industrial product security experience is relevant • Direct experience with IEC 62443-3-2 and -3-3 is nice to have • Familiarity with NERC CIP or the BDEW Whitepaper is nice to have • Knowledge of industrial protocols and architectures: IEC 61850, IEC 60870-5-104, DNP3, Modbus, and the Purdue model is nice to have • Certifications such as ISA/IEC 62443, GICSP, CEH, or CySA+ are nice to have; no hard requirement

🏖️ Benefits

• Competitive remuneration • Remote work • 24 days off per year and floating days • Private clinic health services, Regina Maria Medical Insurance • Flexible benefits through Up multibenefits platform • Referral bonus scheme • Team events, online or at the office • Training and development opportunities with allocated budget • Professional Certifications • Knowledge sharing context • Certification support if needed

Apply Now

Similar Jobs

🕒 August 6

Inetum

10,000+ employees

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Integration Security & Access Governance Engineer strengthening enterprise access controls at Inetum, a European digital services leader. Remediating SoD issues and governing emergency, production, and ERP integration access.

ERP

🕒 July 9

ESA - Electronic Security Association

11 - 50

🔐 Security

📋 Compliance

Lead Cyber Security Architect driving innovation in security architecture at Resideo. Collaborating with teams to embed security across technology landscape and monitor emerging threats.

Cyber Security

🕒 June 25

Sophos

1001 - 5000

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

Senior Incident Response Analyst supporting Managed Detection and Response customers at Sophos. Leading investigation efforts on active cyber incidents with a fast-paced decision-making focus.

Cyber Security

Linux

MacOS

SQL

🕒 June 22

SAP Fioneer

501 - 1000

💼 Consulting

🛡️ Insurance

📦 Logistics

Data Security Engineer responsible for data security controls and compliance in cloud platforms. Collaborating with cross-functional teams at SAP Fioneer to enhance data protection capabilities.

Cloud

Python

🕒 May 6

meteocontrol

201 - 500

💼 Consulting

📦 Logistics

⚡ Energy

OT Security Architect designing security architectures for renewable energy power plants. Supporting customer projects and compliance with international security standards and regulations.

Cyber Security