5 дней назад
Industrial Cybersecurity Risk Analyst (OT Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Industrial Cybersecurity Risk Analyst (OT Security): Conducting and documenting Cybersecurity Threat and Risk Analyses for IT and OT systems, products, and architectures across Grid Solutions with an accent on threat modeling, risk prioritization, and compliance with IEC 62443, CRA, NIS2, and NERC CIP. Focus on moderating TRA workshops, translating complex technical findings into actionable mitigation strategies, and managing residual risk acceptance throughout the project lifecycle.
Location: Bucharest, Romania — hybrid remote/office
Company
develops energy technologies and grid solutions for reliable, sustainable, and digital power infrastructure across more than 90 countries.
What you will do
- Plan, conduct, and document Cybersecurity Threat and Risk Analyses for IT and OT systems, products, architectures, and components.
- Identify, evaluate, and prioritize risks by analyzing threat scenarios, attack vectors, threat actors, exposure, exploitability, impact, and residual risk.
- Lead and moderate TRA workshops with project stakeholders, subject matter experts, engineers, and cybersecurity specialists.
- Recommend risk-based mitigation strategies, monitor their implementation, and manage formal residual risk acceptance.
- Maintain risk registers, TRA documentation, and risk treatment records for traceability, compliance, and audit readiness.
- Improve TRA methodologies, workflows, templates, tools, and secure-by-design practices while advising project and R&D teams.
Requirements
- University degree in IT security, computer science, cybersecurity, electronics, electrical engineering with an IT security focus, or comparable professional experience in OT or product security.
- Experience in cybersecurity threat and risk assessment, threat modeling, and risk prioritization in OT or product security.
- Solid knowledge of IEC 62443, CRA, NERC CIP, BDEW Whitepaper, ISO 27001, and ISO 27005.
- Understanding of industrial control systems, network architectures, protocols, and security risks in operational environments.
- Experience facilitating TRA workshops and engaging multidisciplinary project, engineering, and cybersecurity stakeholders.
- Business-level English is required; German is beneficial. Willingness to travel internationally for less than 30% of the time is expected.
Nice to have
- ISA/IEC 62443, CEH, CySA+, or similar certification.
- German-language skills.
Culture & Benefits
- Work in a cross-border cybersecurity team with colleagues from around the world.
- Access training, personal development, and career growth opportunities.
- Meal tickets, medical subscription, private pension plan, wellbeing initiatives, and Bookster book benefits.
- Work from ’s One Cotroceni Park office in central Bucharest as part of a hybrid setup.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
IT Security Analyst - Senior (Vulnerability Management)
6 дней назад
Senior IT Security Engineer (AI/ML Security)
3 дня назад
Quality Manager (Identity and Access Management)
5 дней назад
Staff Security Engineer (SecOps & Threat)
4 дня назад
SOX IT Specialist (Fintech)
4 дня назад