
Cybersecurity Risk Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Moldova.
• Delivering threat and risk analysis as a service: Orchestrating and executing Cybersecurity Threat and Risk Analyses for IT and OT systems and products associated with Grid Solutions projects.
• Risk identification and prioritization: Recognizing, assessing, and prioritizing cybersecurity risks across various projects and systems; evaluating risk scenarios, attack vectors, and types of attackers in relation to exposure, exploitability, impact, inherent, and residual risk.
• Facilitating TRA workshops: Leading threat and risk analysis workshops alongside senior project members and security experts in the role of TRA moderator.
• Monitoring mitigation and residual risk: Suggesting risk-based strategies, overseeing mitigation efforts, and ensuring that residual risks are formally assessed and acknowledged.
• Ensuring risk transparency: Creating and maintaining the Threat and Risk Analysis, Security Risk Register, and risk treatment documentation to uphold traceability, compliance, and audit readiness.
• Enhancing the methodology: Continuously refining the TRA process, templates, workflows, and tools (e.g., the PSS Threat and Risk Tool).
• Assisting projects and engineering teams: Communicating identified risks and potential countermeasures to project and engineering teams to inform their decision-making.
• Guaranteeing compliance: Converting pertinent standards and regulations into actionable risk management practices (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).
• Completed education: Bachelor’s or Master’s degree in IT Security, Computer Science, Electrical Engineering with a concentration in IT Security, or an equivalent qualification with relevant professional experience.
• Risk analysis expertise: Proven experience in cybersecurity threat and risk assessment, threat modeling, and risk prioritization within OT or product security.
• Familiarity with standards: Knowledge of ISA/IEC 62443 (particularly risk assessment, 62443-3-2/-3-3), along with others such as CRA, NIS-2, NERC CIP, BDEW Whitepaper, ISO 27001/27005.
• Understanding of OT/ICS: Comprehension of industrial control systems, network architectures and protocols, and the manifestation of security risks in operational environments.
• Workshop facilitation skills: Capability to moderate TRA workshops and synchronize multidisciplinary stakeholders from project, engineering, and security domains.
• Analytical mindset: Strong analytical and systematic approach; capable of translating technical details into clear, prioritized risk statements.
• Communication proficiency: Fluent in English with a high degree of initiative and the ability to convey risk information to both technical and non-technical stakeholders (German language skills are a plus).
• Preferred certifications: Credentials such as ISA/IEC 62443, CEH, CySA+, or similar are advantageous (not mandatory).
• Competitive remuneration
• Remote work opportunities
• Sports and leisure benefits
• 20 days of sick leave paid at 100%
• 32 days of vacation per calendar year
• Team events, whether online, at the office, or offsite
• Professional development plan with guidance and mentorship
• Training and development opportunities with an allocated budget
• Professional certifications
• Optional medical insurance
NTT
BDR Solutions LLC
ON Partners
Danaher Corporation
Get handpicked remote jobs straight to your inbox weekly.