
Cybersecurity Risk Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Romania.
• Delivering threat and risk analysis as a service: Planning and executing Cybersecurity Threat and Risk Analyses for IT and OT systems and products within Grid Solutions projects.
• Risk identification and prioritization: Recognizing, assessing, and prioritizing cybersecurity risks across various projects and systems; analyzing risk scenarios, attack vectors, and types of attackers based on exposure, exploitability, impact, inherent, and residual risk.
• Moderating TRA workshops: Leading threat and risk analysis workshops in collaboration with senior project members and security experts as the TRA facilitator.
• Monitoring mitigation and residual risk: Suggesting risk-based strategies, monitoring mitigation efforts, and ensuring that residual risks are properly reviewed and accepted.
• Ensuring risk transparency: Generating and maintaining the Threat and Risk Analysis, Security Risk Register, and risk treatment documentation to guarantee traceability, compliance, and readiness for audits.
• Enhancing the methodology: Ongoing improvement of the TRA process, templates, workflows, and tools (e.g., the PSS Threat and Risk Tool).
• Assisting projects and engineering teams: Communicating identified risks and potential countermeasures to project and engineering teams to inform their decision-making.
• Compliance assurance: Converting relevant standards and regulations into actionable risk management practices (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).
• Educational background: Bachelor’s or Master’s degree in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or an equivalent qualification with pertinent professional experience.
• Risk analysis expertise: Proven experience in cybersecurity threat and risk assessment, threat modeling, and risk prioritization in OT or product security.
• Standards knowledge: Familiarity with ISA/IEC 62443 (particularly risk assessment, 62443-3-2/-3-3) and other standards such as CRA, NIS-2, NERC CIP, BDEW Whitepaper, ISO 27001/27005.
• Understanding of OT/ICS: Insight into industrial control systems, network architectures, and protocols, along with an understanding of how security risks arise in operational settings.
• Workshop facilitation skills: Capability to moderate TRA workshops and align diverse stakeholders from project, engineering, and security domains.
• Analytical approach: Strong analytical mindset and structured working style; proficient in translating technical details into concise, prioritized risk statements.
• Communication proficiency: Fluent in English, demonstrating a high level of initiative and the ability to convey risks to both technical and non-technical stakeholders (German language skills are a plus).
• Preferred certifications: Certifications such as ISA/IEC 62443, CEH, CySA+, or similar are advantageous (not mandatory).
• Competitive salary
• Option for remote work
• 24 vacation days per year plus floating holidays
• Access to private clinic health services, Regina Maria Medical Insurance
• Flexible benefits through the Up multibenefits platform
• Referral bonus program
• Team-building events, either online or in the office
• Training and development opportunities with an allocated budget
• Professional certifications supported
• Knowledge sharing context
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.