
Senior Cybersecurity Risk Analyst
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Romania.
• Plan and execute Cybersecurity Threat and Risk Analyses for IT and OT systems and products within Grid Solutions projects.
• Identify, assess, and prioritize cybersecurity risks, including risk scenarios, attack vectors, types of attackers, exposure, exploitability, impact, inherent risk, and residual risk.
• Lead threat and risk analysis workshops as the TRA moderator, collaborating with senior project members and security specialists.
• Suggest risk-based measures, monitor mitigation efforts, and ensure that residual risks are formally reviewed and accepted.
• Create and sustain Threat and Risk Analyses, Security Risk Registers, and risk treatment documentation to ensure traceability, compliance, and readiness for audits.
• Enhance TRA processes, templates, workflows, and tools, including the PSS Threat and Risk Tool.
• Communicate identified risks and countermeasures to project and engineering teams.
• Interpret relevant standards and regulations into actionable risk work, including IEC 62443, CRA, NIS-2, NERC CIP, and the BDEW Whitepaper.
• Contribute to the execution of projects, security compliance, and market readiness for Grid Solutions initiatives, encompassing R&D, hardware and software products, and critical infrastructure systems.
• A minimum of 5 years of experience in cybersecurity, with at least 3 years dedicated to threat and risk assessment, threat modeling, and risk prioritization.
• Complete ownership of risk assessments from start to finish.
• Practical experience in applying a structured risk assessment framework such as IEC 62443, ISO 21434, ISO 27005, or EN 50701.
• Familiarity with embedded, safety-critical, or operational environments where availability and integrity are prioritized over confidentiality.
• Capability to moderate TRA workshops and align diverse project, engineering, and security stakeholders.
• Proven commitment to maintaining a security risk register with full traceability from risk identification to treatment and formally accepted residual risk.
• Strong analytical skills and the ability to translate technical details into clear, prioritized risk statements.
• Proficient in English.
• High initiative and the ability to convey risk to both technical and non-technical stakeholders.
• A technical degree in IT Security, Computer Science, Electrical Engineering, or a related field, or equivalent professional experience.
• Direct experience with ICS/OT is preferred; experience in automotive, rail, medical device, or industrial product security is relevant.
• Familiarity with IEC 62443-3-2 and -3-3 is advantageous.
• Knowledge of NERC CIP or the BDEW Whitepaper is a plus.
• Understanding of industrial protocols and architectures: IEC 61850, IEC 60870-5-104, DNP3, Modbus, and the Purdue model is beneficial.
• Certifications such as ISA/IEC 62443, GICSP, CEH, or CySA+ are advantageous but not mandatory.
• Competitive salary.
• Option for remote work.
• 24 days of vacation annually, plus floating days.
• Access to private clinic health services via Regina Maria Medical Insurance.
• Flexible benefits available through the Up multibenefits platform.
• Referral bonus program.
• Team-building events, both online and in-office.
• Training and development opportunities with a dedicated budget.
• Support for professional certifications.
• Knowledge-sharing environment.
• Certification assistance as needed.
GitLab
GitLab
Cisco
Lovesac
Get handpicked remote jobs straight to your inbox weekly.