Senior Cybersecurity Risk Analyst

Posted Aug 18

This is a fully remote position, open to applicants in Romania.

📋 Description

• Plan and execute Cybersecurity Threat and Risk Analyses for IT and OT systems and products within Grid Solutions projects.

• Identify, assess, and prioritize cybersecurity risks, including risk scenarios, attack vectors, types of attackers, exposure, exploitability, impact, inherent risk, and residual risk.

• Lead threat and risk analysis workshops as the TRA moderator, collaborating with senior project members and security specialists.

• Suggest risk-based measures, monitor mitigation efforts, and ensure that residual risks are formally reviewed and accepted.

• Create and sustain Threat and Risk Analyses, Security Risk Registers, and risk treatment documentation to ensure traceability, compliance, and readiness for audits.

• Enhance TRA processes, templates, workflows, and tools, including the PSS Threat and Risk Tool.

• Communicate identified risks and countermeasures to project and engineering teams.

• Interpret relevant standards and regulations into actionable risk work, including IEC 62443, CRA, NIS-2, NERC CIP, and the BDEW Whitepaper.

• Contribute to the execution of projects, security compliance, and market readiness for Grid Solutions initiatives, encompassing R&D, hardware and software products, and critical infrastructure systems.


⛳️ Requirements

• A minimum of 5 years of experience in cybersecurity, with at least 3 years dedicated to threat and risk assessment, threat modeling, and risk prioritization.

• Complete ownership of risk assessments from start to finish.

• Practical experience in applying a structured risk assessment framework such as IEC 62443, ISO 21434, ISO 27005, or EN 50701.

• Familiarity with embedded, safety-critical, or operational environments where availability and integrity are prioritized over confidentiality.

• Capability to moderate TRA workshops and align diverse project, engineering, and security stakeholders.

• Proven commitment to maintaining a security risk register with full traceability from risk identification to treatment and formally accepted residual risk.

• Strong analytical skills and the ability to translate technical details into clear, prioritized risk statements.

• Proficient in English.

• High initiative and the ability to convey risk to both technical and non-technical stakeholders.

• A technical degree in IT Security, Computer Science, Electrical Engineering, or a related field, or equivalent professional experience.

• Direct experience with ICS/OT is preferred; experience in automotive, rail, medical device, or industrial product security is relevant.

• Familiarity with IEC 62443-3-2 and -3-3 is advantageous.

• Knowledge of NERC CIP or the BDEW Whitepaper is a plus.

• Understanding of industrial protocols and architectures: IEC 61850, IEC 60870-5-104, DNP3, Modbus, and the Purdue model is beneficial.

• Certifications such as ISA/IEC 62443, GICSP, CEH, or CySA+ are advantageous but not mandatory.


🏝️ Benefits

• Competitive salary.

• Option for remote work.

• 24 days of vacation annually, plus floating days.

• Access to private clinic health services via Regina Maria Medical Insurance.

• Flexible benefits available through the Up multibenefits platform.

• Referral bonus program.

• Team-building events, both online and in-office.

• Training and development opportunities with a dedicated budget.

• Support for professional certifications.

• Knowledge-sharing environment.

• Certification assistance as needed.

People also viewed

GitLab1 day ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job
GitLab1 day ago

Principal Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$203.2k – $275k/year
ApplyView job
Cisco1 day ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac1 day ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology1 day ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers