Yopeso logo
YopesoPosted 1 week ago

Senior Cybersecurity Risk Analyst

Remote

Full TimeSenior LevelSmall

Job Summary

Conduct Threat and Risk Assessments for Grid Solutions projects, including R&D, product development, and critical infrastructure systems like HVDC and HVAC. Identify, evaluate, and prioritize cybersecurity risks across IT and OT systems while facilitating workshops with senior project members and security specialists. Track mitigation measures, maintain security risk registers, and ensure documentation meets audit readiness for standards such as IEC 62443, NIS-2, and NERC CIP. Translate technical details into clear risk statements to support project and engineering teams in making informed decisions.

Required Qualifications

  • At least 5 years in cybersecurity
  • Minimum of 3 years focused on threat and risk assessment, threat modeling, and risk prioritization
  • Experience owning risk assessments end-to-end
  • Hands-on experience applying a structured risk assessment standard such as IEC 62443, ISO 21434, ISO 27005, or EN 50701
  • Understanding of embedded, safety-critical, or operational environments where availability and integrity take precedence over confidentiality, and where patching and downtime are constrained
  • Ability to moderate TRA workshops and align multidisciplinary stakeholders from project, engineering, and security
  • Demonstrated rigour in maintaining a security risk register with full traceability from risk to treatment to formally accepted residual risk
  • Strong, structured way of working; able to translate technical detail into clear, prioritized risk statements
  • Proficient in English, with a high level of initiative and the ability to communicate risk to technical and non-technical stakeholders
  • A technical degree in IT Security, Computer Science, Electrical Engineering, or a related field
  • Equivalent professional experience

Desired Qualifications

  • Direct 62443 experience
  • Direct experience with IEC 62443-3-2 and -3-3
  • Familiarity with NERC CIP (relevant for North American projects) or the BDEW Whitepaper (relevant for the German-speaking market)
  • Knowledge of industrial protocols and architectures: IEC 61850, IEC 60870-5-104, DNP3, Modbus, the Purdue model
  • Certifications such as ISA/IEC 62443, GICSP, CEH, or CySA+
  • Direct ICS/OT experience
  • Automotive, rail, medical device or industrial product security experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce