Cybersecurity Analyst
Risk-Based Cybersecurity Assessments
Perform risk-based cybersecurity assessments using the NIST Cybersecurity Framework.
Threat Modeling
Conduct Threat Modeling to identify and evaluate cybersecurity risks.
Vulnerability Management
Review vulnerability information and assess risk impact, exploitability, and residual risk.
Risk Treatment Documentation
Maintain and update vulnerability risk registers and risk treatment documentation.
Evaluation of Security Controls
Evaluate the adequacy of existing security controls (e.g., access controls, encryption, vulnerability management, logging) as a part of assessments.
Documentation
Document assessment results clearly and support risk-based decision making.
Collaboration
Collaborate with system owners and stakeholders to gather evidence and clarify system context.
Continuous Improvement
Support management in the continuous improvement of cybersecurity strategies, policies, and standards to safeguard company information, systems, and technology assets.
Skills & Requirements
- Proven experience with a wide range of information security processes and principles, including but not limited to risk assessments, threat modeling, risk analysis, and defense in depth.
- Practical understanding of NIST CSF, NIS2 EU Directive and risk-based security principles.
- Strong capability in identifying, analyzing, and mitigating cybersecurity threats using a risk driven approach.
- Solid and broad cybersecurity background, including strong knowledge of regulatory requirements and industry best practices.
- Strong analytical, communication and documentation skills, with ability to collaborate effectively with diverse teams.
- Self-driven and proactive, with a demonstrated ability to take initiative and work independently.
- Experience using Microsoft Office 365 tools, including Excel, PowerPoint, Word, and Power BI.
Education/ Certifications
- Master's degree in Cybersecurity (preferred)
- Master's degree in computer science or related technical discipline (second preference)
- Bachelor's degree in cybersecurity or related field (third preference)
- CompTIA Security+ (preferred / nice to have)
- Other relevant cybersecurity certifications related to risk management or frameworks (optional)