For a client in Namur, we are looking for a Risk Analyst.
Project start and end dates: 03/11/2026 - 30/11/2027
Location: Namur, with a presence required in our offices at least 60% of the time.
Required languages: English, French
Main mission:
Assess, prioritize and trace the cyber risks related to industrial systems and their IT dependencies present on public infrastructure and recommend appropriate treatment measures.
Key activities:
- Mapping & inventory: Identify OT assets and their IT dependencies. Identify the SPOFs.
- Operational risk analysis: Apply the methodology to model threats, vulnerabilities and impacts. Use concrete scenarios based on feedback.
- Treatment plan & prioritization: Develop the action implementation plan to address the risks analyzed. Quantify the cost/impact and develop a risk reduction roadmap.
- Project & Contract Integration: Draft the IT/OT security clauses in the specifications. Check the compliance of critical OT suppliers.
- IT/OT & SOC Synergy: Translate OT risks into logging requirements and detection rules for the SOC.
- Resilience & exercises: Participate in restoration tests and OT/IT table-top exercises. Contribute to feedback and continuous improvement of service continuity plans.
- Reporting & Governance: Maintain the OT risk register, prepare summaries for the Cyber Committee and for NIS2 audits.
Examples of deliverables:
- Service continuity plan and restoration plan after disaster.
- Detailed inventory of OT assets & IT dependencies.
- OT risk register with scoring, scenarios, owners, and deadlines.
- Zone & duct mapping + flow diagrams.
- Prioritized treatment plan.
- Security requirements grids for OT purchases/modernizations.
- Quarterly reports to the Coordinator.
Expected behavioral skills:
- Assertiveness and the ability to be proactive.
- Autonomy and appreciation of teamwork.
- Very good communicator, customer oriented and results.
- Positive and caring attitude, active listening.
- Capacity for pedagogy and popularization of technical aspects.
- Rigorous and methodical.
Technical skills required:
- Communication & influence.
- Knowledge of industrial communication protocols.
- Knowledge of control systems.
- Cybersecurity framework.
- Risk management methodologies.
- Information security standards and repositories.
- GRC tools & reporting.