Are you an experienced Cybersecurity Risk Manager with a strong background in ICT security risk assessment, governance, and compliance?
This role offers a unique opportunity to contribute to the protection of critical ICT systems, including environments processing sensitive and classified information.
You will be joining a highly specialised security environment where your expertise will directly contribute to strengthening cybersecurity resilience, governance, and risk management across critical European ICT services.
- analyse cybersecurity threats and attacker profiles
- conduct ICT security risk assessments using ITSRM2, EBIOS, MAGERIT, PILAR, FENCE, and similar tools
- develop and maintain security policies, procedures, and guidance
- assess and improve cybersecurity processes, standards, tools, and organisational maturity
- provide cybersecurity guidance and training to ICT teams
- advise on Secure SDLC, security-by-design, and security-by-default
- support threat modelling and define technical security requirements
- perform or support code reviews and application security assessments
- advise on cloud and AI security controls
- support risk identification, mitigation, treatment, and monitoring
- contribute to business continuity, governance, compliance, reporting, and stakeholder engagement
- assess and manage third-party and supplier security risks
- experience in cybersecurity risk management or a similar role
- strong expertise in ICT risk management, governance, and security assurance
- experience with ITSRM2, EBIOS, MAGERIT, or similar risk methodologies
- experience developing cybersecurity policies, standards, and procedures
- ability to advise both technical and non-technical stakeholders
- experience with sensitive or classified information is an advantage
Technical knowledge ("must have"):
- cybersecurity risk assessment methodologies (ITSRM2, EBIOS, MAGERIT)
- security risk assessment tools such as PILAR, FENCE, or equivalent solutions
- information security and personal data protection principles
- security governance, risk management, and compliance frameworks
- secure SDLC and security-by-design principles
- threat modelling methodologies
- technical security requirements definition and implementation
- code security review practices
- cloud security controls
- AI security controls
Professional Certifications (at least four are mandatory):
- Experience working with systems handling EU Classified Information (EUCI)
- Active and valid CONFIDENTIEL UE / EU CONFIDENTIAL clearance