Cloud Cyber Risk Analyst
Location: Lisbon | Porto
Level of Experience: Mid (3 to 6 years)
Salary Package & Benefits: €1,200 to €2,000 (salary base) + Food Allowance + Flex Benefits
Main Tasks
1. Cloud security perimeter through Software as a Service (SaaS) & Third-Party usages
- Active participation in (cloud) third party onboarding studies (risk assessment, review of cases studies, …)
- Active participation to governance/organization topics on third party cases
- Active participation to ensure third party cybersecurity governance is in place and follow‑up third party cybersecurity governance in the run
- Contribution to the committees on the studied cases
2. Cyber Risk assessments support for the Cloud Maturity Assurance Team (CMAT)/Task Force topics
- Understand risk assessments already produced (based on ISO 27005/EBIOS Risk Manager) and impacts of remediations plans progresses on risks.
- Skills to follow up/challenge remediation plans implemented by service providers or entities.
- Contribute actively to risk assessments of cloud platforms and cloud applications.
3. Other activities
- Contribute to maintain cloud cybersecurity risk in tools when necessary
- Contribute to governance/organization topics related to the team
Technical Skills
- Minimum of 5 years of experience in cybersecurity (certification ISO 27001 Lead Implementor or Auditor appreciated)
- Risk management methodologies skills based on ISO 27005 and/or EBIOS Risk Manager (certification ISO 27005 Risk Manager and/or EBIOS Risk Manager appreciated)
- Knowledge of a risk management related to third party cloud services appreciated.
- Knowledge on Cloud specific Cyber Security appreciated (such as SOC2, CSA, ISO27017)
- Knowledge on Cyber Security control frameworks appreciated (such as NIST, CIS)
- Knowledge in project management would be appreciated.
- Excellent written and verbal communication skills.
- Collaborative skills, and the ability to communicate information.