Risk Analyst

Il y a 1 semaine

Namen, Namen, Belgique V-IT NV Temps plein 65 000 € - 90 000 € Contrat

For a client in Namur, we are looking for a Risk Analyst.

Project start and end dates: 03/11/2026 - 30/11/2027

Location: Namur, with a presence required in our offices at least 60% of the time.

Required languages: English, French

Main mission:

Assess, prioritize and trace the cyber risks related to industrial systems and their IT dependencies present on public infrastructure and recommend appropriate treatment measures.

Key activities:

  • Mapping & inventory: Identify OT assets and their IT dependencies. Identify the SPOFs.
  • Operational risk analysis: Apply the methodology to model threats, vulnerabilities and impacts. Use concrete scenarios based on feedback.
  • Treatment plan & prioritization: Develop the action implementation plan to address the risks analyzed. Quantify the cost/impact and develop a risk reduction roadmap.
  • Project & Contract Integration: Draft the IT/OT security clauses in the specifications. Check the compliance of critical OT suppliers.
  • IT/OT & SOC Synergy: Translate OT risks into logging requirements and detection rules for the SOC.
  • Resilience & exercises: Participate in restoration tests and OT/IT table-top exercises. Contribute to feedback and continuous improvement of service continuity plans.
  • Reporting & Governance: Maintain the OT risk register, prepare summaries for the Cyber Committee and for NIS2 audits.

Examples of deliverables:

  • Service continuity plan and restoration plan after disaster.
  • Detailed inventory of OT assets & IT dependencies.
  • OT risk register with scoring, scenarios, owners, and deadlines.
  • Zone & duct mapping + flow diagrams.
  • Prioritized treatment plan.
  • Security requirements grids for OT purchases/modernizations.
  • Quarterly reports to the Coordinator.

Expected behavioral skills:

  • Assertiveness and the ability to be proactive.
  • Autonomy and appreciation of teamwork.
  • Very good communicator, customer oriented and results.
  • Positive and caring attitude, active listening.
  • Capacity for pedagogy and popularization of technical aspects.
  • Rigorous and methodical.

Technical skills required:

  • Communication & influence.
  • Knowledge of industrial communication protocols.
  • Knowledge of control systems.
  • Cybersecurity framework.
  • Risk management methodologies.
  • Information security standards and repositories.
  • GRC tools & reporting.