This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cyber Risk Analysts will work under the guidance of the Lead Consultant to execute the detailed risk assessments and analysis of End-of-Life technologies. In this role, you will collect and analyse data on EOL systems, evaluate cyber risks using the defined methodology, and support the implementation of remediation plans. The analysts serve as the backbone of the risk assessment, performing hands-on evaluation of assets and vulnerabilities and ensuring that risk documentation and tracking are maintained. Two Analyst positions are open, and both will collaborate closely with the Lead and with various technology teams. This role requires strong analytical skills, attention to detail, and a proactive approach to managing cyber risks across a range of legacy technologies.
Job Responsibility:
Perform Risk Assessments: Conduct in-depth cyber risk assessments for identified EOL systems and technologies
Apply Risk Methodology: Use the new cyber risk rating methodology to calculate risk scores or levels for each EOL asset or vulnerability
Identify Mitigations: Work with the team to identify risk mitigation options for each high-risk finding
Remediation Support: Support the prioritization and remediation of EOL risks by coordinating with technical teams
Monitor & Report: Continuously monitor risk treatment plans and ensure that remediation steps are completed or on track
Stakeholder Collaboration: Engage with various stakeholders at a working level
Process Improvement: Contribute to developing templates, checklists, or process improvements as the project progresses
Requirements:
Strong analytical and problem-solving skills
Attention to detail
Good understanding of foundational cybersecurity principles (confidentiality, integrity, availability)
Familiarity with common vulnerabilities and exploits affecting older systems
Knowledge of cyber risk frameworks and standards (such as NIST, ISO27001)
Ability to work with various technology inventories and tools
Comfort with spreadsheets, databases, or GRC tools
Solid written and verbal communication skills
Collaborative mindset
Good organizational skills
Adaptability
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field
Equivalent experience in cyber risk or IT security roles can be considered in lieu of a formal degree
Nice to have:
Relevant industry certifications (e.g., CompTIA Security+, Certified Ethical Hacker (CEH), GIAC/GSEC, CRISC, Certified Information Systems Auditor (CISA), ISO 27001 Lead Auditor/Implementer)
Any training or courses in cyber risk analysis, enterprise risk management, or IT audit
Knowledge of internal risk systems or financial industry compliance standards
Some experience with vulnerability scanning tools or reading vulnerability advisories