EU remote
CyberSecurity Risk Manager
About this role
Develop and maintain the organisation’s cybersecurity risk management strategy Conduct cybersecurity risk assessments and analyses to identify threats, categorise assets, assess vulnerabilities, and recommend risk treatment options Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems and maintain awareness of the evolving threat landscape Perform Business Impact Assessments and support cybersecurity risk-based decision making Design, implement, monitor, and evaluate cybersecurity controls to ensure risks remain at acceptable levels Implement and maintain cybersecurity risk management frameworks, methodologies, standards, and best practices Support compliance with security, risk, governance, and regulatory requirements Enable business stakeholders, asset owners, and executives to make risk-informed decisions Promote a cybersecurity risk-aware culture across the organisation Develop and maintain cybersecurity risk registers, reports, metrics, and documentation Support threat modelling activities for systems, applications, and DevOps environments Contribute to the design of Zero Trust Architecture and security controls for critical enterprise services, including Directory Services Support personal data protection and information security governance initiatives Communicate risk management activities, findings, and recommendations to relevant stakeholders Minimum 9 years of relevant IT professional experience, with at least 6 years in a cybersecurity risk management, information security governance, cybersecurity architecture, or similar role.
Minimum education level: Level 7 (Master's degree or equivalent) in an ICT-relevant field. At least 4 of the following certifications: CISA (Certified Information Systems Auditor) CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) CISSP (Certified Information Systems Security Professional) CGRC (Certified in Governance, Risk and Compliance) CSSLP (Certified Secure Software Lifecycle Professional) CCSP (Certified Cloud Security Professional) CISSP-ISSMP (Certified Information Systems Security Management Professional) GSNA (GIAC Certified Systems and Network Auditor) GCCC (GIAC Certified Critical Controls) GIAC Certified ISO-27000 Specialist ISO 27001 Lead Implementer ISO 27001 Lead Auditor ISO 27005 Risk Manager or equivalent, internationally recognized certification Excellent verbal and written communication in English, C1+ certificate desirable Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, tools, best practices, cyber threats, threat taxonomies, vulnerabilities, risk assessment methodologies, risk treatment strategies, and security controls.