Skip to content

Cybersecurity Risk Analyst - Moldova

  • Remote
    • Chisinau, Chișinău, Moldova, Republic of
  • cyber

Job description

Yopeso has been developing a diverse range of software products, from large-scale applications to smaller solutions, for 20 years. With a growing team of over 300 employees across five locations, we are dedicated to fostering a culture of growth, transparency, and professionalism.

At Yopeso, we value authenticity, curiosity, and ambition. These values drive us to build strong connections within our community and with our partners, ensuring trust, integrity, and transparency in all our business practices. We strive to maintain the highest professional standards and continuously challenge ourselves to develop high-quality, high-performance, and secure software solutions.

Our approach is rooted in efficient collaboration among passionate professionals working in agile teams. Guided by curiosity and ambition, we strive to create products that are meaningful and impactful, while remaining true to our authentic selves.

What we offer:

  • Competitive remuneration

  • Remote work

  • Sports/leisure benefit

  • 20 sick leave days paid at 100%

  • 32 calendar days of vacation

  • Team events, online, at the office, or outside

  • Professional development plan with guidance and mentorship

  • Training and development opportunities with an allocated budget

  • Professional Certifications

  • Optional medical insurance

Job requirements

As a Cybersecurity Risk Analyst, you will play a crucial role in conducting Threat and Risk Assessments (TRA) for a wide range of Grid Solutions projects, including R&D initiatives, product development (hardware & software), and full-scope critical infrastructure systems such as HVDC, HVAC, Firefighting, and more.

By identifying, assessing, and prioritizing cybersecurity risks, you will collaborate with various teams to ensure that potential threats are detected early and that appropriate mitigation measures are implemented. Your work will contribute directly to improving project execution, security compliance, and market readiness.

How You’ll Make an Impact

  • Providing threat & risk analysis as a service: Planning and performing Cybersecurity Threat and Risk Analyses for IT and OT systems and products across Grid Solutions projects.

  • Identifying and prioritizing risks: Identifying, evaluating, and prioritizing cybersecurity risks across projects and systems; assessing risk scenarios, attack vectors, and attacker types along exposure, exploitability, impact, inherent and residual risk.

  • Moderating TRA workshops: Facilitating threat and risk analysis workshops together with senior project members and security specialists as TRA moderator.

  • Tracking mitigation and residual risk: Recommending risk-based measures, tracking mitigation, and ensuring residual risks are formally reviewed and accepted.

  • Maintaining risk transparency: Producing and maintaining the Threat and Risk Analysis, Security Risk Register and risk treatment documentation to ensure traceability, compliance and audit readiness.

  • Strengthening the methodology: Continuously improving the TRA process, templates, workflows and tooling (e.g., the PSS Threat and Risk Tool).

  • Supporting projects and engineering teams: Sharing identified risks and possible countermeasures with project and engineering teams as input for their decisions.

  • Ensuring compliance: Translating relevant standards and regulations into practical risk work (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).

What You Bring

  • Completed studies: Bachelor or Master in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or a comparable qualification with relevant professional experience.

  • Expertise in risk analysis: Experience in cybersecurity threat and risk assessment, threat modeling and risk prioritization in OT or product security.

  • Knowledge of standards: Familiarity with ISA/IEC 62443 (especially risk assessment, 62443-3-2/-3-3), and others such as CRA, NIS-2, NERC CIP, BDEW Whitepaper, ISO 27001/27005.

  • OT/ICS understanding: Understanding of industrial control systems, network architectures and protocols, and how security risks manifest in operational environments.

  • Workshop facilitation: Ability to moderate TRA workshops and align multidisciplinary stakeholders from project, engineering, and security.

  • Analytical mindset: Strong analytical and structured way of working; able to translate technical detail into clear, prioritized risk statements.

  • Communication skills: Proficient in English, with a high level of initiative and the ability to communicate risk to technical and non-technical stakeholders (German is a plus).

  • Desirable certifications: Certifications such as ISA/IEC 62443, CEH, CySA+, or similar are a plus (no hard requirement).

or