
Senior Cybersecurity Risk Analyst
- Remote
- Cluj-Napoca, Cluj, Romania
- Bucuresti, București, Romania
- Iasi, Iași, Romania
+2 more- cyber
Job description
Yopeso has been developing a diverse range of software products, from large-scale applications to smaller solutions, for 19 years. With a growing team of over 250 employees across five locations, we are dedicated to fostering a culture of growth, transparency, and professionalism.
At Yopeso, we value authenticity, curiosity, and ambition. These values drive us to build strong connections within our community and with our partners, ensuring trust, integrity, and transparency in all our business practices. We strive to maintain the highest professional standards and continuously challenge ourselves to develop high-quality, high-performance, and secure software solutions.
Our approach is rooted in efficient collaboration among passionate professionals working in agile teams. Guided by curiosity and ambition, we strive to create products that are meaningful and impactful, while remaining true to our authentic selves.
What we offer:
Competitive remuneration
Remote work
24 days off per year and floating days
Private clinic health services, Regina Maria Medical Insurance
Flexible benefits through Up multibenefits platform
Referral bonus scheme
Team events, online or at the office
Training and development opportunities with allocated budget
Professional Certifications
Knowledge sharing context
Job requirements
As a Cybersecurity Risk Analyst, you will play a crucial role in conducting Threat and Risk Assessments (TRA) for a wide range of Grid Solutions projects, including R&D initiatives, product development (hardware & software), and full-scope critical infrastructure systems such as HVDC, HVAC, Firefighting, and more.
By identifying, assessing, and prioritizing cybersecurity risks, you will collaborate with various teams to ensure that potential threats are detected early and that appropriate mitigation measures are implemented. Your work will contribute directly to improving project execution, security compliance, and market readiness.
How You’ll Make an Impact
Providing threat & risk analysis as a service: Planning and performing Cybersecurity Threat and Risk Analyses for IT and OT systems and products across Grid Solutions projects.
Identifying and prioritizing risks: Identifying, evaluating, and prioritizing cybersecurity risks across projects and systems; assessing risk scenarios, attack vectors, and attacker types along exposure, exploitability, impact, inherent and residual risk.
Moderating TRA workshops: Facilitating threat and risk analysis workshops together with senior project members and security specialists as TRA moderator.
Tracking mitigation and residual risk: Recommending risk-based measures, tracking mitigation, and ensuring residual risks are formally reviewed and accepted.
Maintaining risk transparency: Producing and maintaining the Threat and Risk Analysis, Security Risk Register, and risk treatment documentation to ensure traceability, compliance, and audit readiness.
Strengthening the methodology: Continuously improving the TRA process, templates, workflows and tooling (e.g., the PSS Threat and Risk Tool).
Supporting projects and engineering teams: Sharing identified risks and possible countermeasures with project and engineering teams as input for their decisions.
Ensuring compliance: Translating relevant standards and regulations into practical risk work (e.g., IEC 62443, CRA, NIS-2, NERC CIP, BDEW Whitepaper).
What You Bring
Experience in risk analysis: At least 5 years in cybersecurity, with a minimum of 3 years focused on threat and risk assessment, threat modeling, and risk prioritization. Titles vary (security architect, product security engineer, TARA analyst, OT security consultant). What matters is that you have owned risk assessments end-to-end, not only contributed to them;
Applied standards experience: Hands-on experience applying a structured risk assessment standard such as IEC 62443, ISO 21434, ISO 27005, or EN 50701. Direct 62443 experience is a strong plus. If you bring the method from an adjacent domain, we support the transition;
Operational environment understanding: Understanding of embedded, safety-critical, or operational environments where availability and integrity take precedence over confidentiality, and where patching and downtime are constrained. Direct ICS/OT experience is preferred; automotive, rail, medical device, or industrial product security is equally relevant;
Workshop facilitation: Ability to moderate TRA workshops and align multidisciplinary stakeholders from project, engineering, and security;
Documentation discipline: Demonstrated rigour in maintaining a security risk register with full traceability from risk to treatment to formally accepted residual risk;
Analytical mindset: Strong, structured way of working; able to translate technical detail into clear, prioritized risk statements;
Communication skills: Proficient in English, with a high level of initiative and the ability to communicate risk to technical and non-technical stakeholders;
Completed studies: A technical degree in IT Security, Computer Science, Electrical Engineering, or a related field. Equivalent professional experience is equally acceptable.
Nice to Have
Direct experience with IEC 62443-3-2 and -3-3;
Familiarity with NERC CIP (relevant for North American projects) or the BDEW Whitepaper (relevant for the German-speaking market);
Knowledge of industrial protocols and architectures: IEC 61850, IEC 60870-5-104, DNP3, Modbus, the Purdue model;
Certifications such as ISA/IEC 62443, GICSP, CEH, or CySA+. No hard requirement, and we support certification if you do not have one yet.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.