nexttech
nexttech1d ago
New

Industrial Cybersecurity Risk Analyst

RomaniaRomania·Cluj-NapocaRemotemid
Risk AnalystData & AI
2 views0 saves0 applied

Quick Summary

Overview

About Nexttech Founded in 2015, Nexttech has built a solid foundation in delivering comprehensive IT solutions tailored to meet diverse client needs.

Technical Tools
Risk AnalystData & AI

Founded in 2015, Nexttech has built a solid foundation in delivering comprehensive IT solutions tailored to meet diverse client needs. With expertise spanning five key industry sectors—Banking, Energy, Telecom, Automotive and E-commerce & Logistics—we provide nearshore and onshore services designed to drive efficiency and support strategic growth.

Our team supports every phase of the Software Development Life Cycle (SDLC), from developing detailed roadmaps and resolving complex software challenges to ensuring quick time-to-market and optimized ROI.

• Managed Services: End-to-end support for seamless IT operations.
• Custom Software Development: Tailored solutions to address specific business challenges.
• Team Augmentation: Enhance your in-house capabilities with specialized expertise.
• Nearshoring Services: Collaborative solutions that offer the benefits of proximity and cultural alignment.
• Dedicated Development Teams: Aligned teams committed to your project’s long-term success.
• Quality Assurance & Testing: Ensuring high-quality performance and reliability.
• Consulting and Advisory Services: Expert insights to help navigate complex projects and decisions.

At Nexttech, we take pride in our commitment to client success, fostering trusted partnerships, and delivering solutions that align with each client’s unique goals and vision.

We are looking for an Industrial Cybersecurity Risk Analyst to identify, assess and prioritize cybersecurity risks affecting IT and OT systems, products and architectures used within critical energy infrastructure.

In this role, you will provide Cybersecurity Threat and Risk Analysis as a service across customer and R&D projects. You will facilitate risk assessment workshops, evaluate attack scenarios and translate complex technical findings into clear, actionable mitigation measures.

You will collaborate with project teams, engineering specialists and cybersecurity experts to ensure that risks are transparent, appropriately treated and formally accepted. This is an ideal opportunity for someone with strong expertise in industrial cybersecurity, threat modeling and risk management who enjoys working across multidisciplinary and international environments.

Main tech & standards: #IndustrialCybersecurity #OTSecurity #ICS #ThreatModeling #RiskAssessment #IEC62443 #ISO27001 #ISO27005 #NIS2 #CRA #NERCCIP

Responsibilities

~1 min read

• Plan and perform Cybersecurity Threat and Risk Analyses for IT and OT systems, products, components and architectures
• Support full customer and R&D projects by providing structured cybersecurity risk assessments
• Identify and assess potential attack scenarios, attack vectors, threat actors and system vulnerabilities
• Evaluate exposure, exploitability, business impact, inherent risk and residual risk
• Prioritize cybersecurity risks based on technical severity and business impact

• Plan and facilitate Threat and Risk Analysis workshops with project members, engineering teams and cybersecurity specialists
• Guide multidisciplinary stakeholders through structured risk identification and evaluation activities
• Translate technical cybersecurity findings into clear and understandable risk statements
• Communicate identified risks and potential countermeasures to customer project and R&D teams
• Support project stakeholders in making informed, risk-based decisions

• Recommend appropriate technical and organizational risk mitigation measures
• Collaborate with engineering and project teams to define practical risk treatment plans
• Track mitigation activities and monitor the status of identified cybersecurity risks
• Assess residual risks after mitigation measures have been implemented
• Ensure residual risks are formally reviewed, documented and accepted by the appropriate stakeholders

• Create and maintain Threat and Risk Analysis documentation
• Maintain Security Risk Registers and risk treatment records
• Ensure cybersecurity risks, decisions and mitigation measures remain traceable throughout the project lifecycle
• Support compliance reviews and cybersecurity audits by maintaining accurate and complete risk documentation
• Ensure risk documentation meets internal governance and external regulatory requirements

• Continuously improve Threat and Risk Analysis methodologies, templates and workflows
• Contribute to the development and implementation of standardized cybersecurity risk assessment processes
• Support the selection and improvement of tools used for threat modeling and risk management
• Share lessons learned and best practices across project and cybersecurity teams
• Help strengthen cybersecurity risk management capabilities across the organization

• Translate applicable cybersecurity standards and regulations into practical risk assessment activities
• Ensure risk assessments are aligned with ISA/IEC 62443 requirements, particularly IEC 62443-3-2 and IEC 62443-3-3
• Support compliance with regulations and frameworks such as the Cyber Resilience Act, NIS2, NERC CIP and the BDEW Whitepaper
• Apply relevant risk management principles from ISO 27001 and ISO 27005
• Monitor relevant regulatory developments and support their integration into the Threat and Risk Analysis methodology

• Bachelor’s or Master’s degree in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or a comparable qualification
• Relevant professional experience in cybersecurity threat and risk assessment
• Experience with threat modeling, risk evaluation and cybersecurity risk prioritization
• Strong background in OT security, industrial cybersecurity or product security
• Good understanding of industrial control systems, operational technology environments and industrial network architectures
• Knowledge of common industrial communication protocols and the cybersecurity risks associated with them
• Familiarity with ISA/IEC 62443, particularly the risk assessment and system security requirements covered by IEC 62443-3-2 and IEC 62443-3-3
• Knowledge of relevant regulations and standards such as CRA, NIS2, NERC CIP, BDEW Whitepaper, ISO 27001 and ISO 27005
• Experience assessing attack vectors, threat actors, exposure, exploitability, impact, inherent risk and residual risk
• Ability to facilitate structured Threat and Risk Analysis workshops
• Strong analytical skills and a structured, methodical approach to problem-solving
• Ability to transform complex technical information into clear, prioritized and actionable risk statements
• Strong stakeholder management skills and the ability to collaborate with project, engineering and security teams
• Proficiency in both German and English
• High level of initiative, ownership and willingness to take on new cybersecurity challenges

Nice to Have

~1 min read

• ISA/IEC 62443 certification
• Certified Ethical Hacker – CEH
• CompTIA Cybersecurity Analyst – CySA+
• Experience with cybersecurity risk management or threat modeling tools
• Experience supporting cybersecurity audits or regulatory compliance assessments
• Experience working within the energy, utilities or critical infrastructure sectors
• Familiarity with secure product development and product cybersecurity lifecycle processes
• Experience working in international and multidisciplinary project environments

At Nexttech, we don’t rely on polished platitudes; instead, we let our team members’ voices speak to the essence of who we are:

• “An organization that always listens to feedback from employees, continuously improving based on input and suggestions.”
• “A culture that encourages work-life balance and independence at work.”
• “A place where genuine communication and respect thrive between all levels of the company.”
• “An organization that’s close to people, where kindness and support are constants.”
• “A culture that makes new members feel welcomed, involved in day-to-day decisions, and valued for their unique skill set from day one.”
• “A team that promotes psychological safety and the confidence to speak your mind without fear.”

We promise an environment where respect, openness, and recognition are at the core of your experience. Here, you’ll find a collaborative and responsible team that values fun, autonomy, and flexibility. You’ll face challenges that allow you to grow, supported every step of the way by peers and leadership alike.

If you possess strong industrial cybersecurity expertise, an analytical mindset, a collaborative spirit and a proactive attitude, along with resilience, flexibility and a desire to support your teammates, you’ll fit right in at Nexttech.


Location & Eligibility

Where is the job
Cluj-Napoca, Romania
Remote within one country
Who can apply
RO

Listing Details

Posted
August 6, 2026
First seen
August 7, 2026
Last seen
August 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
59%
Scored at
August 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

nexttechIndustrial Cybersecurity Risk Analyst