Risk Analyst
For a client in Namur, we are looking for a Risk Analyst.
Project start and end dates: 03/11/2026 - 30/11/2027
Location: Namur, with a presence required in our offices at least 60% of the time.
Required languages: English, French
Main mission:
Assess, prioritize and trace the cyber risks related to industrial systems and their IT dependencies present on public infrastructure and recommend appropriate treatment measures.
Key activities:
Mapping & inventory: Identify OT assets and their IT dependencies. Identify the SPOFs.
Operational risk analysis: Apply the methodology to model threats, vulnerabilities and impacts. Use concrete scenarios based on feedback.
Treatment plan & prioritization: Develop the action implementation plan to address the risks analyzed. Quantify the cost/impact and develop a risk reduction roadmap.
Project & Contract Integration: Draft the IT/OT security clauses in the specifications. Check the compliance of critical OT suppliers.
IT/OT & SOC Synergy: Translate OT risks into logging requirements and detection rules for the SOC.
Resilience & exercises: Participate in restoration tests and OT/IT table-top exercises. Contribute to feedback and continuous improvement of service continuity plans.
Reporting & Governance: Maintain the OT risk register, prepare summaries for the Cyber Committee and for NIS2 audits.
Examples of deliverables:
Service continuity plan and restoration plan after disaster.
Detailed inventory of OT assets & IT dependencies.
OT risk register with scoring, scenarios, owners, and deadlines.
Zone & duct mapping + flow diagrams.
Prioritized treatment plan.
Security requirements grids for OT purchases/modernizations.
Quarterly reports to the Coordinator.
Expected behavioral skills:
Assertiveness and the ability to be proactive.
Autonomy and appreciation of teamwork.
Very good communicator, customer oriented and results.
Positive and caring attitude, active listening.
Capacity for pedagogy and popularization of technical aspects.
Rigorous and methodical.
Technical skills required:
Communication & influence.
Knowledge of industrial communication protocols.
Knowledge of control systems.
Cybersecurity framework.
Risk management methodologies.
Information security standards and repositories.
GRC tools & reporting.