- Company Name
- Devoteam
- Job Title
- Cyber Security Risk Manager
- Job Description
-
Job Title: Cyber Security Risk Manager
Role Summary: Trusted advisor for clients’ digital transformation projects, assessing and mitigating cyber risks. Drives the cyber intelligence cycle, monitors threat landscapes, develops risk analysis, and ensures compliance with evolving standards and regulations. Maintains a high cybersecurity maturity level across client environments.
Expactations:
- Serve as a proactive, independent problem‑solver with strong communication and presentation skills.
- Collaborate cross‑functionally with business and technical stakeholders to clarify risk requirements.
- Work autonomously in dynamic settings, balancing on‑site client visits and remote collaboration.
- Continuously update knowledge of emerging threats, technologies, and regulatory changes.
Key Responsibilities:
- Conduct risk assessments, design mitigation plans, and validate implementations for complex technical environments.
- Maintain detailed risk registers, controls documentation, and compliance evidence.
- Monitor threat intelligence feeds, identify relevant cyber trends, and advise on threat response actions.
- Develop and enforce security best‑practice procedures and guidelines aligned with ISO27001/ISO27002, ISO27005, CIS‑20, PCI‑DSS, SOC2, EU NIS, GDPR, and other applicable frameworks.
- Lead or participate in audit, business continuity, and internal control reviews to satisfy regulatory requirements.
- Deliver clear reports, briefings, and recommendations to senior stakeholders and audit bodies.
Required Skills:
- Expertise in information security, cybercrime, cloud security, DevOps, and risk management.
- Strong grasp of security concepts: Zero‑Trust, CASB, Cloud, SIEM, SOAR, PKI, IAM, PAM, DevSecOps.
- Proficiency in risk control frameworks (ISO 27001/02, 27005, CIS‑20, PCI‑DSS, SOC2, EU NIS, GDPR).
- Excellent written and oral communication, with ability to translate business needs into technical risk solutions.
- Team‑player mentality, self‑starter, and proactive initiative.
- Proficiency in English; fluency in Dutch or French a plus.
Required Education & Certifications:
- Master’s degree in Computer Science, Engineering, or Cyber Security, or equivalent experience.
- ISO 27001 Lead Auditor or Lead Implementer certification.
- Data privacy and security certifications highly valued: CISSP, CEH, C/CISO, CISA, CISM, CRISC, CDPSE, CIPP/US, CIPM, CIPT, TOGAF.