We are looking for a French-speaking Security Risk Analyst to join our partner team in charge of the security governance for the main entity and seven other subsidiaries (six English-speaking and one French-speaking). The activity covers the insurance sector, including property and personal insurance.
In this role, you will contribute to the analysis and validation of security exception requests, support IT teams in implementing Group security standards, monitor and follow up on audit results related to applications, third parties, and physical sites. You will also provide security guidance for business projects by conducting risk assessments, defining security requirements, and evaluating both intrinsic and residual risks. To a lesser extent, you will manage IT operational risks, maintain the ASSU referential, and develop dashboards to track initiatives.
Your work will include producing deliverables such as project security classifications, risk analyses, risk acceptance documents, dashboards with security and risk indicators, as well as managerial presentations for IT and business stakeholders.
Requirements
Technical skills
Solid knowledge of risk analysis methodologies and security fundamentals (classification, AICT assessment, intrinsic / residual risks, risk scenarios)
Familiarity with standards and frameworks : ISO 2700x, ITIL, COBIT
Understanding of security best practices in IT systems management (authorizations, anonymization, incident management, authentication, backup, archiving, patching, antivirus updates, network segmentation, NAC, Wi-Fi, etc.)
Knowledge of security tool administration (firewalls, proxies, SIEM, DLP, IDS / IPS, vulnerability scanners such as Qualys, IAM systems)
Nice to have
Experience in security architecture
Understanding of security monitoring and major cyber threats (malware, cybercrime, APTs) and their attack vectors
Previous experience in IT security audits
Relevant certifications (CISSP, ISO 27001 / 27005, NIST)
Languages & tools
French : minimum B2, written and spoken
English : written and spoken proficiency
Good command of Excel and PowerPoint
Security Analyst • Bucharest, Romania