Information Risk Analyst

Job Title: Information Risk Analyst
Contract Type: Contract
Location: Brussels, Belgium
Salary: Négociable
Reference: 72783-ITBEL-EVS_1540829086
Contact Name: Elise Vander Straeten
Contact Email:
Job Published: October 29, 2018 16:04

Job Description

Information Risk Analyst:

The Business Continuity and Assurance team within the Cyber Security Department defines, establishes and provides information assurance. The team manages regulatory adherence for security, supports security response to external RfPs, manages client queries regarding security policies/controls, provides assurance in response to client due diligence, and manages the first-line internal controls framework. These sub-functions collaborate across security capabilities, with IT and business teams and functions such as HR, Risk Management and Compliance.

Your part of the deal:
Based on our consolidated of IT Assets Inventory, the objective of the project is to obtain a differentiated view of business applications risk profile according to their Confidentiality, Integrity and Availability, aligned with the company Risk Mgt methodology:

- evaluating the inherent risk of the application from a business perspective;
- assessing separately the financial impact, the regulatory impact and the client impact in case of respectively confidentiality, integrity or availability incident
- ultimately slotting the applications in one of the 5 buckets of different risk profile.

Assessments will be conducted through workshops with business owners of the applications, business managers, Risk Management and enterprise architects.
This project is key to support the prioritization for the deployment of the company security initiatives.

Your Profile:

* Handles standard situation by relying on existing procedures and methods, covering several but known domains of expertise.
* Relies on existing processes and policies to take decisions.
* Focuses on execution in his domain, according to defined processes and methods. Runs and maintains the operational process.
* Works autonomously on standard activities or non-complex demands. Organises, co-ordinates and plans activities independently. Priorities are set by the job. Uses expertise to challenge the goals and scope of new requests and evaluates the impact of these new requirements.
Knowledge of security risk management, risk governance.
*Strong oral and written skills to translate complex risk requirements.
*Experience with security and controls frameworks, such as ISO 27001, COBIT5, SANS Top 20 Controls and NIST Cybersecurity Framework.
*Experience with audit good practice.
*Knowledge of onsite risk assessments, and managing targeted risk remediation activities.