05 ago
|
NTek Software Solutions
|
España
05 ago
NTek Software Solutions
España
Description & Mission Details
Main mission:
To assess, prioritize and trace cyber risks related to industrial systems and their IT dependencies present on public infrastructures managed by SPW MI (tunnels, dams, locks, remote management, road equipment, fiber optics, etc.) and recommend appropriate treatment measures.
Key Activities
Mapping & inventory
- List OT assets (PLC, RTU, HMI, field networks) and their IT dependencies in the unified CMDB.
- Identify the SPOFs: Domain Controller, inter-network links, critical markets, firewalls…
Operational risk analysis
- Apply the SPW methodology to model threats (tunnel closure, dam overflow, etc.), vulnerabilities and impacts (safety of people, environment, availability, finances, image, etc.)
- Use concrete scenarios based on the lessons learned from the 2025 crisis by the SPW.
Treatment plan & prioritization
- Develop the implementation plan for actions to address the analyzed risks (reduction, avoidance, transfer, acceptance).
- Quantify the cost/impact and develop a risk reduction roadmap aligned with the business continuity of the systems
- Communicate the complete risk management cycle.
Project & Market Integration
- Draft the IT/OT security clauses in the specifications.
- Verify the compliance of critical OT suppliers (PLC maintenance, supervision).
Synergie IT/OT & SOC
- Translate OT risks into logging requirements and detection rules for the SPW SOC (use-case, PLC takeovers, …).
Resilience & exercises
- Participate in restoration tests and OT/IT table-top exercises to validate impact hypotheses.
- Contribute to feedback and analyze the root causes
- Contribute to the continuous improvement of business continuity plans (BCP) and disaster recovery plans (DRP).
Reporting & Governance
- Keep the OT risk register up to date,
prepare summaries for the Cyber MI Committee and for NIS2 audits (risk management policy).
Examples of deliverables
- Business continuity plan and disaster recovery plan
- Detailed inventory of OT assets & IT dependencies (CMDB).
- OT risk register with scoring, scenarios, owners and deadlines.
- Mapping of zones & conduits + flow diagrams.
- Prioritized treatment plan (24-month roadmap).
- Safety requirements grids for OT purchases/modernizations.
- Quarterly reports to the Coordinator: risk status, progress, decisions to be arbitrated.
Expected behavioral skills
- Assertiveness and the ability to be proactive
- You are independent but you enjoy working in a team
- Excellent communicator, customer and results oriented
- Positive and caring attitude, active listening
- Ability to teach and simplify technical aspects
- Rigorous and methodical
Mission extension
- Mission: extendable until 30/11/2027
Skills, Roles, & Languages Matrix
Category
Requirement / Skill
Required Level
Most Recent Experience
Roles
T2 - Confirmed Risk Analyst (mandatory)
—
Any time
Skills
Communication & influence (simplification for managers and field teams)
T1 - Junior
Any time
Skills
Knowledge of industrial communication protocols such as Modbus, PROFINET, DNP3 or equivalents. (mandatory)
T2 - Confirmed
Any time
Skills
Knowledge of control systems such as SCADA, PLC, RTU, DCS or equivalent systems. (mandatory)
T2 - Confirmed
Any time
Skills
Cybersecurity framework (NIST, Cyberfundamentals) (mandatory)
T2 - Confirmed
Any time
Skills
Risk management methodologies (ISO 27005, IEC 62443-3-2, EBIOS RM) (mandatory)
T2 - Confirmed
Any time
Skills
Information security standards and frameworks (IEC 62443) (mandatory)
T1 - Junior
Any time
Skills
CRM & Reporting Tools (mandatory)
T1 - Junior
Any time
Languages
English (mandatory)
Beginners (A1)
—
Languages
French (mandatory)
Proficiency (C2)
—
📌 Business risk and continuity analyst (España)
🏢 NTek Software Solutions
📍 España