logo ARENGY
Full time

Cyber Security Risk Analyst

ARENGY • Dubai (United Arab Emirates)

Apply

About us

ARENGY is an IT-Digital and Engineering Consulting Company operating in the Middle East from Dubai. Our customers are the most successful industry leaders executing projects around the globe. We are partnering with one of the leading Railway System Company in Dubai. We are looking for a Cyber Security Risk Analyst.

Job Description

Your responsibilities: 1. Establish Objectives and Scope: Define the goals and scope of the risk assessment. Identify what assets, systems, or processes will be included in the assessment. 2. Asset Inventory and Classification: Identify and catalog all assets within the organization, including hardware, software, data, and personnel. Classify assets based on their importance and sensitivity to the business. 3. Identify Threats and Vulnerabilities: Analyze potential threats that could affect your assets. This involves understanding the various types of cyber threats (e.g., malware, phishing, insider threats) and vulnerabilities (e.g., unpatched systems, weak passwords) that could exploit those assets. 4. Risk Identification: Assess the likelihood and potential impact of threats exploiting vulnerabilities. This involves determining the risk level associated with each potential threat and vulnerability combination. 5. Risk Analysis and Evaluation: Evaluate the identified risks based on their likelihood and potential impact. Assign a risk score or ranking to prioritize which risks are most critical. 6. Risk Treatment and Mitigation: Develop strategies to address and mitigate the identified risks. This might involve implementing security controls, conducting regular software updates, employee training, or other measures to reduce risk. 7. Create a Risk Management Plan: Develop a comprehensive plan outlining how identified risks will be managed. This plan should include prioritization, responsibilities, timelines, and the allocation of resources. 8. Implement and Monitor Controls: Implement the risk mitigation measures and security controls as outlined in the risk management plan. Continuously monitor these controls to ensure their effectiveness. 9. Review and Update: Regularly review and update the risk assessment process to adapt to new threats, changes in technology, or modifications in business operations. 10. Documentation and Reporting: Document all steps taken during the risk assessment process and create reports summarizing the identified risks, mitigation strategies, and the overall risk landscape for stakeholders. Remember, a risk assessment is an ongoing process that needs regular review and updates to address emerging threats and changes in the organization's infrastructure or operations. The Cyber Security Risk Analyst should also conduct a Risk assessment following the principle below: 1. Risk Context: Understanding the context of risk is crucial. This involves considering the organization's objectives, the business environment, legal and regulatory requirements, and the expectations of stakeholders. 2. Risk Assessment Methodology: Establish a structured and systematic approach to risk assessment. Define methodologies and criteria for identifying, analyzing, and evaluating risks consistently across the organization. 3. Risk Identification: Identify potential threats to information assets and vulnerabilities within the organization's systems, processes, and infrastructure. This includes internal and external threats, intentional or un

Required qualifications

5+ years of Information security or technology experience. Proven experience in Risk Assessment and Risk Management as per ISO27001. Holder of a recognized certification such as CISSP, CISM, CRISC, CISA, CompTIA Security+, GSLC, CRM, CEH.

Job details

Company

ARENGY

Contract

Full time • Full-time

Experience

5 years minimum

Degree

No degree

Salary

Attractive salary

Job location

Dubai (United Arab Emirates)

Reference

1684591

Share

Twitter facebook linkedin
Cyber Security Risk Analyst

Interested in this job ?
Apply

Have you worked on Risk Assessment and Risk Management as per ISO27001 ?

Yes No

Do you have at least 5 years of working experience on Information security or technology?

Yes No

Are you holding the certification ISA/IEC-62443 or are you certified Lead Auditor (ISO27001)?

Yes No

Can you describe your experience in Risk Assessment and Risk Management as per ISO27001?

What is your nationality?

Where are you located?

💬 Personalize your message to the recruiter, Click here !


By clicking on Apply, I accept that the information entered will be used as part of the management of applications. In accordance with the law "Informatique et Libertés", you can exercise your right of access to the data concerning you and have them rectified by contacting us : jobposting.pro/contact
Learn more about our data protection policy.