About The Position

Nexttech is seeking an Industrial Cybersecurity Risk Analyst to identify, assess, and prioritize cybersecurity risks affecting IT and OT systems, products, and architectures used within critical energy infrastructure. This role involves providing Cybersecurity Threat and Risk Analysis as a service for customer and R&D projects. The analyst will facilitate risk assessment workshops, evaluate attack scenarios, and translate complex technical findings into actionable mitigation measures. Collaboration with project teams, engineering specialists, and cybersecurity experts is crucial to ensure risks are transparent, appropriately treated, and formally accepted. This position is ideal for individuals with strong expertise in industrial cybersecurity, threat modeling, and risk management, who thrive in multidisciplinary and international environments.

Requirements

  • Bachelor’s or Master’s degree in IT Security, Computer Science, Electrical Engineering with a focus on IT Security, or a comparable qualification.
  • Relevant professional experience in cybersecurity threat and risk assessment.
  • Experience with threat modeling, risk evaluation, and cybersecurity risk prioritization.
  • Strong background in OT security, industrial cybersecurity, or product security.
  • Good understanding of industrial control systems, operational technology environments, and industrial network architectures.
  • Knowledge of common industrial communication protocols and the cybersecurity risks associated with them.
  • Familiarity with ISA/IEC 62443, particularly the risk assessment and system security requirements covered by IEC 62443-3-2 and IEC 62443-3-3.
  • Knowledge of relevant regulations and standards such as CRA, NIS2, NERC CIP, BDEW Whitepaper, ISO 27001, and ISO 27005.
  • Experience assessing attack vectors, threat actors, exposure, exploitability, impact, inherent risk, and residual risk.
  • Ability to facilitate structured Threat and Risk Analysis workshops.
  • Strong analytical skills and a structured, methodical approach to problem-solving.
  • Ability to transform complex technical information into clear, prioritized, and actionable risk statements.
  • Strong stakeholder management skills and the ability to collaborate with project, engineering, and security teams.
  • Proficiency in both German and English.
  • High level of initiative, ownership, and willingness to take on new cybersecurity challenges.

Nice To Haves

  • ISA/IEC 62443 certification
  • Certified Ethical Hacker – CEH
  • CompTIA Cybersecurity Analyst – CySA+
  • Experience with cybersecurity risk management or threat modeling tools
  • Experience supporting cybersecurity audits or regulatory compliance assessments
  • Experience working within the energy, utilities, or critical infrastructure sectors
  • Familiarity with secure product development and product cybersecurity lifecycle processes
  • Experience working in international and multidisciplinary project environments

Responsibilities

  • Plan and perform Cybersecurity Threat and Risk Analyses for IT and OT systems, products, components, and architectures.
  • Support customer and R&D projects by providing structured cybersecurity risk assessments.
  • Identify and assess potential attack scenarios, attack vectors, threat actors, and system vulnerabilities.
  • Evaluate exposure, exploitability, business impact, inherent risk, and residual risk.
  • Prioritize cybersecurity risks based on technical severity and business impact.
  • Plan and facilitate Threat and Risk Analysis workshops with project members, engineering teams, and cybersecurity specialists.
  • Guide multidisciplinary stakeholders through structured risk identification and evaluation activities.
  • Translate technical cybersecurity findings into clear and understandable risk statements.
  • Communicate identified risks and potential countermeasures to customer project and R&D teams.
  • Support project stakeholders in making informed, risk-based decisions.
  • Recommend appropriate technical and organizational risk mitigation measures.
  • Collaborate with engineering and project teams to define practical risk treatment plans.
  • Track mitigation activities and monitor the status of identified cybersecurity risks.
  • Assess residual risks after mitigation measures have been implemented.
  • Ensure residual risks are formally reviewed, documented, and accepted by the appropriate stakeholders.
  • Create and maintain Threat and Risk Analysis documentation.
  • Maintain Security Risk Registers and risk treatment records.
  • Ensure cybersecurity risks, decisions, and mitigation measures remain traceable throughout the project lifecycle.
  • Support compliance reviews and cybersecurity audits by maintaining accurate and complete risk documentation.
  • Ensure risk documentation meets internal governance and external regulatory requirements.
  • Continuously improve Threat and Risk Analysis methodologies, templates, and workflows.
  • Contribute to the development and implementation of standardized cybersecurity risk assessment processes.
  • Support the selection and improvement of tools used for threat modeling and risk management.
  • Share lessons learned and best practices across project and cybersecurity teams.
  • Help strengthen cybersecurity risk management capabilities across the organization.
  • Translate applicable cybersecurity standards and regulations into practical risk assessment activities.
  • Ensure risk assessments are aligned with ISA/IEC 62443 requirements, particularly IEC 62443-3-2 and IEC 62443-3-3.
  • Support compliance with regulations and frameworks such as the Cyber Resilience Act, NIS2, NERC CIP, and the BDEW Whitepaper.
  • Apply relevant risk management principles from ISO 27001 and ISO 27005.
  • Monitor relevant regulatory developments and support their integration into the Threat and Risk Analysis methodology.

Benefits

  • Work-life balance
  • Independence at work
  • Genuine communication and respect
  • Kindness and support
  • Welcoming environment for new members
  • Involvement in day-to-day decisions
  • Recognition of unique skill sets
  • Psychological safety
  • Confidence to speak your mind without fear
  • Respect, openness, and recognition
  • Collaborative and responsible team
  • Fun
  • Autonomy
  • Flexibility
  • Opportunities for growth
  • Support from peers and leadership
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service