Back to all jobs
Visible on IKONS todayNewPopular

Cybersecurity IT OT and Business Continuity Analyst

HainautHybridHours negotiable<3months

Evaluate, prioritize, and document cyber risks related to industrial systems and their IT dependencies within public infrastructures such as tunnels, dams, locks, telemanagement systems, road equipment, and fiber optics.

  • Recommend appropriate treatment measures.

What you do

Mapping & inventory.

  • Inventory OT assets (PLC, RTU, HMI, field networks) and their IT dependencies in a unified CMDB.
  • Identify Single Points of Failure (SPOFs) such as Domain Controllers, network interconnections, critical markets, or firewalls.

Operational risk analysis.

  • Apply a risk management methodology to model threats, vulnerabilities, and potential impacts on personal safety, the environment, service availability, finances, and image.
  • Rely on concrete scenarios and feedback from incidents or crises.

Treatment plan & prioritization.

  • Develop an action plan for treating identified risks: reduction, avoidance, transfer, or acceptance.
  • Evaluate costs and impacts, then build a risk reduction roadmap aligned with the operational continuity of systems.
  • Communicate clearly throughout the risk management cycle.

Integration into projects & markets.

  • Draft IT/OT security clauses in specifications.
  • Control the compliance of critical suppliers involved in OT environments, particularly for the maintenance of PLCs and supervision systems.

IT/OT & SOC synergy.

  • Translate OT risks into logging requirements and detection rules for a SOC, for example, in the form of use cases related to PLC takeovers.

Resilience & exercises.

  • Participate in restoration tests and OT/IT table-top exercises to validate impact hypotheses.
  • Contribute to feedback and root cause analysis.
  • Contribute to the continuous improvement of service continuity plans (BCP) and disaster recovery plans (DRP).

Reporting & governance.

  • Keep the OT risk register up to date.
  • Prepare summaries for cyber governance committees and for NIS2 audits related to risk management policy.

Deliverables.

  • Service continuity plan and disaster recovery plan.
  • Detailed inventory of OT assets and IT dependencies in the CMDB.
  • OT risk register with scoring, scenarios, responsibilities, and deadlines.
  • Mapping of zones and conduits, as well as flow diagrams.
  • Prioritized treatment plan with a 24-month roadmap.
  • Security requirements grids for OT purchases or modernizations.
  • Quarterly reports: risk status, progress, and decisions to be arbitrated.

Profile

  • Confirmed experience in risk analysis.
  • Very good communication and influencing skills, with the ability to vulgarize complex subjects.
  • Proficiency in industrial communication protocols such as Modbus, PROFINET, DNP3, or equivalents.
  • Good knowledge of control systems such as SCADA, PLC, RTU, DCS, or equivalents.
  • Knowledge of cybersecurity frameworks such as NIST and Cyberfundamentals.
  • Proficiency in risk management methodologies such as ISO 27005, IEC 62443-3-2, and EBIOS RM.
  • Knowledge of information security standards and frameworks, notably IEC 62443.
  • Practice of GRC and reporting tools.
  • Ability to evolve in IT/OT environments and contribute to business continuity and resilience topics.

Languages.

  • French: mandatory
  • English: mandatory

Behavioral competencies.

  • Assertiveness and ability to be proactive in proposing solutions.
  • Autonomy, with a good team spirit.
  • Excellent communication skills, with a customer and results-oriented approach.
  • Positive, benevolent attitude and active listening.
  • Ability to teach and simplify technical subjects for both executives and field teams.
  • Rigor and method.

How to apply

View the full assignment text and application details once your tailored application is ready.

Order a tailored application to view the full assignment and application details.

More context, less searching.

You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.