← Back to job listings
DE
Risk Analyst
Devoteam · Lisboa, Portugal
About The Role
 
- PCI-DSS Compliance & Audit Management: Act as the primary point of contact for external auditors; independently gather, prepare, validate, and present evidence required for PCI-DSS audits and certification processes.
- Vulnerability & Risk Management: Proactively identify security vulnerabilities and risks, drive the remediation lifecycle, and maintain risk tracking/remediation plans prioritized by threat level.
- Technical Asset & Access Analysis: Analyze technical inventories (including cryptographic keys, certificates, privileged access, and network assets) and cross-reference data across disparate sources.
- Cross-Functional Collaboration: Partner with multidisciplinary technical teams and IT vendors to monitor security initiatives, ensure compliance alignment, and execute corrective action plans.
- Governance & Documentation: Draft and maintain internal policies, standards, risk notes, and audit-ready documentation in line with best governance practices.
Experience & Domain Knowledge
- Proven experience managing PCI-DSS audit and certification processes, including direct interaction with external auditors.
- Deep technical understanding of PCI-DSS requirements (e.g., cryptographic key management, network segmentation, access controls, logging, and monitoring).
- Strong working knowledge of DORA (Digital Operational Resilience Act) requirements relevant to financial institutions.
- Practical expertise in vulnerability management methodologies, risk management frameworks, and remediation lifecycles.
Technical & Environmental Competencies
- Familiarity with network and infrastructure concepts (segmentation, firewalls, external exposure).
- Experience with multi-platform environments (Windows, Linux/AIX) and cloud architectures.
- Hands-on familiarity with core security tooling:
- Vulnerability management & scanning tools
- SIEM / EDR solutions
- Identity & Privileged Access Management (PAM)
- Certificate & cryptographic key management tools
Key Skills & Attributes
- Analytical Capability: Ability to read, interpret, and synthesize complex technical audit and vulnerability reports.
- Autonomy & Rigor: High level of self-organization, attention to detail, and the ability to manage competing deadlines independently in an audit context.
- Proactivity & Critical Thinking: Sharp ability to anticipate risks, connect scattered data points, and resolve potential issues before they become formal audit findings.
- Communication & Negotiation: Clear, assertive, and articulate communication skills across diverse audiences (technical teams, vendors, auditors, and management).
The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.
What we offer
- Professional development and monitoring talent;
- Commitment to our employees' development;
- Collaboration in a company that is constantly growing and evolving.
- Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.
Would you like to join our team? Then send your CV.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring