A public infrastructure organisation in Belgium is strengthening how it manages cyber and continuity risks across tunnels, dams, locks, traffic equipment, remote-control systems and optical-fibre networks in Wallonia. As an industrial cybersecurity risk analyst for public infrastructure, you will assess OT assets and their IT dependencies, using SCADA systems, PLCs and industrial protocols such as Modbus and PROFINET to support risk treatment and continuity planning.
The mission
The work covers operational technology deployed across public infrastructure, including PLCs, RTUs, HMIs, field networks and supervisory environments, together with critical IT dependencies such as domain controllers, firewalls and inter-network links. You will maintain an inventory in a unified CMDB and identify single points of failure. Risk scenarios will connect cyber events to consequences such as tunnel shutdown, dam overflow, safety, environmental, availability and financial impacts. The analysis will support the NIST Cybersecurity Framework, CyberFundamentals, ISO 27005, IEC 62443-3-2 and EBIOS RM.
You will manage the full cycle of OT risk management, from asset and dependency mapping through scoring, treatment decisions, roadmap development and reporting. Your outputs will include an OT risk register, zone and conduit maps, a prioritised 24-month OT risk reduction roadmap, security requirements for OT procurement and modernisation, and contributions to business continuity and disaster recovery plans. You will work with infrastructure, security, procurement, suppliers and SOC stakeholders, translating OT risks into logging and detection use cases. You will also participate in restoration tests and IT/OT tabletop exercises, then capture lessons learned and root causes.
Your responsibilities
- Map OT assets, IT dependencies and single points of failure in the unified CMDB, covering SCADA systems, PLCs, RTUs, HMIs and industrial networks.
- Analyse operational cyber risks using concrete scenarios, including tunnel stoppages, dam incidents, loss of supervision and unauthorised automation access.
- Prioritise treatment options by assessing risk reduction, cost, operational impact and alignment with service continuity requirements.
- Define security clauses and supplier requirements for critical OT maintenance, procurement and modernisation projects.
- Translate OT risk scenarios into SOC logging requirements, detection rules and relevant use cases.
- Report risk status, decisions, owners and deadlines to governance committees and support NIS2 audit requirements using GRC tools and structured reporting.
Your profile
Essential skills
- Apply risk methodologies such as ISO 27005, IEC 62443-3-2 and EBIOS RM to operational and information security contexts.
- Understand industrial communication protocols, including Modbus, PROFINET, DNP3 or equivalent technologies.
- Understand control-command environments involving SCADA systems, PLCs, RTUs, DCS and related operational technology.
- Work with cybersecurity frameworks such as the NIST Cybersecurity Framework and CyberFundamentals.
- Maintain risk registers, treatment plans and management reporting using GRC tools.
- Explain technical risks clearly to executives, operational teams, suppliers and other non-specialist stakeholders, with the communication and influence needed to support decisions.
- Work independently and methodically while contributing constructively to multidisciplinary IT, OT, SOC and business teams.
- Operate at a medior level, showing initiative, assertiveness, active listening and a practical, results-oriented approach.