This Job Vacancy has Expired!

Business Impact Security Risk Assessment Analyst

Posted on Mar 19, 2019 by Base 3

Brussel, Brussel Belgium
Information Technology
Immediate Start
Annual Salary

Business Impact Security Risk Assessment Analyst

The Business Continuity and Assurance team within the Cyber Security Department defines, establishes and provides information assurance. The team manages regulatory adherence for security, supports security response to external RFPs, manages client queries regarding security policies/controls, provides assurance in response to client due diligence, and manages the first-line internal controls framework. These sub-functions collaborate across security capabilities, with IT and business teams and functions such as HR, Risk Management and Compliance.


Based on our consolidation of IT Assets Inventory, the objective of the project is to obtain a differentiated view of business applications risk profile according to their Confidentiality, Integrity and Availability, aligned with the Risk Management methodology:

  • Evaluating the inherent risk of the application from a business perspective.
  • Assessing separately the financial impact, the regulatory impact and the client impact in case of respectively confidentiality, integrity or availability incident.
  • Ultimately slotting the applications in one of the 5 buckets of different risk profile.
  • Assessments will be conducted through workshops with business owners of the applications, business managers, Risk Management and enterprise architects.

This project is key to support the prioritization for the deployment of the security initiatives.


  • Handle standard situation by relying on existing procedures and methods, covering several but known domains of expertise.
  • Rely on existing processes and policies to take decisions.
  • Focus on execution in your domain, according to defined processes and methods. Runs and maintain the operational process.
  • Work autonomously on standard activities or non-complex demands. Organize, coordinate and plan activities independently. Priorities are set by the job. Use expertise to challenge the goals and scope of new requests and evaluate the impact of these new requirements.
  • Knowledge of security risk management, risk governance.
  • Strong oral and written skills to translate complex risk requirements.
  • Experience with security and controls frameworks, such as ISO 27001, COBIT5, SANS Top 20 Controls and NIST Cybersecurity Framework.
  • Experience with audit good practice.
  • Knowledge of onsite risk assessments, and managing targeted risk remediation activities.

Reference: 673717325