
Noesis
We are an international technology consultancy with a thousand talents specialized in different technologies. Every day, we work together to create innovative solutions that impact society. We are in Portugal, Spain, the Netherlands, Brazil, Ireland, and the USA. It is in cultural diversity and opportunities that we find the motivation to innovate and challenge ourselves to be better.
About company Cyber risk analyst - Lisbon/hybrid
Remote
Lisbon
August 20, 2026
Full-time
Cyber Risk Analyst - Lisbon/Hybrid
Noesis is looking for professionals with the following profile:
Main Tasks and Responsibilities:
- Coordinate and support the corporate Information Security Risk Management process, ensuring its consistent application in assets, services, projects, processes, and third-party service providers;
- Ensure the quality, consistency, and traceability of risk assessments, validating scenarios, threats, vulnerabilities, controls, impacts, and risk levels;
- Manage the Corporate Information Security Risk Register, ensuring classification, updating, traceability, and linkage to controls, requirements, treatment plans, and evidence;
- Support the definition and prioritization of risk treatment plans, ensuring the adequacy of mitigation measures to exposure, criticality, and applicable requirements;
- Monitor the implementation and effectiveness of mitigation and remediation actions, tracking responsible parties, deadlines, deviations, and residual risks;
- Consolidate and analyze risk information from multiple sources, identifying trends, relevant exposures, and decision-making needs;
- Produce executive reports, dashboards, and risk indicators, supporting the monitoring of risk exposure, the effectiveness of controls, and the evolution of treatment plans;
- Conduct gap assessments, support audits, inspections, and compliance initiatives;
- Collaborate with internal and external stakeholders and contribute to the continuous improvement of the function, promoting methodologies, processes, tools, and a culture of Information Security risk.
Requirements:
- Bachelor's or master's degree (preferably) in Management, Cybersecurity, Computer Science, Information Systems, or an equivalent area;
- Relevant professional experience (implementation and/or execution of Cybersecurity Risk Management, Information Security, or GRC) of at least 2 years;
- Knowledge of Risk Management methodologies;
- Knowledge of relevant standards in Cybersecurity and Information Security (e.g., ISO 27001, ISO 27005, NIST CSF);
- Knowledge of Information Technologies (e.g., management of information systems, application platforms, software development);
- Experience and/or knowledge of GRC tools and risk registers;
- Basic knowledge of Governance, Risk & Compliance frameworks;
- Fluent Portuguese and advanced English (spoken and written).
Preferred Requirements (not mandatory):
- Experience in Disaster Recovery and/or Business Continuity projects.
- Experience/Certifications/Training in NIS2 and ISO 27001 projects.
- Experience in Risk Management.
- Participation in compliance assessments.
- Complementary training in Risk Management or Information Security.
- Interest in aviation regulation and operational risk.
Work regime:
Hybrid (2x a week in the office)
If you meet these requirements and would like to join an innovative organization that continually invests in the training of its talents, send us your application.
Join us. Let’s innovate together!
All our recruitment and selection processes are based on equal opportunities, valuing the competence and potential of each person and ensuring that no candidate is discriminated against on the basis of gender, ethnicity, sexual orientation, age, religion, or physical condition.