Smart Consulting

Smart Consulting is a consulting company with over 15 years of experience in the IT and Telecommunications sectors. Specializing in Team Extension, Team-as-a-Service, Managed Services, Custom Software Development, and Nearshore, we have a team of over 250 professionals who contribute to the development and enhancement of projects both nationally and internationally.
About company

Cyber security analyst

Remote

location Porto

date August 25, 2026

types Full-time

🚀 We are looking for an IT Cyber Risk Analyst / Permanent Control Analyst to join a Cybersecurity team focused on managing technological risk in the payments sector.

This is a role with a strong analytical and governance component, where you will identify operational risks, monitor permanent controls, and ensure the effective implementation of corrective actions in a critical IT perimeter.

What your daily routine will look like:

  • Define and promote cybersecurity governance practices for IT services
  • Support teams in understanding, controlling, and managing cyber risks
  • Supervise cyber risk end-to-end across different payment service areas
  • Identify and analyze ICT and non-ICT risk
  • Determine root causes and potential adverse events
  • Collect and analyze risk inputs, including RCSA results, historical incidents, and control plans
  • Plan and monitor permanent control activities
  • Monitor remediation actions and verify the effectiveness of implemented measures
  • Issue alerts and propose corrective actions
  • Produce a consolidated view of risks for Cybersecurity and IT Risk stakeholders
  • Support risk management exercises, audits, and control assessments
  • Contribute to analyses related to third-party management
  • Collaborate with Security, Development, Production, IT Risk teams, and other relevant areas

What we are looking for:

  • More than 3 years of experience in IT Risk Management, Cyber Risk, or Permanent Control
  • Knowledge of GRC IT
  • Experience with ServiceNow and Microsoft Office
  • Strong root cause analysis and impact assessment capabilities
  • Experience in identifying, assessing, and monitoring operational risks
  • Ability to monitor action plans and validate the effectiveness of controls
  • Knowledge of cybersecurity governance and risk management
  • Fluent in English, written and spoken
  • Fluent in French, written and spoken

We also value:

  • Knowledge of payment activities and regulations
  • Familiarity with DORA and PCI-DSS
  • Experience with RCSA, audits, and control frameworks
  • Knowledge of IT continuity, resilience, and third-party risk management
  • Experience in financial or regulated environments
  • Strong stakeholder management capabilities
  • Proactive, organized, and continuous improvement-oriented profile
  • Willingness to learn and ease of working with different teams

What we offer:

  • Challenging project in the area of Cybersecurity and IT Risk
  • Contact with governance, risk management, and permanent control processes
  • International and multidisciplinary environment
  • Opportunity to work in a critical payments perimeter
  • Strong exposure to technological risk, resilience, and compliance issues
  • Full visa support, if necessary

Location:

Porto

Model:

Hybrid

Junior Salary Package: €12,880 to €21,000 gross (14 months) + Meal Allowance + Flexible BenefitsMid Salary Package: €14,000 to €28,000 gross (14 months) + Meal Allowance + Flexible BenefitsSenior Salary Package: €20,000 to €49,000 gross (14 months) + Meal Allowance + Flexible Benefits