Cloud Cyber Risk Analyst & Third-Party Risk Manager (Hybrid)
Job Summary
CLOUD CYBER RISKANALYST & THIRD-PARTY RISK MANAGER(HYBRID LISBON OR PORTO)
Portuguese company hires for hybrid position
Location: Lisbon orPorto Portugal
Only candidates already basedin Portugal will be considered
Work Model: Hybrid
Language Requirements:English C1 (mandatory) French A2 (nice to have)
Seniority: Senior (5years)
Sector: Banking
Instructions: Please send yourCV in English and make sure to include all skills and experience that match therequirements of the opportunity. This will significantly increase your chancesof success.
Role Overview
You will play a key role in ensuring the cybersecurityand resilience of cloud environments covering IaaS PaaS SaaS andthird-party solutions. Working closely with international teams youwill contribute to risk assessments governance and cloud security strategywith a strong focus on third-party risk management.
Key Responsibilities
Cloud & Third-Party RiskManagement
- Perform risk assessments for third-party and SaaS onboarding
- Contribute to cloud cybersecurity governance and policies
- Support third-party risk governance frameworks and monitoring
- Participate in governance committees and decision-making processes
Cloud Cyber RiskAssessment
- Analyze and support risk assessments (ISO 27005 / EBIOS RM frameworks)
- Evaluate and challenge remediation plans from providers and stakeholders
- Contribute to cloud risk mapping and risk cartography
- Support Cloud Maturity Assurance initiatives (CMAT)
Governance & ContinuousImprovement
- Maintain risk data and reporting tools
- Contribute to organizational and governance topics
- Promote best practices in cloud cybersecurity and risk management
Must-Have Skills
- Strong experience in Cybersecurity and IT Risk Management
- Knowledge of risk methodologies (ISO 27005 EBIOS RM)
- Experience with cloud environments (AWS Azure GCP IBM Cloud)
- Understanding of third-party risk management in cloud ecosystems
- Familiarity with security frameworks (ISO 27001 NIST CIS)
- Strong analytical and problem-solving skills
Nice to Have
- Certifications such as ISO 27001 Lead Implementer/Auditor
- Knowledge of cloud security standards (SOC2 ISO 27017 CSA)
- Experience in project management or governance roles
- Exposure to risk cartography and reporting tools
Soft Skills
- Strong ability to influence stakeholders without direct authority
- Excellent communication and collaboration skills
- Ability to make pragmatic decisions in dynamic environments
- Critical thinking and strategic mindset
- Proactive and solution-oriented approach
Why Join
- Work within a strategic Cloud CISO environment
- Contribute to enterprise-level cybersecurity and risk initiatives
- Engage with international teams and complex cloud ecosystems
- Gain exposure to advanced governance and risk frameworks
- Grow into leadership roles in cybersecurity and cloud risk
Keywords
Cloud Security Cyber Risk Third-Party Risk SaaS IaaSPaaS ISO 27005 EBIOS ISO 27001 NIST CIS AWS Azure GCP IBM Cloud RiskAssessment Governance CMAT Cybersecurity
#CI - PROC26196
Required Experience:
Manager