tl;dr: Can someone with experience in IT security risk management / compliance share some insights into their work? Thanks!
Hi security folks,
I'm currently looking into future employment options and am wondering if a more experienced person could provide some insight into what it's like working in IT security risk assessment. Right now I have a potential job opportunity (Europe) as "cyber security consultant" with strong focus on risk analysis and risk management.
The job posting lists aspects such as:
- functional system analysis
- compilation of documents
- conducting risk analysis after relevant standard (e.g. ISO 27005, BSI 200-3, NIST 800-30)
- identifying vulnerabilities
- creation of mitigation plans
- risk and process management
Now, my current situation is kind of complex, because I just got out of a somewhat failed (at least from my point of view) startup while completing my M.SC. in Industrial Cyber Security in parallel. In the startup, we were providing IT security consulting services for industrial companies for the last 2 years in which I worked on a dozen or so projects in the field. I also hold some prior experience from my apprenticeship and studies while working at an IT security firm.
However, my project experience does not really include classical risk management as in: perform risk analysis after ISO 27005. It's more like: We need a security concept for high-availability network segmentation of the plant / network anomaly detection including a threat analysis of the remote access connections / security concept for these old Windows clients, and so on...
Now I'm wondering if just performing risk management is too much of a "paper tiger" job because I kind of enjoy working technically as well (I also worked as a Linux based software developer before).
I would be happy to read your insights and thoughts, thanks a lot!
submitted by [comments]
SOCIAL SHARE CARD GENERATOR