Devoteam Cyber Trust | Risk Analyst | Financial Services

  • Full-time
  • Contract type: Permanent contract

Company Description

Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.

Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.

The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

Job Description

 

  • PCI-DSS Compliance & Audit Management: Act as the primary point of contact for external auditors; independently gather, prepare, validate, and present evidence required for PCI-DSS audits and certification processes.

  • Vulnerability & Risk Management: Proactively identify security vulnerabilities and risks, drive the remediation lifecycle, and maintain risk tracking/remediation plans prioritized by threat level.

  • Technical Asset & Access Analysis: Analyze technical inventories (including cryptographic keys, certificates, privileged access, and network assets) and cross-reference data across disparate sources.

  • Cross-Functional Collaboration: Partner with multidisciplinary technical teams and IT vendors to monitor security initiatives, ensure compliance alignment, and execute corrective action plans.

  • Governance & Documentation: Draft and maintain internal policies, standards, risk notes, and audit-ready documentation in line with best governance practices.

Qualifications

Experience & Domain Knowledge

  • Proven experience managing PCI-DSS audit and certification processes, including direct interaction with external auditors.

  • Deep technical understanding of PCI-DSS requirements (e.g., cryptographic key management, network segmentation, access controls, logging, and monitoring).

  • Strong working knowledge of DORA (Digital Operational Resilience Act) requirements relevant to financial institutions.

  • Practical expertise in vulnerability management methodologies, risk management frameworks, and remediation lifecycles.

Technical & Environmental Competencies

  • Familiarity with network and infrastructure concepts (segmentation, firewalls, external exposure).

  • Experience with multi-platform environments (Windows, Linux/AIX) and cloud architectures.

  • Hands-on familiarity with core security tooling:

    • Vulnerability management & scanning tools

    • SIEM / EDR solutions

    • Identity & Privileged Access Management (PAM)

    • Certificate & cryptographic key management tools

Key Skills & Attributes

  • Analytical Capability: Ability to read, interpret, and synthesize complex technical audit and vulnerability reports.

  • Autonomy & Rigor: High level of self-organization, attention to detail, and the ability to manage competing deadlines independently in an audit context.

  • Proactivity & Critical Thinking: Sharp ability to anticipate risks, connect scattered data points, and resolve potential issues before they become formal audit findings.

  • Communication & Negotiation: Clear, assertive, and articulate communication skills across diverse audiences (technical teams, vendors, auditors, and management).

Additional Information

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

What we offer:

  • Professional development and monitoring talent;
  • Commitment to our employees' development;
  • Collaboration in a company that is constantly growing and evolving.
  • Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.

Would you like to join our team? Then send your CV.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice