> Markdown version of [/jobs/ext/1604073-cyber-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/1604073-cyber-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Risk Specialist - **Company:** BASF SE - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Cyber Security, Supervisory Control and Data Acquisition (SCADA), Laboratory Information Management Systems, Network Segmentation, Power BI, RSA (Cryptosystem), Microsoft SharePoint, Information Security Management System, Cyber Threat Analysis, Information Technology, Cybercrime, Process Control Systems - **Published:** July 31, 2026 - **Apply:** https://es.indeed.com/viewjob?jk=8255776b201b0424 ## About the Role * Bachelor's degree in computer science, Information Technology, or a related field * Experience with developing, implementing, and maintaining an ISMS based on ISO 27001 and familiarity with IEC 62443 or comparable OT security frameworks * Profound experience in cyber security, particularly in GRC and cyber security risk management across IT and OT environments * Strong experience in security for automation and laboratory environments, including industrial control systems (ICS), SCADA, DCS, PLCs, and LIMS/PIMSSolid understanding of OT architectures and concepts (e.g., Purdue Model, network segmentation, zones and conduits) and their implications for cyber risk management * Strong understanding of risk management principles, frameworks and practices, especially in the field of risk aggregation as well as definition and evaluation of generic risks on enterprise level * Experience with risk assessments, cyber threats and vulnerabilities * Knowledge of relevant laws and regulations related to cyber security and OT security * Ability to bridge communication between IT security teams and OT/engineering stakeholders in production environments * Excellent communication and interpersonal skills, with the ability to work effectively with internal team members and cross-functional teams * Relevant certifications such as CISSP, CISM, CRISC are a plus additional OT-focused certifications (e.g., GICSP, ISA/IEC 62443) are highly desirable ## Description We are seeking an experienced Cyber Security Risk Specialist to join our CISO organization. As part of the Cyber Security Risk Management team, you will contribute to the development, implementation, and maintenance of our cyber security risk management framework., You will be a part of our Cyber Governance, Risk and Compliance (GRC) Product Family, which is the pilar of the second Line of Defense (2LoD) and manages the Cyber Security Framework for the whole BASF Group, following a risk-based approach. One major part of that is to develop and implement risk management tools, policies, and procedures in line with ISO 27001 and other relevant standards. Your core responsibilities will be: * Provide support to Asset Owners and Risk Owners to facilitate the operationalization of Cyber Risk Management-related processes across both IT and OT (Automation Technology) environments, * Foster collaboration with our global Risk Community, incl. OT stakeholders, by actively gathering their feedback, while effectively communicating updates and enhancements to ensure alignment and engagement. * Provide awareness materials and moderate training sessions on Cyber Security Risk Management with dedicated modules for OT environments to promote continuous learning and compliance towards BASF Business Units * Derive new processes or pilots to strengthen GRC in response to the evolving threat landscape in IT and OT (Automation Technology) * Conduct research on new threats by leveraging different sources such as Google Threat Intelligence or Dragos * Execute strategic risk assessments on-demand to identify and evaluate emerging risks in IT and OT, including risks to production continuity, safety, and environmental impact, that could negatively affect or harm BASF * Maintain and improve the toolset that our team provides (RSA Archer, Power BI, Knowledge Base within SharePoint) ensuring integration of OT-specific risk scenarios, asset classifications, and network segmentation (e.g., Purdue model layers) * Aggregate operational risks and translate asset-specific risks to generic risk scenarios on enterprise level to support senior management reporting and strategic as well as tactical decision-making * Support the lifecycle update of group-wide cyber security governance regulations based on generic BASF risk landscape * Work closely with cross-functional teams to support compliance of risk management processes with ISMS according to ISO 27001 and OT security requirements * Collaborate with Asset Owners and Risk Owners to maintain a risk register of IT and OT risks and associated risk treatment plans up to date * Monitor and report on the effectiveness of risk management controls including OT-specific compensating controls (e.g., network segmentation, jump hosts, monitoring) and support the reporting of significant risks to senior management., Because we are counting on innovative solutions, sustainable actions, connected thinking and on you, become a part of our formula for success and develop the future with us - in a global team that embraces diversity and equal opportunities irrespective of gender, age, origin, sexual orientation, disability or belief. At BASF, we are committed to upholding and ensuring compliance with company standards related to quality, environment, health, safety, and energy, in line with our global guidelines. We actively promote a culture of prevention and continuous improvement, encouraging collaboration in initiatives related to quality, environmental protection, health, safety, and energy performance. We foster responsible energy use, promoting efficiency in daily operations and supporting the identification of improvement projects and energy-saving opportunities. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)