Risk Analyst & Permanent Control

CONSORT GROUPPortoteamtailorpublicerad 2026-08-18
Krav:FinTechSecurityRemoteHybrid

Every moment counts. Especially those you live to the fullest. Welcome to Consort Group. For over 30 years, Consort Group has been helping companies leverage their data and infrastructure. It is backed by two leaders, Consortis and Consortia, and places people and social responsibility at the heart of its values. This is your future team Established in 2021, Consort Portugal supports the strategic offshoring choices of our clients, particularly in Europe, and brings our expertise in infrastructure services to the Portuguese market. With a team of around 45 employees, our Service Center based in Porto is developing a dynamic nearshore business, offering the French and European markets an environment of excellence and high potential. Risk Analyst & Permanent Control This is your mission Are you passionate about cybersecurity, IT risk management and permanent control ? Then this position is for you. As a Risk Analyst & Permanent Control , you will contribute to identifying, analysing and monitoring cyber and operational risks within a highly critical IT Payments environment. You will support permanent control activities, assess risks and incidents, coordinate remediation actions and provide consolidated risk reporting to cybersecurity and risk stakeholders. Working closely with security, development and production teams, you will contribute to strengthening cybersecurity governance and ensuring that risks are properly identified, assessed, controlled and remediated. Build side: Contribute to the definition and promotion of cybersecurity governance for IT Payment Services.

Support the identification and assessment of ICT and non-ICT operational risks.

Contribute to RCSA exercises, risk assessments, audits and other risk-management activities.

Analyse operational risks by reviewing historical incidents, control plans and RCSA results.

Perform root-cause analysis and assess potential impacts and adverse events.

Contribute to the continuous improvement of the cyber risk landscape and control framework.

Run side: Execute and monitor permanent control activities across the IT Payments perimeter.

Supervise cyber risks across multiple payment-related activities and entities.

Monitor remediation plans and follow up on corrective actions through to completion.

Verify the effectiveness of remediation measures and challenge action owners when required.

Prepare alerts, risk indicators and consolidated risk overviews for cybersecurity and risk stakeholders.

Support third-party risk management and related control activities.

Collaborate with security, development, production, IT risk, continuity and resilience stakeholders.

This is your background You have at least 3 years of professional experience in IT risk management, cybersecurity risk, permanent control, operational risk or a related field . You have a strong understanding of risk identification, assessment and remediation processes and are comfortable working with multiple stakeholders in a complex IT environment. Experience in cybersecurity and/or payment environments is highly valued. Knowledge of DORA and PCI-DSS is a strong plus. You are analytical, proactive and comfortable challenging risks and controls while maintaining constructive relationships with business and technical teams. This is your expertise: 3+ years of experience in IT Risk Management, Cybersecurity Risk, Operational Risk or Permanent Control

Strong knowledge of risk identification, assessment, control execution and remediation

Experience with RCSA, operational incidents, audits and control plans

Strong root-cause analysis and impact assessment capabilities

Knowledge of GRC / IT risk management tools , ideally ServiceNow

Good knowledge of Microsoft Office Suite

Understanding of cybersecurity governance and IT risk frameworks

Knowledge of DORA and PCI-DSS is a strong plus

Experience in payment services or financial services is a plus

This is how you work as part of a team: Proactive attitude and strong sense of ownership

Excellent stakeholder management and communication skills

Strong analytical and problem-solving capabilities

Ability to challenge risks and controls constructively

Structured, rigorous and detail-oriented approach

Ability to work autonomously in a complex international environment

Continuous learning mindset

Strong collaboration skills across technical and risk functions

Language Skills : English: Mastery

French: Mastery

This is our commitment At Consort Group, you are an expert who we support so that every assignment becomes a step that counts. Attentive and human onboarding

A truly hands-on management style

Continuous training opportunities

Concrete commitments: inclusion, equality, solidarity

A comprehensive HR package: health insurance, TR card, CSE

A culture of feedback and meaningful projects

The recruitment process: An initial phone call with our recruitment team

An HR interview and a job interview with a business engineer

A test or technical interview with one of our experts

A final meeting with your future manager or project manager

And if we're a good fit, we'll get started together

Good to know Location: Porto Contract: Permanent contract Remote work: Hybrid (50%) Salary: From 44 K€ to 56 K€ (depending on experience) gross annual salary Job category: Risk Management / Cybersecurity / Permanent Control

What you will do here, you won't do anywhere else. This moment is yours.