The project focuses on threat modeling, quantitative/qualitative risk scoring, and proposing mitigation strategies (for example: network segmentation, encryption, access control) to protect production data and ensure operational continuity.
Work is hosted in the R&D department and the assignment is for 1 trainee; the outcome must align with data privacy standards and compliance frameworks.
Key responsibilities / tasks you will do:
Conduct threat modeling for production systems and identify high-risk assets, attack surfaces, and threat scenarios.
Perform risk scoring and business impact analysis to prioritize vulnerabilities and produce a risk register.
Propose practical mitigation strategies (network segmentation, encryption schemes, access control policies, backup and continuity measures) and evaluate trade-offs.
Required expertise and expected skills:
Understanding of cybersecurity principles, secure architecture concepts, and common attack vectors.
Familiarity with business impact analysis, risk mitigation planning, and relevant data privacy / compliance frameworks (mentioning requirements is expected in analyses).
Practical knowledge of network security, encryption basics, and access control models is highly desirable.
Deliverables and outcomes:
A documented threat model for the targeted production environment, including diagrams and identified controls.
A prioritized risk register with scoring methodology, recommended mitigations, and an implementation roadmap.
A final report and presentation demonstrating how proposed measures protect production data and ensure operational continuity.
Departmental context and supervision:
Hosted by R&D with a single trainee position; collaboration with operations and IT security stakeholders is expected.
Regular check-ins and reviews to align mitigation plans with operational constraints and compliance requirements.
How to apply:
To apply, send your CV and a short motivation letter to hr@bakomotors.com.
Use the email subject: "Application – 7 Cybersecurity Risk Assessment PFE" and indicate your availability and any relevant project or coursework experience.