OT Cyber Security Technologist
Working Location
Onsite at operational plants.
Key Responsibilities
- Execute day-to-day Industrial Control System (ICS) activities related to operational technology (OT) security in plants.
- Manage the design and oversee implementation of all security measures linked to ICS applications and systems.
- Conduct risk assessments and develop contingency plans to mitigate foreseeable security threats and protect the confidentiality and integrity of employee, customer, and business information, ensuring compliance with ICS cybersecurity policies and standards.
- Conduct audits of operations to assess compliance with information security policies and relevant regulations through periodic security reviews and self-certification testing.
- Support external audits and assessments (such as penetration tests), perform internal assessments, and track recommendation implementation to ensure compliance.
- Ensure ongoing risk assessment of external and internal threats, and that security practices and controls remain appropriate.
- Analyse risk in the context of critical and significant operational changes, evaluate requirements, conduct task risk assessments, and develop implementation strategies and plans with technical measures in place.
- Commission preparation and implementation of necessary operational security software updates, firewall installations, hardware additions, and authorized technical changes to meet required security levels.
- Design and manage processes for detection, investigation, correction, and/or prosecution of operational security breaches, violations, and incidents.
- Benchmark, analyse, report on, and recommend improvements for OT security infrastructure.
- Collaborate with management to address OT security issues as new equipment, facilities, services, and systems are installed.
- Liaise with governance functions and managers on information security matters such as routine activities and emerging risks.
- Plan, implement, and upgrade security measures and controls to protect digital files and operational security systems against unauthorized access, modification, or destruction.
- Maintain and review security access authorizations.
- Manage network, intrusion detection, and prevention systems.
- Utilize security tools for asset inventory management and risk management reporting to security information and event management systems (SIEM).
- Define, implement, and maintain security manuals, policies, procedures, and instructions.
- Coordinate and act upon further security plans and awareness received from vendors.
- Conduct security assessments of network infrastructure, hosts, and applications.
- Address audit findings related to ICS security and maintain corrective actions.
- Download, validate, and apply the latest antivirus updates, monitor the AV server dashboard, and ensure updates are published to all ICS machines.
- Perform asset identification, monitoring, and analysis using relevant tools and event logs.
- Analyze ICS firewall event logs, DNS, router, and switches events.
- Validate and deploy firmware/software updates and deactivate unnecessary software or access.
- Define and implement backup schedules for all ICS assets including system configurations, machine images, routers, switches, and firewalls.
- Manage user accounts for ICS, network, and security equipment.
- Support project teams with integration of new OT systems into the plant security framework.
- Collect and archive system logs, changes, failure events, etc., to support audits and forensic analysis.
- Ensure implementation activities comply with ICS policies, instructions, and manuals.
Health, Safety, Security, Environment, and Quality
Ensure compliance with all relevant quality, health, safety, and environmental management procedures and controls to guarantee employee safety, compliance, delivery of high-quality services, and responsible environmental stewardship.
Reports
Prepare timely and accurate departmental statements and reports to meet requirements, policies, and standards.
Internal and External Communications
- Language: Fluent English required.
- Attitude: Positive and strong personality.
- Audit Interaction: Ability to communicate and negotiate during internal and external audit observations.
- Internal Contacts:
- Maintenance (PLC/DCS)
- Maintenance Planning
- Information Technology & Security
- Internal Auditors
- External Contacts:
- Contractors
- Government/statutory authorities
- Service providers
- Consultants
- External Auditors
Requirements
- Education: Bachelor's degree in Information Security Technology, Computer Science, or Electronic/Electrical Engineering.
- Certification: ICS certification from SANS is required.
- Additional certifications highly desirable:
- GIAC GICSP (Global Industrial Cybersecurity Professional)
- ISA CAP (Certified Automation Professional)
- ISA/IEC-62443, Advanced SCADA Security, or equivalent
- Industrial Cybersecurity for OPC or OPC-UA training
- ITIL
- Additional certifications highly desirable:
- Experience: At least 3-5 years of field experience in OT cybersecurity within the oil and gas or petrochemical industry.
- Technical Knowledge:
- Expertise in IT/OT ICS areas such as PLC, DCS, PDCS, firewalls, networks, and switches.
- Experience implementing IT/OT security policies and regulation compliance.
- Familiarity with international and national standards such as ISA99, IEC62443, IEC61511, IEC62351, IEC62591, ISO27001, 27002, and 27005.
- Thorough understanding of core operations and information security requirements.
- Experience with ICS, DCS, PDCS, PLC, ESD, servers, routers, switches, and firewalls across several major technologies.
- High exposure to implementing and maintaining Operational Security Management Systems.
- Skills:
- Outstanding interpersonal communication at all levels of organization.
- Excellent planning, time management, decision making, and problem-solving abilities.
- Advanced analytical, conceptual thinking, and customer service orientation.
- Proficient with all related tools and instruments.
- Ability to read and interpret safety rules, operating/maintenance instructions, procedures, technical manuals, and engineering drawings.
- Strong negotiation skills for claims handling.
- Positive, motivated personality.