We are seeking a Senior OT/ICS Cybersecurity Specialist to support cybersecurity risk assessment, compliance, and governance activities across Operational Technology (OT) and Industrial Control Systems (ICS) environments.
The role works closely with the GRC team to ensure OT cybersecurity requirements are correctly interpreted, assessed, and aligned with operational and safety constraints.
This is an assessment and advisory role, not an implementation or SOC position.
- Support OT/ICS cybersecurity compliance and gap assessments in line with regulatory and industry standards (e.g., NCA OTCC-1:2022, IEC 62443).
- Translate regulatory cybersecurity requirements into practical assessments for OT environments, including SCADA, PLC, DCS, industrial networks, and SIS.
- Provide technical input to OT cybersecurity risk assessments, including risk identification, impact analysis, and treatment recommendations.
- Assist in building and maintaining the OT Risk Register, ensuring risks are accurately categorized, prioritized, and owned.
- Review OT cybersecurity architecture, including network segmentation, IT/OT separation, and industrial DMZ design.
- Assess the effectiveness and feasibility of OT cybersecurity technical controls without compromising safety or availability.
- Support preparation of OT cybersecurity compliance and risk assessment reports for regulatory and executive audiences.
- Engage with operational, engineering, and GRC stakeholders to ensure findings are operationally realistic and clearly communicated.
- Bachelor’s in Cybersecurity, Engineering, Computer Science, or equivalent.
- 5+ years OT/ICS cybersecurity experience in industrial or critical infrastructure.
- Skilled in risk assessments, compliance, and gap analysis.
- Strong knowledge of IEC 62443, NIST/ISA-IEC, and OT security architecture.
- Ability to assess OT controls with operational and safety awareness.
- Excellent collaboration and reporting skills for GRC, operations, and executive audiences.
Preferred Requirements :
- Experience in OT GRC or regulated environments.
- Certifications: ISA/IEC 62443, ISO/IEC 27001, GICSP, CISSP, or equivalent.