OT Vulnerability Analyst

OT Vulnerability Analyst

Portsmouth Full-Time 44000 - 58000 £ / year (est.) No home office possible
C

At a Glance

  • Tasks: Identify and manage OT vulnerabilities using cyber tools and assessments.
  • Company: Join SGN, a leader in innovative energy solutions focused on safety and sustainability.
  • Benefits: Enjoy competitive pay, enhanced maternity/paternity leave, life assurance, and more perks.
  • Why this job: Be part of a mission-driven team ensuring safety and warmth in communities.
  • Qualifications: 2 years of cyber security experience in OT environments required; expertise in key security domains preferred.
  • Other info: Security Clearance is necessary for this role.

The predicted salary is between 44000 - 58000 £ per year.

An experienced OT Vulnerability Analyst to ensure that OT vulnerabilities are identified by cyber tools, assessments and audits are assessed, prioritized, and risk managed appropriately and in line with policies. You will also be responsible for providing relevant technical/non-technical security and providing reports to the vulnerability manager.

We deliver safety, warmth, and comfort to homes and businesses across the community. Whether you’re supporting from the office or working on the front line, every role plays a part.

How you’ll support us on our mission to keep people safe and warm:

  • Provide cyber security assurance activities by ensuring implemented solutions are a replica of agreed and approved architecture definition documents.
  • Where required, propose solutions and coordinate delivery of mitigating actions to ensure risk levels are aligned with risk appetite.
  • Work alongside and coordinate our third-party vendors including ‘managed security services provider’ (MSSP), penetration testers, attack path mapping and SOC operators including following up remediation work and reports.
  • Work with the technical security and assurance team to help deliver new security tooling.
  • Be a Security touchpoint for Project Business Analysts and Project Management and provide project with security consultations, supporting OT Security projects within the Cyber programme.
  • Review both high/low level architecture definition documents for compliance against security policies, standards and regulatory requirements pertinent to OT environments.
  • Attend relevant Architecture Review Board and Technical Design Authority meetings providing sign-off to designs created to deliver technical solutions into the OT environment.
  • Produce in-flight project functional and non-functional security requirements and embed into existing processes.
  • Post-implementation / pre-go live auditing of initial requirements for Security OT projects, checking agreed design proposals matched against delivered solutions.
  • Operate collaboratively with the IT/OT Security Leads and the wider Corporate IT team to deliver the required solutions.
  • Configure vulnerabilities management tools to ensure security vulnerabilities are identified across the SGN IT and OT estate.
  • Triage, assess and prioritize identified security vulnerabilities, ensure mitigating controls are identified and implemented where necessary.
  • Track remediation, risks, and exceptions and provide the Security Assurance function with vulnerability metrics and reports which include a view of outstanding vulnerabilities, plans for remediation, applied exceptions and security risks.
  • Support continued service improvements initiatives.

What you’ll need:

We’re looking for a blend of skills and attributes that make you a great fit for this role. If you don’t tick every box, don’t worry – we provide tailored learning and development programs to help you grow and succeed with us.

  • Must have 2 years’ cyber security experience within an OT environment with strong OT / ICS knowledge about products, architectures and workflows.
  • Must have proven expertise in three of the following security domain areas: Vulnerability Assessment and Management, Security Risk and Compliance, Security Architecture, Endpoint Protection, Network Security, and Security Engineering.
  • Good understanding and practical experience of Cyber Security Frameworks and standards such as NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc.
  • Good understanding of Cyber Assurance Framework and experience with working with Regulators and providing compliance updates for OT environment.
  • Knowledge of the Purdue Model and experience of application of network segmentation to OT systems to bolster the cybersecurity.
  • Role will require Security Clearance.

Why SGN?

SGN is a leader in pioneering research and development toward a net-zero energy system. Our cutting-edge technologies and innovative thinking are driving change in the gas industry, all while keeping people safe and warm.

If you require any accommodations or support during the application process, reach out to us. We’re here to help ensure an inclusive and accessible experience for everyone.

OT Vulnerability Analyst employer: Cornerstone

At SGN, we pride ourselves on being an exceptional employer, offering a supportive work culture that prioritises employee well-being and professional growth. With competitive salaries, a comprehensive benefits package including enhanced maternity/paternity pay and a cycle-to-work scheme, we empower our team members to thrive in their roles while contributing to our mission of delivering safety and comfort to communities. Join us in a dynamic environment where your expertise as an OT Vulnerability Analyst will be valued and where you can make a meaningful impact in the evolving landscape of cybersecurity.
C

Contact Detail:

Cornerstone Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land OT Vulnerability Analyst

✨Tip Number 1

Familiarise yourself with the specific cyber security frameworks mentioned in the job description, such as NIST and ISO standards. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and understanding of the requirements for the role.

✨Tip Number 2

Network with professionals in the OT security field through platforms like LinkedIn or industry-specific forums. Engaging with others can provide insights into current trends and challenges, which you can reference in your discussions with us.

✨Tip Number 3

Prepare to showcase your experience with vulnerability management tools. Be ready to discuss specific tools you've used, how you've configured them, and the outcomes of your assessments, as this is a key aspect of the role.

✨Tip Number 4

Understand the Purdue Model and be prepared to explain how you've applied network segmentation in previous roles. This knowledge will be crucial in demonstrating your fit for the position and your ability to enhance our cybersecurity posture.

We think you need these skills to ace OT Vulnerability Analyst

Cyber Security Experience in OT Environment
Vulnerability Assessment and Management
Security Risk and Compliance
Security Architecture
Endpoint Protection
Network Security
Security Engineering
Knowledge of Cyber Security Frameworks (NCSC, NIST, ISO 27001, ISO 27005, IEC62443)
Understanding of Cyber Assurance Framework
Experience with Regulators and Compliance Updates
Knowledge of the Purdue Model
Application of Network Segmentation to OT Systems
Technical Report Writing
Collaboration with Third-Party Vendors
Configuration of Vulnerability Management Tools
Risk Management and Mitigation

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your relevant experience in cyber security, particularly within OT environments. Emphasise your expertise in vulnerability assessment and management, as well as any familiarity with Cyber Security Frameworks like NIST or ISO standards.

Craft a Strong Cover Letter: In your cover letter, explain why you are passionate about the role of an OT Vulnerability Analyst. Mention specific projects or experiences that demonstrate your skills in managing vulnerabilities and working with security tools, and how they align with the company's mission.

Showcase Relevant Skills: Clearly outline your technical skills related to security architecture, endpoint protection, and network security. Use bullet points to make it easy for the hiring manager to see your qualifications at a glance.

Proofread Your Application: Before submitting your application, carefully proofread all documents for spelling and grammatical errors. A polished application reflects your attention to detail, which is crucial in a security role.

How to prepare for a job interview at Cornerstone

✨Know Your Cyber Security Frameworks

Familiarise yourself with key cyber security frameworks such as NIST, ISO 27001, and IEC62443. Be prepared to discuss how these frameworks apply to operational technology (OT) environments and how you've implemented them in past roles.

✨Demonstrate Your Technical Expertise

Highlight your experience in vulnerability assessment and management, security architecture, and endpoint protection. Be ready to provide specific examples of how you've identified and mitigated vulnerabilities in OT systems.

✨Showcase Your Collaboration Skills

This role requires working closely with various teams and third-party vendors. Prepare to discuss instances where you've successfully collaborated on projects, particularly in delivering security solutions or managing risks.

✨Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about challenges you've faced in previous roles and how you approached them, especially regarding compliance and risk management in OT environments.

OT Vulnerability Analyst
Cornerstone
C
  • OT Vulnerability Analyst

    Portsmouth
    Full-Time
    44000 - 58000 £ / year (est.)

    Application deadline: 2027-07-09

  • C

    Cornerstone

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>