At a Glance
- Tasks: Join our team to enhance OT cybersecurity through red and blue team activities.
- Company: Capula, part of the EDF Group, leading in advanced system integration.
- Benefits: 28 days holiday, flexible working, private healthcare, and mental health support.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: 3-5 years in cyber security with hands-on experience in offensive security.
- Other info: Inclusive workplace celebrating diversity and offering excellent career growth.
The predicted salary is between 36000 - 60000 £ per year.
With a focus on operational technology and digital transformation, Capula, part of the EDF Group, has been a leader in advanced system integration for decades; optimising efficiency and delivering performance on a massive scale. Continuous innovation remains a central focus of our business as we plan for future developments. Our operations span highly regulated and demanding industrial sectors, where we have successfully executed essential projects in energy, water, renewables, and manufacturing.
At Capula, we are committed to fostering an inclusive and equitable workplace where diversity is celebrated in all its forms. We actively encourage applications from individuals of minority backgrounds, underrepresented groups, and those with disabilities. Our goal is to create a supportive environment where everyone can thrive and contribute their unique perspectives.
Summary of Role
We are seeking an experienced OT/ICS Cyber Security Consultant to join our growing team. While the primary focus will be on adversarial red team activities including penetration testing, threat emulation, and resilience validation, the successful candidate will also contribute to blue team functions, such as security architecture, compliance, monitoring, solutions install/configure, risk assessment and incident response. This role demands adaptability, strong problemāsolving skills, and the ability to quickly engage with live and upcoming projects. In addition to deep technical expertise in OT cybersecurity, the candidate will demonstrate excellent communication, client engagement, and collaborative skills to ensure successful project delivery.
Main Activities
- Deliver in conjunction with outsourced partners red team activities including penetration testing, adversary simulation and incident response exercises following defined methodologies.
- Support the planning and execution of security assessments and incident response exercises in OT/ICS environments.
- Develop and implement attack scenarios and detection use cases using frameworks such as MITRE ATT&CK for ICS.
- Assist in the delivery and improvement of crisis simulation exercises and incident response plans.
- Perform vulnerability assessments, threat modelling, and attack path analysis to identify and address security weaknesses.
- Monitor, validate, and enhance security controls and detection capabilities through handsāon testing and analysis.
- Conduct OT/ICS risk assessments and support compliance with relevant standards (e.g., IEC 62443, NIST SP800-82, NISāR).
- Contribute to the deployment, configuration, and maintenance of OT cybersecurity technologies and security monitoring tools.
- Participate in the design and delivery of cybersecurity awareness training for technical and nonātechnical teams.
- Document findings, prepare reports, and provide recommendations to improve cyber resilience.
- Collaborate with internal and external stakeholders to support continuous improvement of security operations and incident response.
- Support proposal development and contribute to service delivery documentation.
- Willingness to travel and work remotely as required.
Essential Requirements
- BS in Engineering, Computer Science, or related discipline, with 3-5 years of practical cyber security experience.
- Handsāon experience in offensive security activities, such as penetration testing, vulnerability assessment, and adversary simulation.
- Working knowledge of ICS/OT environments (e.g., SCADA, PLCs, RTUs) and securing IT/OT interfaces.
- At least one relevant ICS/OT certification (e.g., SANS GICSP, SANS GRID, or IEC 62443).
- Familiarity with ICS protocols (MODBUS, OPC, DNP3) and basic network security principles (switching, routing, firewalls).
- Experience deploying or supporting OT cybersecurity solutions and security monitoring tools.
- Ability to assist in developing attack scenarios and validating security posture against recognised frameworks (e.g., NIST 800-53/82, IEC 62443).
- Exposure to incident response activities, including testing and improving detection and response capabilities.
- Strong communication and stakeholder engagement skills for collaborative work across technical and nonātechnical teams.
- Eligible for UK Cyber Security Council Practitioner registration in a relevant specialism (e.g., Security Testing, Incident Response, Secure System Architecture), or willingness to achieve this within a short timeframe (i.e. already at SFIA Level 4).
- Eligible for SC clearance.
Desirable Requirements
- Ability to work effectively in both engineering and nonāengineering environments, meeting defined responsibilities.
- Certifications such as OSCP, GIAC GPEN, or CREST CRT (red teaming/offensive security).
- Experience collaborating with diverse teams, including third parties and suppliers, to deliver security testing or adversary simulation services.
- Exposure to physical security risk assessments and audits in line with NIS Regulations and NPSA standards.
- Practical experience using offensive security tools and frameworks (e.g., Nessus, Nmap, Metasploit, MITRE ATT&CK for ICS).
- Understanding of Digital Forensics and Incident Response (DFIR) principles and ability to assist in investigations within industrial environments.
Benefits
- 28 days holiday plus bank holidays.
- Flexible working, predominantly office based.
- Pension.
- Life assurance policy.
- Private health care.
- Salary sacrifice programme.
- Mental health assistance programme.
- Cycle to work scheme.
- Green car scheme.
- Support in achieving or maintaining chartered membership recognition (e.g. IET, BCS, CIISEC) and professional memberships fees covered.
ICS OT Cyber Security Consultant in London employer: Capula
Contact Detail:
Capula Recruiting Team
StudySmarter Expert Advice š¤«
We think this is how you could land ICS OT Cyber Security Consultant in London
āØTip Number 1
Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, and donāt be shy to reach out on LinkedIn. You never know who might have the inside scoop on job openings!
āØTip Number 2
Show off your skills! Create a portfolio or a personal website showcasing your projects and achievements in OT cybersecurity. This is a great way to demonstrate your expertise and make a lasting impression on potential employers.
āØTip Number 3
Prepare for interviews by practising common questions and scenarios related to ICS/OT environments. Be ready to discuss your hands-on experience with penetration testing and incident response. Confidence is key!
āØTip Number 4
Donāt forget to apply through our website! Itās the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace ICS OT Cyber Security Consultant in London
Some tips for your application š«”
Tailor Your CV: Make sure your CV is tailored to the ICS OT Cyber Security Consultant role. Highlight your relevant experience in penetration testing and incident response, and donāt forget to mention any certifications you hold that are relevant to the job.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about OT cybersecurity and how your skills align with Capula's mission. Be sure to mention any specific projects or experiences that demonstrate your expertise.
Showcase Your Communication Skills: Since this role involves collaboration with various teams, make sure to highlight your communication skills in both your CV and cover letter. Share examples of how you've successfully engaged with clients or worked in diverse teams.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. Itās the best way to ensure your application gets the attention it deserves, so donāt hesitate to take that step!
How to prepare for a job interview at Capula
āØKnow Your Stuff
Make sure you brush up on your technical knowledge, especially around OT/ICS environments and cybersecurity principles. Be ready to discuss specific tools and frameworks like MITRE ATT&CK for ICS, as well as your hands-on experience with penetration testing and vulnerability assessments.
āØShowcase Your Problem-Solving Skills
Prepare to share examples of how you've tackled complex security challenges in the past. Think about specific incidents where you had to adapt quickly or think on your feet, as this role demands strong problem-solving abilities.
āØCommunicate Clearly
Since this position involves collaboration across technical and non-technical teams, practice explaining complex concepts in simple terms. Be ready to demonstrate your communication skills during the interview, as they are just as important as your technical expertise.
āØEngage with the Company Culture
Capula values diversity and inclusion, so be prepared to discuss how you can contribute to a supportive environment. Show that you understand their commitment to fostering an equitable workplace and how your unique perspective can add value to their team.