At a Glance
- Tasks: Support OT Cyber Security controls and enhance security measures in a dynamic environment.
- Company: Join a leading firm in the industrial and utilities sector focused on cyber security.
- Benefits: Competitive daily rate, flexible work location, and opportunities for professional growth.
- Why this job: Make a real impact on OT security while working with cutting-edge technology.
- Qualifications: Experience in OT security, strong communication skills, and relevant certifications required.
- Other info: Work 2 days a week onsite in London or Capenhurst with excellent career advancement potential.
Contract: 12 months
Location: 2 days per week onsite (London or Capenhurst)
Industry: Industrial / Utilities / Nuclear
Clearance: SC, must be a British Citizen
Start: ASAP/Jan
Rate - £575 - 650/day inside IR35
Purpose of the Role
The OT Cyber Security Specialist will support the design, development, integration, and delivery of OT security controls as part of a wider OT Cyber Security Enhancement Programme. The role reports to the Head of OT Cyber Security & Cyber Assurance, with matrix reporting to the OT Security Programme Manager, and sits within the Group Information Security Department.
The successful candidate must be experienced in developing OT cyber security procedures, maintaining and embedding Cyber Security Management Systems (CSMS), creating technical documentation, and delivering training and awareness activities.
Key Accountabilities
- Programme Support and Delivery
- Develop and update site management system procedures to align with OT Cyber Security Standards.
- Amend existing procedures based on OT security review findings, embedding improvements in the global CSMS.
- Collaborate with site Information Security Managers to integrate changes and support risk assessment refreshes.
- Coordinate and prioritise risk treatment activities in line with updated procedures.
- Support the OT Security Programme Manager in delivering control uplifts, including documentation updates.
- Gap Analysis & Risk Assessment
- Lead gap assessments against the OT cyber security standard and global OT risk framework.
- Define risk mitigation requirements in collaboration with engineering, local security, and technical teams.
- Work with engineering, design authority, IT, site ISMs, and maintenance teams to embed security controls in the project lifecycle.
- Support assurance reviews for new and existing projects to confirm compliance with reference architectures and security standards.
- Liaise with project teams and vendors to ensure risk considerations are embedded from design to deployment.
- Security Awareness & Training
- Develop and support the delivery of a global OT security awareness campaign.
- Prepare and deliver tailored training materials to stakeholders across the OT governance structure.
- Work with marketing/communications to coordinate the rollout of security awareness materials.
- Business Engagement & Communications
- Prepare and communicate assessment results, recommendations, guidance, and industry trends to operational and tactical stakeholders.
- Support KPI reporting and contribution of security performance metrics to leadership.
Job Requirements
- Vocational Qualifications (Preferred)
- Bachelor's or Master's degree in Automation, Robotics, Cyber Security, Computer Science, or related discipline.
- Relevant OT/IT cyber security certifications such as: ISA/IEC 62443 Series, CISSP / CISM / CISACEHGICSPCSSA.
- Behavioural Competencies
- Strong collaboration and teamwork.
- Commitment to continuous improvement.
- Accountability and empowerment.
- Transparency, respect, and inclusivity.
- Strong focus on safety and integrity.
- Long-term, strategic thinking.
- Professional Skills
- Excellent written and verbal communication skills, able to tailor to technical and non-technical audiences.
- Proven experience delivering high-quality work independently or within cross-disciplinary teams.
- Strong stakeholder management and relationship-building skills.
- Effective problem-solving and collaboration capabilities.
- Technical Skills Required:
- Minimum 3+ years OT Security experience within programme design/delivery or security engineering.
- Strong experience in procedural writing and documentation creation.
- Experience developing and maintaining Cyber Security Management Systems (CSMS).
- Proven application of security standards and best practices including NIST CSF, ISO 27001, IEC 62443, and NIS regulations.
- Strong understanding of OT systems, networks, architecture, protocols, and vulnerabilities.
- Experience in: Developing OT security procedures and processes, end-to-end risk assessment, management, and treatment, conducting compliance assessments and assurance reviews, translating business needs into technical specifications, delivering training and awareness activities to promote a strong cyber security culture.
- Additional Requirements
- Must hold current SC clearance (essential).
- No dual citizenship.
- Must be able to work onsite 2 days per week in London or Capenhurst.
- Experience working in industrial, utilities, or nuclear environments is strongly preferred.
OT Cyber Security Analyst employer: Morson Edge
Contact Detail:
Morson Edge Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land OT Cyber Security Analyst
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the OT Cyber Security field. Attend industry events, join relevant online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Prepare a portfolio or a presentation that highlights your experience with OT security procedures and risk assessments. When you get the chance to chat with potential employers, use this to demonstrate how you can add value to their team.
✨Tip Number 3
Practice makes perfect! Before any interviews, do some mock interviews with friends or mentors. Focus on articulating your experience with Cyber Security Management Systems and your approach to embedding security controls. The more comfortable you are, the better you'll perform!
✨Tip Number 4
Apply through our website! We’ve got loads of opportunities waiting for talented individuals like you. Make sure to tailor your application to highlight your experience in developing OT security procedures and your understanding of compliance assessments. Let’s get you that dream job!
We think you need these skills to ace OT Cyber Security Analyst
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in OT cyber security. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Skills: Don’t just list your qualifications; demonstrate how your skills align with the role. Talk about your experience with Cyber Security Management Systems and any relevant certifications you've got under your belt.
Be Clear and Concise: When writing your application, keep it straightforward. We appreciate clarity, so avoid jargon unless it's necessary. Make sure your points are easy to read and get straight to the point.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're keen on joining our team!
How to prepare for a job interview at Morson Edge
✨Know Your OT Cyber Security Standards
Familiarise yourself with the key OT cyber security standards like ISA/IEC 62443 and NIST CSF. Be ready to discuss how you've applied these standards in your previous roles, especially in developing procedures and conducting risk assessments.
✨Showcase Your Documentation Skills
Prepare examples of technical documentation you've created, such as Cyber Security Management Systems (CSMS) or training materials. Highlight your experience in procedural writing and how it has contributed to successful project outcomes.
✨Demonstrate Collaboration Experience
Be prepared to share specific instances where you've worked with cross-disciplinary teams, such as engineering and IT, to embed security controls. Emphasise your teamwork skills and how they’ve led to effective risk mitigation.
✨Engage with Stakeholder Communication
Think about how you’ve communicated complex security concepts to both technical and non-technical audiences. Prepare to discuss your approach to delivering assessment results and recommendations, ensuring clarity and relevance for stakeholders.