OT Cyber and Compliance Manager

OT Cyber and Compliance Manager

Full-Time 70000 - 90000 £ / year (est.) Home office (partial)
RES

At a Glance

  • Tasks: Lead OT cyber security and compliance for renewable energy assets, ensuring robust protection against threats.
  • Company: Join a pioneering renewable energy company focused on innovation and sustainability.
  • Benefits: Enjoy a competitive salary, flexible remote work, and opportunities for professional growth.
  • Other info: Dynamic role with potential for significant impact and career advancement.
  • Why this job: Make a real difference in the renewable sector while tackling exciting cyber challenges.
  • Qualifications: 7+ years in OT cyber security with strong governance and technical skills required.

The predicted salary is between 70000 - 90000 £ per year.

As the global renewable energy sector scales at pace, the systems connecting our wind, solar, and battery assets — SCADA platforms, remote monitoring environments, and OT networks — are increasingly targeted by sophisticated threat actors. The emergence of AI-enabled attack toolkits has lowered the barrier to large-scale OT intrusions, while a rapidly tightening regulatory landscape across the UK, Europe, the US, and Australia is placing new and binding compliance obligations on operators of energy infrastructure.

To address this challenge, we are creating a new role of OT Cyber & Compliance Manager within the OT & SCADA function. This is a high-impact role combining governance, technical delivery, and commercial development. The post-holder will be the owner of OT cyber security across our managed portfolio — building the compliance programmes, the technical controls, and ultimately the client-facing service capability that positions the business as a trusted partner on cyber resilience in renewables.

This role will ultimately ensure that:

  • Our OT infrastructure and managed sites meet all applicable regulatory requirements across every jurisdiction in which we operate
  • Clients receive confident, accurate responses to cyber and compliance questions during procurement and throughout contract delivery
  • The Jupiter OT tenant and site-level OT networks are architected, hardened, and continuously maintained to industry-leading standards
  • A new, revenue-generating OT cyber compliance service offering is built, launched, and led from within the OT team
  • Patching, vulnerability management, and penetration testing happen systematically, with clear ownership and evidence trails

The post-holder will work in close partnership with the Head of OT Architecture, regional OT managers, and the Group Cyber team. The role requires occasional site visits to wind, solar, and battery assets across the portfolio.

Key Accountabilities

OT Cyber Governance & Compliance

  • Design, build, and own a global OT cyber compliance programme covering NIS2 (Europe), the UK Cyber Resilience Act, NERC CIP Low-Impact (US), and the Security of Critical Infrastructure Act (SOCI, Australia)
  • Ensure local compliance managers and regional teams have the systems, policies, procedures, and evidence repositories in place to meet their respective local regulatory requirements
  • Maintain the OT risk register, track remediation actions, and provide OT input into the enterprise cyber risk framework
  • Own audit readiness across all regulatory programmes; lead self-certification processes and support external audits with structured, credible evidence
  • Liaise with the Group Cyber function to ensure consistency between IT and OT compliance approaches

Client Engagement & Business Development

  • Lead the OT cyber response to client RfP processes and vendor risk assessments, providing technically authoritative and commercially compelling answers to cyber and compliance questionnaires
  • Build the internal business case for, and lead early client engagements in, a new OT cyber compliance services offering for assets owners
  • Work with Business Development leads to define contractual language around OT cyber obligations, clarifying what we do and do not offer in client agreements
  • Shape and articulate our OT cyber services proposition to clients, positioning the organisation as a market leader in OT security for renewables

Technical OT Security

  • Configure, maintain, and continuously evolve the Jupiter OT tenant in Azure, including security architecture, firewall rules, VPN/IPSEC configurations, and vendor remote access controls
  • Establish and own systematic programmes for OT patching, vulnerability scanning, and penetration testing across managed assets and centralised infrastructure
  • Lead OT incident response and recovery activities in relation to cyber events, working closely with Group Cyber colleagues
  • Develop and implement OT-specific cyber security standards, hardening baselines, and monitoring controls aligned to recognised frameworks (NIST CSF, IEC 62443, ISA/IEC)
  • Maintain an OT asset inventory and manage vulnerability risk across the portfolio

OT Network & Architecture

  • Conduct site visits to wind, solar, and battery power plants to assess the current state of OT network equipment and infrastructure
  • Lead OT network deployment activities at sites, ensuring security-by-design is embedded from the outset
  • Support the Head of OT Architecture on OT network design standards, patterns, and architecture roadmaps, acting as the security authority on architecture decisions
  • Work with regional teams to standardise OT network configurations globally, reducing complexity and improving cyber posture across the fleet

Knowledge & Skills

Experience & Qualifications

Knowledge

  • Extensive knowledge of OT/ICS cyber security principles, frameworks, and standards including NIST CSF, IEC 62443, NERC CIP, and ISO 27001
  • Deep understanding of OT network architecture, secure design patterns, and common vulnerabilities in SCADA, EMS, and DCS environments
  • Thorough knowledge of cyber regulatory regimes applicable to energy infrastructure: NIS2, UK Cyber Resilience Act, NERC CIP, and SOCI
  • Practical knowledge of Azure OT/IT security services including Microsoft Defender for IoT, Azure Firewall, and VPN/IPSEC configuration
  • Familiarity with industrial communication protocols: OPC UA/DA, Modbus, MQTT, DNP3, and IEC 61850

Skills

  • Able to translate complex cyber and compliance requirements into practical policies, controls, and audit-ready evidence
  • Strong commercial acumen; able to engage clients credibly on cyber risk and build proposals that grow revenue
  • Excellent written communication — able to produce clear, professional responses to RfP questionnaires, audit submissions, and board-level reports
  • Collaborative and influential; able to work across OT, IT, Legal, and Business Development functions without direct authority
  • Pragmatic and delivery-focused, with an ability to balance rigour and pace in a fast-moving operational environment
  • Comfortable working on-site at wind, solar, and battery assets, including in remote locations

Experience

  • 7+ years' experience in OT/ICS cyber security roles, with demonstrable delivery across both governance and technical domains
  • Proven experience designing or managing compliance programmes under at least one of: NERC CIP, SOCI, NIS2, or equivalent CNI cyber regulation
  • Hands-on experience configuring and managing OT network infrastructure — firewalls, VPNs, remote access — in an operational energy or utilities environment
  • Experience conducting or commissioning vulnerability assessments and penetration tests on OT/SCADA systems and managing remediation
  • Track record of engaging clients or senior stakeholders on cyber topics — through RfP responses, audit support, or advisory engagements
  • Experience working in, or closely alongside, renewable energy, utilities, or other critical infrastructure operations
  • Experience designing or delivering OT cyber services to external clients, including scoping, commercial framing, and client management
  • Familiarity with Microsoft Azure OT security tooling (Defender for IoT, Sentinel) and cloud-connected OT architecture
  • Experience with OT site network assessments and deployment across wind, solar, or battery assets
  • Knowledge of SCADA platforms common in renewables (e.g. Siemens WinCC, GE iFIX, OSIsoft PI/AF, Ignition)

Qualifications

  • GICSP (Global Industrial Cyber Security Professional) or equivalent OT security certification
  • CISSP, CISM, or equivalent information security qualification
  • Azure security certifications (AZ-500 or SC-200)
  • Degree in Computer Science, Electrical/Electronic Engineering, Cyber Security, or related discipline

OT Cyber and Compliance Manager employer: RES

At RES, we pride ourselves on being an excellent employer, offering a dynamic work culture that fosters collaboration and innovation in the renewable energy sector. As a Solar Asset Monitor, you will benefit from comprehensive training opportunities, a supportive team environment, and the chance to contribute to sustainable energy solutions while enjoying a flexible work schedule. Our commitment to diversity and employee growth makes RES a rewarding place to build your career in the thriving UK solar industry.

RES

Contact Details:

RES Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land OT Cyber and Compliance Manager

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including RES, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through RES

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at RES. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace OT Cyber and Compliance Manager

OT Cyber Security Principles
NIST CSF
IEC 62443
NERC CIP
ISO 27001
Azure Security Services
Vulnerability Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at RES insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to RES that you’re committed to staying ahead in the game.

How to prepare for a job interview at RES

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at RES to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at RES.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.