At a Glance
- Tasks: Identify and manage OT vulnerabilities using cyber tools and assessments.
- Company: Join SGN, a leader in innovative energy solutions and safety.
- Benefits: Competitive salary, hybrid work, enhanced family leave, and wellness support.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
- Why this job: Make a real impact on cybersecurity in the evolving gas industry.
- Qualifications: 2 years of cyber security experience in an OT environment required.
The predicted salary is between 63000 - 77000 £ per year.
We are looking for an experienced OT Vulnerability Analyst to ensure that OT vulnerabilities are identified by cyber tools, assessments and audits are assessed, prioritized, and risk managed appropriately and in line with policies. You will also be responsible for providing relevant technical/non-technical security and providing reports to the vulnerability manager.
Here’s how you will contribute…
- Provide cyber security assurance activities by ensuring implemented solutions are a replica of agreed and approved architecture definition documents.
- Where required, propose solutions and coordinate delivery of mitigating actions to ensure risk levels are aligned with risk appetite.
- Work alongside and coordinate our third-party vendors including ‘managed security services provider’ (MSSP), penetration testers, attack path mapping and SOC operators including following up remediation work and reports.
- Work with the technical security and assurance team to help deliver new security tooling.
- Be a Security touchpoint for Project Business Analysts and Project Management and provide project with security consultations, supporting OT Security projects within the Cyber programme.
- Security Architecture and Design - Review both high/low level architecture definition documents for compliance against security policies, standards and regulatory requirements pertinent to OT environments.
- Attend relevant Architecture Review Board and Technical Design Authority meetings providing sign-off to designs created to deliver technical solutions into the OT environment.
- Produce in-flight project functional and non-functional security requirements and embed into existing processes.
- Post-implementation / pre-go live auditing of initial requirements for Security OT projects, checking agreed design proposals matched against delivered solutions.
- Operate collaboratively with the IT/OT Security Leads and the wider Corporate IT team to deliver the required solutions.
- Configure vulnerabilities management tools to ensure security vulnerabilities are identified across the SGN IT and OT estate.
- Triage, assess and prioritize identified security vulnerabilities, ensure mitigating controls are identified and implemented where necessary.
- Track remediation, risks, and exceptions and provide the Security Assurance function with vulnerability metrics and reports which include a view of outstanding vulnerabilities, plans for remediation, applied exceptions and security risks.
- Support continued service improvements initiatives.
What you will need:
- Must have 2 years’ cyber security experience within an OT environment with strong OT / ICS knowledge about products, architectures and workflows.
- Must have proven expertise in three of the following security domain areas: Vulnerability Assessment and Management, Security Risk and Compliance, Security Architecture, Endpoint Protection, Network Security, and Security Engineering.
- Good understanding and practical experience of Cyber Security Frameworks and standards such as NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc.
- Good understanding of Cyber Assurance Framework and experience with working with Regulators and providing compliance updates for OT environment.
- Knowledge of the Purdue Model and experience of application of network segmentation to OT systems to bolster the cybersecurity.
- Role will require Security Clearance.
Not sure you meet every requirement? Research shows some people – particularly women and those from underrepresented backgrounds – may hesitate to apply unless they meet every criteria. At SGN, we value diverse backgrounds, experiences and perspectives. If this role interests you but you’re not sure you tick every box, we’d still love to hear from you. You might be just who we’re looking for – now or in the future.
Why SGN? SGN leads pioneering research and development for a net-zero energy system. Our innovative technologies are transforming the gas industry while keeping people safe and warm. We are an award-winning employer, including CCA Gold Awards for Great Places to Work and Inclusivity and Accessibility, and a proud Gold member of the Armed Forces Covenant.
If you require any accommodations or support during the application process, reach out to us. We're here to help ensure an inclusive and accessible experience for everyone.
OT Vulnerability Analyst in Portsmouth employer: SGN Your gas. Our network.
SGN is an award-winning employer that prioritises innovation and inclusivity, making it an excellent place for the Head of AI to thrive. With a strong commitment to employee growth, a hybrid work culture, and comprehensive benefits including enhanced family leave and a joint-contribution pension, SGN fosters a supportive environment where every team member can contribute to pioneering advancements in the gas industry. Located in vibrant cities like London, Portsmouth, and Glasgow, employees enjoy not only professional development but also a fulfilling work-life balance in dynamic urban settings.
Contact Details:
SGN Your gas. Our network. Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land OT Vulnerability Analyst in Portsmouth
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including SGN Your gas. Our network., love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through SGN Your gas. Our network.
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at SGN Your gas. Our network.. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace OT Vulnerability Analyst in Portsmouth
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at SGN Your gas. Our network. insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to SGN Your gas. Our network. that you’re committed to staying ahead in the game.
How to prepare for a job interview at SGN Your gas. Our network.
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at SGN Your gas. Our network. to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at SGN Your gas. Our network..
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.