At a Glance
- Tasks: Identify and manage OT vulnerabilities using cyber tools and assessments.
- Company: SGN is a leader in innovative energy solutions, focusing on safety and sustainability.
- Benefits: Enjoy competitive pay, enhanced maternity/paternity leave, life assurance, and a cycle-to-work scheme.
- Why this job: Join a mission-driven team dedicated to keeping communities safe and warm with cutting-edge technology.
- Qualifications: 2 years of cyber security experience in an OT environment; expertise in key security domains required.
- Other info: Security Clearance is necessary for this role.
The predicted salary is between 46000 - 58000 £ per year.
An experienced OT Vulnerability Analyst to ensure that OT vulnerabilities are identified by cyber tools, assessments and audits are assessed, prioritized, and risk managed appropriately and in line with policies. You will also be responsible for providing relevant technical/non-technical security and providing reports to the vulnerability manager.
How you’ll support us on our mission to keep people safe and warm:
- Provide cyber security assurance activities by ensuring implemented solutions are a replica of agreed and approved architecture definition documents.
- Where required, propose solutions and coordinate delivery of mitigating actions to ensure risk levels are aligned with risk appetite.
- Work alongside and coordinate our third-party vendors including 'managed security services provider' (MSSP), penetration testers, attack path mapping and SOC operators including following up remediation work and reports.
- Work with the technical security and assurance team to help deliver new security tooling.
- Be a Security touchpoint for Project Business Analysts and Project Management and provide project with security consultations, supporting OT Security projects within the Cyber programme.
- Review both high/low level architecture definition documents for compliance against security policies, standards and regulatory requirements pertinent to OT environments.
- Attend relevant Architecture Review Board and Technical Design Authority meetings providing sign-off to designs created to deliver technical solutions into the OT environment.
- Produce in-flight project functional and non-functional security requirements and embed into existing processes.
- Post-implementation / pre-go live auditing of initial requirements for Security OT projects, checking agreed design proposals matched against delivered solutions.
- Operate collaboratively with the IT/OT Security Leads and the wider Corporate IT team to deliver the required solutions.
- Configure vulnerabilities management tools to ensure security vulnerabilities are identified across the SGN IT and OT estate.
- Triage, assess and prioritize identified security vulnerabilities, ensure mitigating controls are identified and implemented where necessary.
- Track remediation, risks, and exceptions and provide the Security Assurance function with vulnerability metrics and reports which include a view of outstanding vulnerabilities, plans for remediation, applied exceptions and security risks.
- Support continued service improvements initiatives.
What you’ll need:
We’re looking for a blend of skills and attributes that make you a great fit for this role. If you don’t tick every box, don’t worry - we provide tailored learning and development programs to help you grow and succeed with us.
- Must have 2 years’ cyber security experience within an OT environment with strong OT / ICS knowledge about products, architectures and workflows.
- Must have proven expertise in three of the following security domain areas: Vulnerability Assessment and Management, Security Risk and Compliance, Security Architecture, Endpoint Protection, Network Security, and Security Engineering.
- Good understanding and practical experience of Cyber Security Frameworks and standards such as NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc.
- Good understanding of Cyber Assurance Framework and experience with working with Regulators and providing compliance updates for OT environment.
- Knowledge of the Purdue Model and experience of application of network segmentation to OT systems to bolster the cybersecurity.
- Role will require Security Clearance.
Why SGN?
SGN is a leader in pioneering research and development toward a net-zero energy system. Our cutting-edge technologies and innovative thinking are driving change in the gas industry, all while keeping people safe and warm.
OT Vulnerability Analyst employer: SGN
Contact Detail:
SGN Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land OT Vulnerability Analyst
✨Tip Number 1
Familiarise yourself with the specific cyber security frameworks mentioned in the job description, such as NIST and ISO standards. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the OT security field through platforms like LinkedIn. Engaging with industry experts can provide insights into current trends and challenges, which you can discuss during your interview.
✨Tip Number 3
Prepare to discuss real-world examples of how you've managed vulnerabilities in an OT environment. Being able to articulate your hands-on experience will set you apart from other candidates.
✨Tip Number 4
Stay updated on the latest developments in OT security technologies and tools. Showing that you're proactive about learning and adapting to new solutions will impress the hiring team at SGN.
We think you need these skills to ace OT Vulnerability Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your relevant experience in cyber security, particularly within an OT environment. Emphasise your expertise in vulnerability assessment and management, as well as any specific frameworks you are familiar with.
Craft a Strong Cover Letter: In your cover letter, explain why you are passionate about the role of OT Vulnerability Analyst. Mention how your skills align with the job requirements and how you can contribute to SGN's mission of safety and innovation.
Showcase Relevant Projects: If you have worked on specific projects related to cyber security or OT environments, include these in your application. Detail your role, the challenges faced, and the outcomes achieved to demonstrate your hands-on experience.
Highlight Continuous Learning: Mention any ongoing training or certifications you are pursuing in cyber security. This shows your commitment to professional development and staying updated with industry standards, which is crucial for this role.
How to prepare for a job interview at SGN
✨Know Your Cyber Security Frameworks
Familiarise yourself with key cyber security frameworks such as NIST, ISO 27001, and IEC62443. Be prepared to discuss how these frameworks apply to operational technology (OT) environments and how you've implemented them in past roles.
✨Demonstrate Your OT Knowledge
Showcase your understanding of operational technology and industrial control systems (ICS). Be ready to explain specific products, architectures, and workflows you've worked with, as this will highlight your relevant experience.
✨Prepare for Technical Questions
Expect technical questions related to vulnerability assessment and management, security architecture, and network security. Brush up on your knowledge in these areas and think of examples from your previous work that demonstrate your expertise.
✨Highlight Collaboration Skills
Since the role involves working with various teams and third-party vendors, be prepared to discuss your experience in collaborative projects. Share examples of how you've successfully coordinated with others to achieve security goals.