At a Glance
- Tasks: Secure our distilleries and manufacturing sites by assessing and improving OT security practices.
- Company: Join William Grant & Sons, a leader in the spirits industry known for innovation and quality.
- Benefits: Enjoy competitive salary, generous holidays, private healthcare, and personal development resources.
- Why this job: Be part of a dynamic team enhancing security in cutting-edge operational technology environments.
- Qualifications: Proven experience with OT security frameworks and strong technical knowledge of SCADA/ICS/IIoT systems required.
- Other info: Opportunity to work in Glasgow with a focus on continuous improvement and collaboration.
The predicted salary is between 36000 - 60000 £ per year.
At William Grant & Sons, Operational Technology underpins our manufacturing and supply chain excellence. As an Information Security Specialist focusing on OT, you will play a pivotal role in securing our distilleries, manufacturing sites, SCADA/ICS/IIoT environments, and related supply chains. You’ll partner with site leaders, IT and OT teams, and cross-functional stakeholders to embed robust security practices across OT systems, ensuring the resilience and integrity of our operational footprint while supporting innovation and efficiency.
Main Responsibilities
- Lead security assessments across manufacturing sites and distilleries, focusing on SCADA, ICS, and IIoT systems, identifying vulnerabilities and driving remediation.
- Build a robust Information Security Management System (ISMS) aligned with IEC standards, collaborating with site leaders, OT engineers, and IT teams to ensure compliance with OT security frameworks like IEC, NIST CSF, and NIS2.
- Manage third-party OT risks by conducting Vendor Security Assurance Questionnaires (VSAQs) and security reviews to ensure external partners meet WG&S expectations.
- Help develop the OT governance roadmap in line with industry best practices and organizational risk appetite.
- Monitor and advise on the convergence of physical and cyber threats at manufacturing and distillery sites, working with physical security and facilities teams to manage blended risks.
- Provide guidance during OT security incidents, supporting triage, containment, and post-incident analysis to minimize operational disruption.
- Assist the Information Security Leader with investigations related to Operational Technology, contributing technical expertise, evidence gathering, and remediation recommendations.
- Address OT-related security tickets in Assyst to ensure prompt resolution.
Our Ideal Candidate
You are proactive, technically skilled, and passionate about securing OT environments with strong analytical abilities. Required skills include:
- Proven experience with OT security frameworks and standards (e.g., IEC, NIST CSF for OT), assessing and improving OT governance.
- Strong technical knowledge of SCADA/ICS/IIoT security, including OT architectures, protocols, and risk vectors.
- Experience managing third-party OT risks, including conducting VSAQs or similar assessments.
- Ability to develop and implement OT security roadmaps, translating frameworks into controls and projects.
- Incident response experience in OT, aiding containment and recovery to reduce production impact.
- Understanding of physical and cyber security convergence, collaborating with facilities and security teams to mitigate risks.
- Excellent communication skills for translating complex security concepts to diverse stakeholders.
- Problem-solving skills with attention to detail to identify vulnerabilities and recommend mitigations.
- Knowledge of supply chain and logistics technology security considerations.
Desirable but not essential:
- OT security certifications (e.g., GICSP).
- Experience in spirits, manufacturing, or process industries with large-scale OT deployments.
- Knowledge of relevant regulatory and compliance requirements.
- Experience reviewing penetration tests and vulnerability scans for OT systems.
What we can offer you
- Competitive salary and benefits, including a bonus plan.
- Generous holiday entitlement with buy/sell options.
- Private Healthcare and Doctor@Hand (remote GP service).
- Defined contribution pension plan with company contributions.
- Employee Assistance Programme for support on various issues.
- Life Assurance covering eight times your salary.
- Product allocation of our brands.
- Cycle to Work scheme.
- Charity support program.
- Learning resources for personal development.
Information Security Specialist (Operational Technology) employer: William Grant & Sons
Contact Detail:
William Grant & Sons Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Specialist (Operational Technology)
✨Tip Number 1
Familiarise yourself with the specific OT security frameworks mentioned in the job description, such as IEC and NIST CSF. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the Operational Technology field, especially those who have experience in manufacturing or distilleries. Engaging with industry experts can provide insights into the challenges they face and how you can position yourself as a solution.
✨Tip Number 3
Prepare to discuss real-world examples of how you've managed third-party OT risks or conducted security assessments. Being able to share specific experiences will showcase your practical knowledge and problem-solving skills.
✨Tip Number 4
Stay updated on the latest trends and threats in OT security, particularly regarding SCADA, ICS, and IIoT systems. This knowledge will not only enhance your discussions during the interview but also show that you're proactive about continuous improvement in the field.
We think you need these skills to ace Information Security Specialist (Operational Technology)
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Information Security Specialist (Operational Technology) position. Familiarise yourself with key terms like SCADA, ICS, IIoT, and relevant security frameworks such as IEC and NIST CSF.
Tailor Your CV: Customise your CV to highlight your experience with OT security frameworks, incident response, and third-party risk management. Use specific examples from your past roles that demonstrate your technical skills and problem-solving abilities in securing operational technology environments.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security and your understanding of the unique challenges in OT environments. Mention how your skills align with the company's goals and how you can contribute to their operational excellence.
Proofread and Edit: Before submitting your application, carefully proofread your CV and cover letter for any spelling or grammatical errors. Ensure that your documents are clear, concise, and professional, as attention to detail is crucial in the field of information security.
How to prepare for a job interview at William Grant & Sons
✨Understand OT Security Frameworks
Make sure you have a solid grasp of the key OT security frameworks like IEC and NIST CSF. Be prepared to discuss how you've applied these standards in previous roles, as this will demonstrate your technical knowledge and relevance to the position.
✨Showcase Incident Response Experience
Be ready to share specific examples of how you've handled OT security incidents in the past. Highlight your role in containment and recovery efforts, as well as any lessons learned that could apply to the company's operational environment.
✨Communicate Clearly with Stakeholders
Since you'll be working with various teams, practice explaining complex security concepts in simple terms. This will show your ability to bridge the gap between technical and non-technical stakeholders, which is crucial for the role.
✨Prepare for Technical Questions
Expect to face technical questions related to SCADA, ICS, and IIoT systems. Brush up on your knowledge of OT architectures, protocols, and risk vectors, and be ready to discuss how you've identified and mitigated vulnerabilities in these areas.