Title: Technical Specialist-Cybersecurity
Area(s) of responsibility
We are seeking an experienced OT Cybersecurity & Risk Assessment Engineer with 6+ years of expertise in operational technology (OT) security, vulnerability management, and risk assessment. The role involves leveraging leading platforms for product cybersecurity, process hazard analysis, and enterprise risk management, while overseeing software licensing, patch management, and network security for critical industrial environments.
Key Responsibilities
- Conduct OT product cybersecurity risk assessments using the C2A EVSEC Platform, ensuring compliance with industry standards and regulatory requirements.
- Perform process hazard analyses with Kenexis Open-PHA to identify, evaluate, and mitigate operational risks.
- Utilize Sphera for enterprise risk and compliance tracking, integrating findings into organizational safety and security frameworks.
- Manage software licensing for engineering and test teams, including procurement, allocation, upgrades, and compliance audits.
- Operate and maintain vulnerability scanning tools, ensuring timely identification, prioritization, and remediation of security gaps.
- Oversee the vulnerability management lifecycle, from detection through patch deployment and verification.
- Collaborate with IT/OT teams to implement network security controls and ensure secure integration of systems.
- Maintain documentation, audit trails, and reporting for all security and risk management activities.
Required Skills & Experience
- 6+ years in OT cybersecurity, risk assessment, or related industrial security roles.
- Proficiency with C2A EVSEC Platform, Kenexis Open-PHA, Sphera, and vulnerability scanning tools.
- Strong knowledge of risk assessment methodologies, vulnerability management lifecycle, patch management, network security, and OT security best practices.
- Experience managing software licenses and ensuring compliance in regulated environments.
- Ability to work cross-functionally with engineering, IT, and compliance teams.
Preferred Skills
- Familiarity with IEC 62443, NIST CSF, or similar OT cybersecurity frameworks.
- Experience integrating risk assessment outputs into enterprise governance systems.
- Knowledge of industrial control systems (ICS) and process safety standards.