Enable job alerts via email!

Principal Consultant, Industrial OT Cybersecurity

WSP

Toronto

Hybrid

CAD 100,000 - 130,000

Full time

3 days ago
Be an early applicant

Job summary

A leading engineering consulting company is seeking a Principal Consultant in Industrial Cybersecurity to provide technical leadership in major infrastructure projects. This role involves overseeing cybersecurity strategies, managing relationships with clients, and ensuring the resilience of digital infrastructures. Ideal candidates should have 10+ years of experience in digital infrastructure, a background in networking or cybersecurity engineering, and familiarity with various cybersecurity frameworks. This position offers a flexible work environment and opportunities for professional growth.

Benefits

Competitive salary
Flexible work options
Comprehensive benefits including virtual healthcare
Wellness platform

Qualifications

  • 10 years minimum experience in digital infrastructure projects.
  • In-depth experience in Industrial Cyber Security field.
  • Applied knowledge of cybersecurity frameworks such as NIST, ISA/IEC 62443.

Responsibilities

  • Provide cybersecurity expertise for Industrial Control Systems.
  • Lead strategy and planning of cybersecurity activities.
  • Oversee WSP’s cybersecurity project plans and governance.

Skills

Networking
Cybersecurity leadership
Communication skills
Project management

Education

Cybersecurity Engineering degree or equivalent
Relevant Cybersecurity training and certifications

Tools

Microsoft Office
Vulnerability scanning tools

Job description

The Opportunity:

WSPis currently seeking a Principal Consultant, Industrial / OT Cybersecurityto join our Cybersecurity Practice in Canada.

This job function reports into the OT Cybersecurity Practice Director and is a delivery-focused role for WSP major infrastructure projects and professional services mandates.

This role aligns with WSP’s “Future Ready” vision to become the industry leader in digital engineering and advisory services. WSP’s Industrial OT Cybersecurity Practice is formed of Engineers, Specialists, and Consultants who plan, design and implement strategies, frameworks and solutions to ensure the security of (CNI) critical national infrastructures. Our mission is to deliver digital infrastructures that are resilient and can be maintained as such throughout their life cycle. This is an opportunity to work with leading experts within the ICS/OT Cybersecurity Industry, build a cross-functional network of professionals, work in a high-performing, flexible, fun and inclusive environment.

Why choose WSP?

  • We value and are committed to upholding a culture ofinclusionandbelonging
  • OurFlexible Work Policy– we recognize the importance of balance in our lives and encourage you to prioritize the balance in yours. We will support you on and off the job so you can be fully present in both your work and home lives.
  • ACanadiansuccess story - we'reproudto wear the red and white of this beautiful country and show the world what Canada has to offer.
  • Enhancethe world around you - from the environment to the highways, to the buildings and the terrain, WSP is the fabric of Canada.
  • Outstandingcareer opportunities - we're growing and pushing ourselves every day to be greater than yesterday - we're open toyourideas and tryingnewthings.
  • A phenomenalcollaborativeculture and a workforce filled with genuinelygood peoplewho are doing humbly important work. Come find out for yourself what it's like to be a part of our journey.

We offer attractive pay, flexible work options, a great corporate culture, comprehensive and employee-focused benefits including virtual healthcare and a wellness platform as well as great savings programs, and a clear vision for the future.

#WeAreWSP

What you can expect to do here:

  • Provide cybersecurity expertise and technical leadership for Industrial Control Systems (ICS) and Operational Technology (OT) environments.
  • Act as the discipline lead for Industrial Cybersecurity within WSP major infrastructure projects, in complex multi-discipline and stakeholder environments, with a focus on the Rail & Transit domain.
  • Lead the strategy and planning of all cyber security activities and resources needed for major infrastructure projects and / or focused client mandates, spanning the following aspects: early feasibility studies and strategic advisory, requirements management, design, procurement, implementation, testing and commissioning,into operations & maintenance.
  • Define the KPIs by which the project Cybersecurity framework will be measured and continually seek to improve Cybersecurity discipline framework through real-world deployment and application.
  • Oversight and execution of WSP’s Cybersecurity project plans, to ensure the cyber resilience of the digital infrastructure through the following workstreams: governance & planning, tools and technologies, policies and procedures, and people & expertise.
  • Lead on the execution of cyber security threat, vulnerability, and risk assessments by identifying all the critical assets, network connectivity and threat vectors, to define mitigation options and residual risk.
  • Derive, cascade, and clarify cyber security requirements to the suppliers of digital technology and controls systems, and engage in the procurement activities to manage cyber risk in the supply chain.
  • Perform, and lead project teams to perform, the necessary analysis to provide all the required evidence to support the project requirements and verification of security controls through the V-cycle assurance process.
  • Liaise with engineering design, project management and construction teams to ensure the cyber security activities and requirements are being implemented by the project team and by the suppliers.
  • Review cyber security submissions from suppliers, and designers, and provide detailed technical comments.
  • Plan, prepare and implement a cyber security testing strategy to validate the resilience of the digital infrastructure Vs. external and internal threats.
  • Manage client relationships and advise clients on recommended actions relating to active projects – to seize opportunities or mitigate risks.
  • Deliver on critical path project activities and deliverables in allocated timescales to meet overall project deadlines.
  • Identify opportunities for new work, and occasionally contribute to the development of bid materials and proposal exercises to support winning of new work.

What you’ll bring to WSP:

Technical qualifications, experience, and skills:

  • Networking, Telecommunications or Cybersecurity Engineering degree, or equivalent
  • Relevant Cybersecurity training and certifications, for example: GICSP, GIAC, IEC 62443 suite, or a master’s degree in Cybersecurity
  • 10 years minimum experience in the application of one or more of the following areas:
    • Major Infrastructure Projects discipline lead / Project Management – digital infrastructure
    • Telecommunications / Network Technology / Cloud Environment
    • Automation / SCADA / Control Systems
    • Distributed Control Systems / Operational Technology
  • The candidate will possess in-depth experience in the Industrial Cyber Security field with most recent experience having come from any of the following areas:
    • Infrastructure / Engineering Project Program definition and execution – OT Cybersecurity
    • Vulnerability Scanning and Penetration Testing
    • Application security
    • Malware Reverse Engineering
    • Threat Intelligence
    • Security Architecture and Secure-by-Design process
    • Operational Technology/Industrial Control Systems Security
    • Telecommunications and Network Security
    • System or Network administration in a complex multi-national network
  • Experience in the Rail & Transit sector for major multi-discipline (3P) projects and /or operations is required
  • Experience of bridging and managing the technical, schedule and commercial constraints at a project level in relation to OT Cybersecurity.
  • Experience in multiple Industrial Control System fields such as: manufacturing, transportation, energy, utilities, telecommunications and willing to go the “extra mile” to learn more about industrial digital infrastructures and their underlying cybersecurity.
  • Applied knowledge of NIST guidelines, ISA/IEC 62443 standards suite, and ISO 2700x cyber security frameworks
  • Fundamental understanding of IT and OT network communication protocols (e.g. TCP/IP, UDP, DNP3, Modbus, IEC 61850, OPC, OPC UA, PROFINET, etc.)
  • IEC 62443 series, CISSP, CompTIA Security+, or SANS GICSP valid certification is required

Interpersonal and soft skills:

  • Excellent communication skills, both written and verbal.
  • Proficiency in Microsoft Office, including Excel, Word, Visio, Project and Outlook.
  • The ability to work effectively remotely within an extended team.
  • The ability to understand responsibilities and willingness to be accountable of the work delivered.
  • Ability to communicate complex Engineering and Industrial Cybersecurity concepts to non-technical decision makers
  • Ability to work on multiple mandates simultaneously.

What sets you apart:

  • Experience in managing technical teams and overseeing the workstreams of others at a project level.
  • Specific experience pertaining to the Transportation industry sector, e.g. LRT, Heavy Rail, Metro – from an OT Cybersecurity discipline lead perspective – Operations or Projects.
  • Knowledge of the Systems Engineering and Systems Assurance concepts widely used in the Railway domain, e.g. CENELEC EN 50126, 50701
  • International experience, such as European Rail Infrastructure and Projects experience.
  • Professional Engineer (PEng), or European equivalent: CEng (Chartered Engineer) certified and / or working towards these accreditations.
  • Experience working as a Consultant or Advisor to clients, taking into consideration budgetary and inter-disciplinary constraints.
  • Hands-on experience using OT Cybersecurity Asset Discovery & Vulnerability solutions to gain actionable intelligence about clients’ environments
  • Experience in Project or Program Management of Cybersecurity or Networking assignments.
  • Bilingual French / English, an asset
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.