Head of OT & ICS Security Testing

Nettitude Group

Birmingham

On-site

GBP 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible working

Job summary

LRQA seeks a Head of OT & ICS Security Testing to establish and scale a safety-first testing capability across live operational environments. You will lead OT/ICS assessments, penetration testing, and IEC 62443-aligned reviews while driving growth across industries globally.

The role requires technical leadership, strategic alignment with regulations, and the ability to shape client scopes and bids. Hybrid/remote work with international travel is expected.

Qualifications

  • Substantial hands-on OT and ICS security assessment experience in live operational environments.
  • Strong knowledge of IEC 62443 and industrial protocols.
  • Experience leading technical teams and supporting sales in OT/ICS contexts.

Responsibilities

  • Own the OT and ICS testing proposition, methodology and safety-first testing standards for live plants and control environments.
  • Align service line to IEC 62443, NIS2 and sector regulations; build lab, tooling and reference environments.
  • Act as a technical sales lead: shape scope with clients, support bids, present to technical and executive buyers.
  • Lead pod leads and consultants, set technical direction, and enable cross-selling across cyber services.

Skills

OT/ICS security testing
IEC 62443 familiarity
Technical leadership
Sales support

Job description

Head of OT & IC Security Testing

Location:Birmingham : 1 Trinity Park : Bi
Position Category:Technical
Position Type:Employee Regular

Leads LRQA's operational technology and industrial control systems security testing service line, covering OT and ICS assessments, OT penetration testing, IEC 62443-aligned reviews and supporting advisory across energy, utilities, manufacturing, maritime and process industries.

To establish and scale a safety-first OT and ICS testing capability that allows industrial clients to understand and reduce cyber risk in live operational environments, and to grow it into a differentiated, profitable service line that we cross-sell across LRQA Cyber.

Working conditions:

Hybrid or remote, aligned to an LRQA office or home location within one of the delivery regions (UK&I, Greece, US, Mexico, Kuala Lumpur, APAC). Regular domestic and international travel to client sites, LRQA offices and industry events. Occasional out-of-hours and weekend working to meet client testing windows. This is a billable leadership role: the postholder carries a personal utilisation target alongside leadership accountabilities.

Performance measures:
  • Personal utilisation against the 40% target (approximately 8 days per month).
  • Service line order intake, revenue and margin against plan.
  • Pipeline contribution and win rate on opportunities where the postholder acts as technical sales lead.
  • Delivery quality: client satisfaction, report quality, on-time delivery and no material quality escapes.
  • Accreditation and scheme compliance status for the service line.
  • People: retention, engagement, and completion of the 5x5x5 training model (5 days of allocated training time, £5k of funding and 5 certifications per consultant, per year).
  • Contribution to the pooled operating model: consultant cross-skilling and successful redeployment across service lines.
Reporting structure:

Reports to the Head of Offensive Services. Peer to the Heads of the other four offensive service lines. Leads the team/pod leads and will have consultants reporting to them within the service line and, through them, consultants drawn from a pooled capability of approximately 100 offensive security consultants. Consultants are allocated against demand rather than held permanently within a single service line.

Key Responsibilities:
  • Own the OT and ICS testing proposition, methodology and safety-first testing standards for work in live plant, production and control environments.
  • Align the service line to IEC 62443, NIS2 and sector regulation, and build the lab, tooling and reference environments needed to test safely.
  • Act as a technical sales lead: shape scope with clients, support bids and proposals, and present credibly to both technical and executive buyers.
  • Lead, develop and retain the pod leads and consultants in the service line, setting technical direction, career pathways and certification plans under the 5x5x5 training model.
  • Deliver personally on client engagements to the role's utilisation target, retaining hands-on technical credibility with clients and the team.
  • Drive AI-enabled support: adopt and govern AI tooling that increases coverage, reduces manual effort and improves output quality, without compromising client confidentiality or testing safety.
  • Work with peer Heads to keep consultants fungible across service lines, supporting the pooled resourcing model, cross-skilling and a leveraged delivery mix.
Key health & safety responsibilities:
  • Eliminate or minimise employee exposure to risks by regularly reviewing the health and safety risk register, applying appropriate controls, communicating results of risk assessments, and ensuring health and safety is considered in the planning and execution of all LRQA activities.
  • Manage your own, and your team's, compliance with health and safety rules, instructions, systems and legal requirements to ensure employees are suitably trained and adequate resources are available to work safely.
  • Monitor and review health and safety performance, observe safety behaviours in the workplace, taking appropriate corrective and preventative action as necessary and suggesting and implementing improvement activities.
Number of direct reports:

To be confirmed - pod/team leads within the service line, plus indirect leadership of consultants allocated from the pooled capability of other consultants across Offensive Services.

Geographic area of impact:

Global. Delivery regions currently UK&I, Greece, US, Mexico, Kuala Lumpur and APAC, with clients and engagements worldwide.

Size of budget:

To be confirmed - service line P&L contribution; budget scale to be confirmed with Finance.

Key stakeholders:
  • Head of Offensive Services
  • Heads of the other offensive service lines
  • Cyber sales and bid teams
  • Delivery operations and resourcing
  • Marketing and proposition development
  • HR, Reward and Legal
  • Clients and prospects
  • LRQA industrial and inspection businesses
  • Client engineering, operations and HSE functions
  • Sector regulators and standards bodies
What You'll Bring:

Substantial hands-on OT and ICS security assessment experience in live operational environments, with a demonstrable safety-first approach.

Working knowledge of IEC 62443 and industrial protocols and architectures.

Recognised certification such as GICSP, GRID, IEC 62443 or equivalent.

Experience leading technical teams and supporting sales in OT/ICS environments.

Engineering or process control background.

Experience of OT SOC, detection and monitoring propositions.

Experience building a new service line from early stage and driving a cross sell from other cyber services or assessment style services, such as 27001.

Local/Regional Requirements (in addition to those above):
  • UK & Ireland: eligibility for UK security clearance (SC as a minimum) where the role supports CHECK, government or CNI-facing work. Right to work in the UK.
  • United States and Mexico: eligibility to work in-region and to satisfy client-specific background screening and, where required, US federal or state contractual requirements.
  • Greece, Kuala Lumpur and wider APAC: local employment eligibility; regional language capability desirable; awareness of local data protection and testing authorisation requirements.
  • All regions: satisfactory background screening in line with LRQA policy and applicable scheme requirements, and the ability to travel internationally.
Who are LRQA?

LRQA is a leading global assurance partner, combining deep industry expertise with innovative solutions to help organizations manage risk, improve performance, and drive sustainable growth.

<
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Consultant (Incident Response)
Senior Security Consultant (Incident Response)

LRQA • Birmingham

On-site
GBP 70,000 - 110,000
Global OT & ICS Security Testing Leader
Global OT & ICS Security Testing Leader

Nettitude Group • Birmingham

Hybrid
GBP 110,000 - 150,000
Flexible working
Service Desk Manager
Service Desk Manager

LRQA • Birmingham

On-site
GBP 70,000 - 95,000
Senior Resource Scheduler
Senior Resource Scheduler

Nettitude Group • Birmingham

On-site
GBP 38,000 - 54,000
Senior Developer
Senior Developer

Nettitude Group • Birmingham

Remote
GBP 75,000 - 110,000
Senior OT Security Consultant (SC Clearance)
Senior OT Security Consultant (SC Clearance)

Infosec • North East

Remote
GBP 90,000 - 120,000
Business Development Manager (Cyber)
Business Development Manager (Cyber)

Nettitude Group • Birmingham

On-site
GBP 45,000 - 70,000
Principal Security Consultant - DSS
Principal Security Consultant - DSS

Nettitude Group • Birmingham

On-site
GBP 90,000 - 120,000
Principal Cyber Security Consultant
Principal Cyber Security Consultant

AtkinsRéalis • Birmingham

On-site
GBP 90,000 - 130,000
Flexible working
Hybrid work model
Career development
Senior OT Consultant
Senior OT Consultant

lacuna-talent • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible working arrangements
Pension and life assurance
Maternity & paternity leave
+5