We are seeking an experienced OT Cyber Security Engineer to support a programme to strengthen the security and resilience of Operational Technology environments in line with NIS2 requirements.
The successful consultant will design and implement secure OT architectures across multiple platforms. The environment includes instrumentation and control systems, safety systems, Fire and Gas (F&G) systems, telecommunications, subsea control systems and metering systems.
Key Responsibilities
- Consolidate and standardise OT networks across individual platforms.
- Assess existing OT environments and design secure, resilient OT network architectures.
- Ensure OT systems and controls comply with NIS2 requirements and applicable industry security standards.
- Produce User Requirement Specifications for OT cyber security solutions.
- Implement an OT intrusion detection system such as Nozomi Networks.
- Establish centralised collection and monitoring of OT security logs across platforms.
- Implement application whitelisting solutions within OT environments.
- Implement and securely configure Domain Controllers supporting OT systems.
- Identify security risks and recommend appropriate technical controls and remediation measures.
- Work with engineering, IT, cyber security and operational stakeholders to ensure solutions are practical and suitable for critical environments.
- Produce technical designs, security documentation and implementation guidance.
Required Experience
- Strong experience delivering cyber security solutions within Operational Technology or Industrial Control System environments.
- Good understanding of NIS2 and its application to critical infrastructure or industrial environments.
- Experience designing secure OT network architectures, including network segmentation and consolidation.
- Hands‑on experience implementing OT security monitoring or intrusion detection solutions, ideally Nozomi Networks.
- Experience collecting and centralising security logs from OT platforms.
- Knowledge of application whitelisting technologies and their implementation in operational environments.
- Experience implementing or securing Microsoft Active Directory and Domain Controllers within OT environments.
- Ability to create clear User Requirement Specifications and technical design documentation.
- Strong understanding of the security challenges associated with legacy, safety-critical and high-availability systems.
- Confident working with technical and non-technical stakeholders across cyber security, engineering and operations.
- Experience securing instrumentation, control and safety systems.
- Knowledge of Fire and Gas, telecommunications, subsea control or metering systems.
- Familiarity with relevant OT security standards and frameworks, such as IEC 62443, ISO 27001 and the NIST Cybersecurity Framework.
- Experience working within energy, utilities, offshore, oil and gas, manufacturing or another critical‑infrastructure environment.
- Relevant cyber security, networking or OT security certifications.