About The Role
The OT Security Officer will play a pivotal role in safeguarding OPEA and Offshore’s operational technology (OT) environment across renewable energy assets (onshore/offshore wind and photovoltaic sites). This role combines strong governance responsibilities with hands-on security activities to ensure that OT Security controls are effectively implemented and enforced at operational sites in a pragmatic manner. The Officer will serve as the NIS Responsible Officer contact for the regulatory authorities regarding compliance with the NIS Regulations and will oversee alignment with ISO/IEC 27001, IEC 62443, NIST, and the company’s OT Information Security Management System (ISMS). The position requires strong communication and influencing skills to drive compliance and awareness across technical, operational, and business stakeholders across the value chain of Development, Construction & Operations. The role is intended to be Netherlands centric; however you would be expected to lead/support also in other countries as part of a wider Governance, Risk and Compliance team. The role is subjected to either you holding relevant National Security Clearance or be eligible and willing to go through Security Clearance.
Job Requirements & Experience
Governance & Compliance
- Ensure implementation and enforcement of OT security policies, standards, and controls in all development and construction projects and operational assets. Manage and monitor compliance with ISO 27001, IEC 62443, and NIS Regulations across OT environments.
- Conduct and document periodic compliance reviews, audits, and risk assessments of OT systems.
- Act as the primary liaison with Agentschap Telecom (RDI) for all OT security-related compliance and reporting.
- Represent the company at Industry Meetings and working groups as well as staying ahead of the latest developments and innovation in the field.
Risk & Assurance
- Identify, assess, and manage OT security risks, escalating appropriately to management and risk committees.
- Provide assurance to senior stakeholders on OT security posture and regulatory compliance.
- Develop and track OT security KPIs, metrics, and reports for local entity board members and group leadership.
Operational & Technical Activities
- Support deployment and verification of OT security controls across wind and solar sites (e.g., access controls, network segmentation, monitoring, patch management).
- Conduct technical compliance checks, coordinate penetration testing with Operational sites, and perform vulnerability assessments within OT environments. Provide guidance and oversight on incident response, disaster recovery, and business continuity plans for OT.
- Collaborate with IT/OT engineering and operations teams to ensure security by design in new projects and upgrades.
Stakeholder Engagement
- Act as a trusted advisor and single point of contact for OT security within the designated region of responsibility.
- Communicate OT security risks, compliance status, and incident findings clearly to both technical and non-technical stakeholders, including local board members.
- Influence and guide site personnel, engineers, and management to implement required controls.
- Promote a culture of security awareness and accountability across operational sites.
- The role will require travel and close collaboration with operational and engineering stakeholders across the European onshore and offshore fleet. This may require holding or undergoing specific GWO Offshore certifications.
Your Profile
- 5 years’ experience in cybersecurity, with at least 3–5 years in OT/ICS security within critical infrastructure, energy, utilities, or industrial environments
- A successfully completed degree in computer science/business/ business informatics
- A strong understanding and experience in working with NIS, NIS2 and CER Directive (2022/2557)
- A significant amount of knowledge in IT & Operational Technologies (OT), including industry standards IEC62443, NIST SP 800-82
- Strong analytical thinking skills paired with a high focus on results and services
- You have at least 3 years experience in Business Continuity Management.
- You have excellent skills in reporting and engaging with top management, influencing and engaging stakeholders at all levels.
- You are certified ISO27001 Implementer and Auditor
- You are certified in CISSP and/or GICSSP
- ITIL or COBIT exposure is advantageous
- ICS/OT engineering experience is essential i.e. a deep understanding and hands on experience with SCADA, PLC’s and how plant control environments are designed and operated.
- An excellent understanding and experience of priorities between OT and IT
Your Benefits
- Flexible and hybrid working, enabling a balance between remote work and in-office collaboration
- Company pension scheme to help secure your future
- Employee stock programme giving you a stake in our success
- Training and development opportunities to support your professional growth
Note: This version excludes application-process prompts and broader corporate marketing content while preserving core job responsibilities, qualifications, and benefits.