An application made for this job — a tailored resume and cover letter that speak straight to the posting.
SHEIN in Warsaw seeks a locally based OT Security Engineer to support day-to-day cyber security operations of our automated warehouse. You will monitor OT networks, analyze logs, respond to incidents, and coordinate with global security teams.
Required: 3–5 years in cyber security, knowledge of OT networks (TCP/IP, Siemens S7, OPC), and fluent English; CISSP or similar certifications are preferred.
We are looking for a locally based OT Security Engineer in Poland to support the day-to-day cyber security operations of our automated warehousing environment. This role will work closely with local business and operations teams, as well as global security functions, to identify and mitigate OT security risks, respond to security incidents, and strengthen the overall security and resilience of warehouse operations.
1. Routine Warehouse Security Monitoring and Inspections
Conduct routine security monitoring and inspections across warehouse environments.
Identify security gaps and anomalies related to network boundaries, network segmentation, security policies and controls, and device status.
Track identified issues and work with the relevant teams to ensure timely remediation.
2. Security Log and Network Traffic Analysis
Following headquarters-defined SOPs, coordinate with relevant on-site teams to onboard security logs from network security devices, OT servers, and business systems into the centralized security monitoring and alerting platform.
Use the platform to identify and monitor risks such as unusual login activity, anomalous network traffic, unauthorized device connections, and suspicious port communications.
Coordinate the investigation and remediation of identified risks and ensure each case is tracked through to closure.
3. Security Incident Response and Remediation
Assess, investigate, and respond to security incidents, including unusual login activity, malicious access attempts, malware infections, unauthorized connections, and security policy violations.
Coordinate relevant stakeholders during incident response and drive incidents through to resolution.
Maintain incident registers, response records, and lessons learned to continuously improve security operations.
4. Account, Privilege, and Access Control Management
Conduct periodic reviews of third-party endpoint security, remote access, maintenance accounts, and temporary access permissions at warehouse sites.
Identify and address risks associated with shared accounts, default accounts, inactive or obsolete accounts, and accounts that have not been removed in a timely manner.
Reduce the access risks and security blind spots associated with external vendors and third-party maintenance activities.
5. Emergency Response and Business Continuity Support
Participate in emergency response activities involving business disruptions, system failures, malware outbreaks, and loss of connectivity to critical devices.
Support the development and continuous improvement of security incident response plans and cross-functional coordination mechanisms for automated warehouse operations.
Assist the business with emergency response exercises, recovery validation, post-incident reviews, and improvement actions.
6. Compliance Reviews and Security Reporting
Support security compliance activities, including internal and external audits.
Prepare security reports covering the current risk landscape, security incidents, and remediation progress.
Work with the local HR team to deliver security awareness training to warehouse employees, promote secure operating practices, and reduce human-related security risks.