OT Security Specialist

Sasso Consulting (Pty) Ltd

Johannesburg

On-site

ZAR 850,000 - 1,200,000

Full time

48 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sasso Consulting (Pty) Ltd is seeking an OT Security Specialist to assess, implement and improve cybersecurity across industrial control systems and OT networks. The role focuses on protecting critical infrastructure environments from threats and ensuring safety, reliability and availability of operations.

The successful candidate will bring hands-on OT cybersecurity experience, a strong understanding of SCADA/DCS/HMI security, and familiarity with industry standards.

Qualifications

  • Relevant OT cybersecurity experience
  • Proven security of OT/ICS environments
  • Understanding of SCADA/DCS/HMI security
  • Knowledge of IEC 62443 and NIST SP 800-82

Responsibilities

  • Design, implement, and maintain OT cybersecurity controls across OT environments.
  • Assess ICS/SCADA to identify risks and vulnerabilities.
  • Support secure IT/OT integration and network segmentation.
  • Coordinate security improvements with engineering and operations teams.

Skills

OT security
SCADA security
Industrial IT/OT
Vulnerability management
Incident response

Education

Relevant diploma or degree in IT / Cybersecurity / CS / Electrical/ Electronic/ Industrial Automation or related discipline

Tools

Claroty
Nozomi Networks
Dragos

Job description

OT Security Specialist

Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed

Job Overview

We are seeking experienced and technically proficient Operational Technology (OT) Security Specialists to assess, implement, manage and continuously improve cybersecurity controls across industrial control systems (ICS), operational technology networks and critical infrastructure environments.

The successful candidates will be responsible for protecting industrial systems, production environments, operational networks and critical infrastructure against cybersecurity threats, vulnerabilities and unauthorised access.

This role requires strong hands‑on expertise in OT cybersecurity, industrial control systems, SCADA environments, industrial network security, vulnerability management and recognised industrial cybersecurity standards.

The ideal candidates will have proven experience securing operational technology environments within industries such as manufacturing, energy, utilities, mining, telecommunications, water treatment or other critical infrastructure sectors.

The position requires an understanding of the unique security, safety, reliability and availability requirements associated with operational technology environments.

Key Responsibilities

OT Security Architecture and Implementation

  • Design, implement, configure and maintain cybersecurity controls across operational technology environments.
  • Assess industrial control systems and OT infrastructure to identify cybersecurity risks and vulnerabilities.
  • Develop and implement OT security architectures aligned with recognised industrial cybersecurity standards.
  • Support secure integration between Information Technology (IT) and Operational Technology (OT) environments.
  • Implement network segmentation and secure communication controls between IT and OT networks.
  • Apply defence‑in‑depth security principles to industrial infrastructure.
  • Conduct OT security architecture reviews and recommend appropriate security improvements.
  • Support the secure deployment and maintenance of industrial cybersecurity technologies.
  • Ensure cybersecurity controls are implemented without compromising operational safety, reliability or availability.
  • Collaborate with engineering, operations, infrastructure and cybersecurity teams.

Industrial Control Systems and SCADA Security

  • Assess and secure Supervisory Control and Data Acquisition (SCADA) systems.
  • Support cybersecurity controls for Distributed Control Systems (DCS), Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs).
  • Identify security weaknesses within industrial control networks and automation systems.
  • Review security configurations across industrial controllers, engineering workstations and operational servers.
  • Implement secure access controls for industrial control systems.
  • Support secure remote access to OT infrastructure and industrial equipment.
  • Assess cybersecurity risks associated with industrial communication protocols.
  • Assist with security hardening of supported OT systems and industrial workstations.
  • Coordinate security improvements with operational engineering and automation teams.

OT Network Security and Segmentation

  • Implement and maintain industrial network security controls.
  • Configure and support firewalls, network segmentation and secure remote access solutions.
  • Support the design and implementation of industrial demilitarised zones (DMZs).
  • Monitor communications between enterprise IT networks and industrial OT environments.
  • Identify unauthorised network connections, insecure protocols and potential attack paths.
  • Support industrial network asset discovery and security monitoring.
  • Assess industrial network architecture and recommend risk mitigation measures.
  • Implement secure connectivity controls for third‑party vendors and maintenance providers.
  • Support network access restrictions and least‑privilege security principles.

OT Threat Detection and Vulnerability Management

  • Conduct cybersecurity risk assessments across industrial control systems and operational networks.
  • Identify, analyse and prioritise OT vulnerabilities based on exploitability, operational impact and safety considerations.
  • Implement and support OT security monitoring and threat detection technologies.
  • Analyse industrial network traffic and investigate suspicious activity.
  • Monitor emerging OT cybersecurity threats, vulnerabilities and industrial security advisories.
  • Coordinate vulnerability remediation with engineering and operational teams.
  • Support risk‑based patch management and compensating security controls.
  • Conduct security assessments using methods appropriate for sensitive industrial environments.
  • Avoid disruptive scanning or testing on production OT systems without appropriate authorisation and operational safeguards.
  • Maintain OT vulnerability registers, risk assessments and remediation records.

OT Security Incident Response

  • Support cybersecurity incident detection, investigation and response within operational technology environments.
  • Assist with the development and maintenance of OT‑specific incident response procedures.
  • Investigate suspicious activities affecting industrial control systems and OT networks.
  • Coordinate incident response activities with cybersecurity, engineering and operations teams.
  • Support containment and recovery activities while prioritising operational safety and system availability.
  • Participate in OT cybersecurity incident simulations and tabletop exercises.
  • Maintain incident investigation records and technical reports.
  • Recommend security improvements based on incident findings and emerging threats.

OT Security Governance and Compliance

  • Implement OT cybersecurity controls aligned with recognised industrial security frameworks.
  • Support compliance with IEC 62443, NIST SP 800-82 and applicable industry security requirements.
  • Conduct OT security gap assessments and maturity reviews.
  • Develop and maintain OT security policies, procedures and technical standards.
  • Support internal and external cybersecurity audits involving industrial systems.
  • Maintain OT asset inventories, security documentation and network architecture diagrams.
  • Assist with third‑party and industrial vendor cybersecurity assessments.
  • Support cybersecurity awareness initiatives for engineering and operational personnel
  • Recommend continuous improvements to OT security governance and operational resilience.
Minimum Requirements
  • Relevant diploma or degree in Information Technology, Cybersecurity, Computer Science, Electrical Engineering, Electronic Engineering, Industrial Automation, Control Systems Engineering or a related discipline.
  • Typically 3–5 years of relevant experience in OT cybersecurity, industrial control systems security, industrial network security or a closely related technical specialisation.
  • Proven hands‑on experience securing or assessing operational technology or industrial control system environments.
  • Strong understanding of OT infrastructure, industrial automation systems and critical infrastructure security.
  • Practical knowledge of SCADA, PLC, DCS and HMI technologies.
  • Experience with industrial networking and IT/OT network segmentation.
  • Understanding of industrial communication protocols such as Modbus, DNP3, OPC UA or EtherNet/IP.
  • Experience conducting OT cybersecurity risk assessments and vulnerability reviews.
  • Knowledge of industrial firewalls, secure remote access and network monitoring technologies.
  • Understanding of OT‑specific cybersecurity threats and attack techniques.
  • Familiarity with IEC 62443 and NIST SP 800-82.
  • Knowledge of industrial asset management, security monitoring and incident response.
  • Understanding of operational safety, system availability and change management requirements.
  • Strong technical troubleshooting, analytical and documentation skills.
Technical Skills and Competencies

Operational Technology and Industrial Systems

  • Operational Technology (OT)
  • Industrial Control Systems (ICS)
  • Supervisory Control and Data Acquisition (SCADA)
  • Distributed Control Systems (DCS)
  • Programmable Logic Controllers (PLCs)
  • Human-Machine Interfaces (HMIs)
  • Industrial automation networks
  • Engineering workstations
  • Industrial historians
  • Critical infrastructure systems

Industrial Communication Protocols

Understanding of relevant protocols, including:

  • Modbus TCP/RTU
  • DNP3
  • OPC UA
  • EtherNet/IP
  • PROFINET
  • Siemens S7 communications
  • IEC 60870-5-104
  • IEC 61850
  • Industrial Ethernet
  • TCP/IP networking

OT Network Security

  • Industrial firewalls
  • IT/OT network segmentation
  • Industrial DMZ architecture
  • Purdue Enterprise Reference Architecture
  • Secure remote access
  • Network access control
  • Industrial network monitoring
  • Firewall rule management
  • Network traffic analysis
  • Zero Trust principles adapted for OT environments

OT Cybersecurity Platforms

Experience with one or more of the following would be advantageous:

  • Claroty
  • Nozomi Networks
  • Dragos
  • Microsoft Defender for IoT
  • Tenable OT Security
  • Forescout
  • Fortinet OT Security solutions
  • Palo Alto Networks industrial security solutions
  • Other industrial cybersecurity monitoring and protection platforms

OT Threat Detection and Vulnerability Management

  • OT asset discovery and inventory management
  • Passive industrial network monitoring
  • Industrial vulnerability assessments
  • OT threat intelligence
  • Risk-based vulnerability prioritisation
  • Industrial intrusion detection
  • Security incident investigation
  • OT‑specific threat modelling
  • MITRE ATT&CK for ICS
  • Industrial security event analysis

Industrial Infrastructure and Automation

Familiarity with industrial platforms such as:

  • Siemens SIMATIC
  • Schneider Electric Modicon
  • Rockwell Automation / Allen‑Bradley
  • ABB industrial automation systems
  • Honeywell industrial control systems
  • Emerson automation platforms
  • Industrial Windows and Linux systems
  • Industrial network switches and communication gateways

Security Frameworks and Standards

  • IEC 62443 series
  • NIST SP 800-82 – Guide to Operational Technology Security
  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • MITRE ATT&CK for ICS
  • CIS Critical Security Controls, where applicable
  • Industrial cybersecurity risk management
  • Critical infrastructure protection principles

OT Security Incident Response and Resilience

  • OT incident response planning
  • Industrial cybersecurity incident investigation
  • Operational risk assessment
  • Secure system recovery
  • OT backup and restoration principles
  • Business continuity and disaster recovery
  • Industrial system availability and reliability
  • Safety‑aware cybersecurity response procedures
Relevant Certifications (Advantageous)

One or more of the following certifications would be beneficial:

  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • GIAC Response and Industrial Defense (GRID)
  • GIAC Critical Infrastructure Protection (GCIP)
  • ISA/IEC 62443 Cybersecurity Certificate Programme credentials
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • CompTIA Security+
  • Certified SCADA Security Architect (CSSA)
  • Relevant industrial networking or automation certifications
  • Relevant Claroty, Nozomi Networks, Dragos or industrial cybersecurity platform training
  • Relevant OT security, industrial automation or critical infrastructure certifications
Key Personal Attributes
  • Strong analytical and technical problem‑solving abilities.
  • Excellent understanding of industrial cybersecurity risks.
  • High attention to detail and operational safety.
  • Ability to assess security risks without compromising production environments.
  • Strong troubleshooting and investigative skills.
  • Excellent communication and stakeholder engagement abilities.
  • Ability to collaborate effectively with engineering, operations, infrastructure and cybersecurity teams.
  • Proactive approach to identifying industrial cybersecurity threats.
  • Strong organisational and technical documentation skills.
  • Ability to work within complex and operationally sensitive environments.
  • High levels of confidentiality, accountability and professional integrity.
Application Requirements

Interested candidates should submit an updated CV clearly detailing their practical OT cybersecurity, industrial control systems security and industrial network protection experience, together with copies of relevant academic qualifications and professional certifications.

Candidates should specifically highlight:

  • Industrial sectors and operational technology environments they have supported.
  • Experience securing SCADA, PLC, DCS, HMI and industrial automation systems.
  • Practical experience implementing IT/OT network segmentation and industrial firewalls.
  • Industrial communication protocols and automation technologies they have worked with.
  • OT cybersecurity risk assessments, vulnerability management and remediation projects.
  • Experience with Claroty, Nozomi Networks, Dragos, Microsoft Defender for IoT or equivalent platforms.
  • Familiarity with IEC 62443, NIST SP 800-82 and industrial cybersecurity standards.
  • OT security monitoring, threat detection and incident response experience.
  • Industrial cybersecurity implementations, infrastructure upgrades or security improvement projects.
  • The size and complexity of OT environments they have secured or supported.
  • Relevant OT cybersecurity, industrial automation and professional security certifications.

Important: This is a specialist Operational Technology Security opportunity requiring demonstrable practical experience with industrial control systems, OT networks or industrial cybersecurity. General IT security, network administration or cybersecurity experience without substantial OT exposure will not be sufficient.

Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ICS Security Engineer
ICS Security Engineer

Part of nGAGE Talent Limited • Gqeberha

On-site
ZAR 550,000 - 750,000
Cyber Security SOC Analyst
Cyber Security SOC Analyst

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 420,000 - 660,000
OT Security Architect | ICS/SCADA Expert
OT Security Architect | ICS/SCADA Expert

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 850,000 - 1,200,000
IT Security Specialist Talent Pool
IT Security Specialist Talent Pool

Mr Price Group • Durban

On-site
ZAR 600,000 - 800,000
Cyber Security SOC Analyst
Cyber Security SOC Analyst

Sasso Consulting • Centurion

On-site
ZAR 420,000 - 660,000
Principal Technical Consultant
Principal Technical Consultant

CSI3 • Midrand

On-site
ZAR 1,200,000 - 1,800,000
Industrial Automation/OT Consultant
Industrial Automation/OT Consultant

Accenture PLC • Midrand

On-site
ZAR 700,000 - 900,000
Cyber Security Incident Responder
Cyber Security Incident Responder

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 650,000 - 950,000
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Threat and Vulnerability Management Specialist
Threat and Vulnerability Management Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 700,000 - 1,000,000