OT Security Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Operational Technology (OT) Security Specialists to assess, implement, manage and continuously improve cybersecurity controls across industrial control systems (ICS), operational technology networks and critical infrastructure environments.
The successful candidates will be responsible for protecting industrial systems, production environments, operational networks and critical infrastructure against cybersecurity threats, vulnerabilities and unauthorised access.
This role requires strong hands‑on expertise in OT cybersecurity, industrial control systems, SCADA environments, industrial network security, vulnerability management and recognised industrial cybersecurity standards.
The ideal candidates will have proven experience securing operational technology environments within industries such as manufacturing, energy, utilities, mining, telecommunications, water treatment or other critical infrastructure sectors.
The position requires an understanding of the unique security, safety, reliability and availability requirements associated with operational technology environments.
Key Responsibilities
OT Security Architecture and Implementation
- Design, implement, configure and maintain cybersecurity controls across operational technology environments.
- Assess industrial control systems and OT infrastructure to identify cybersecurity risks and vulnerabilities.
- Develop and implement OT security architectures aligned with recognised industrial cybersecurity standards.
- Support secure integration between Information Technology (IT) and Operational Technology (OT) environments.
- Implement network segmentation and secure communication controls between IT and OT networks.
- Apply defence‑in‑depth security principles to industrial infrastructure.
- Conduct OT security architecture reviews and recommend appropriate security improvements.
- Support the secure deployment and maintenance of industrial cybersecurity technologies.
- Ensure cybersecurity controls are implemented without compromising operational safety, reliability or availability.
- Collaborate with engineering, operations, infrastructure and cybersecurity teams.
Industrial Control Systems and SCADA Security
- Assess and secure Supervisory Control and Data Acquisition (SCADA) systems.
- Support cybersecurity controls for Distributed Control Systems (DCS), Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs).
- Identify security weaknesses within industrial control networks and automation systems.
- Review security configurations across industrial controllers, engineering workstations and operational servers.
- Implement secure access controls for industrial control systems.
- Support secure remote access to OT infrastructure and industrial equipment.
- Assess cybersecurity risks associated with industrial communication protocols.
- Assist with security hardening of supported OT systems and industrial workstations.
- Coordinate security improvements with operational engineering and automation teams.
OT Network Security and Segmentation
- Implement and maintain industrial network security controls.
- Configure and support firewalls, network segmentation and secure remote access solutions.
- Support the design and implementation of industrial demilitarised zones (DMZs).
- Monitor communications between enterprise IT networks and industrial OT environments.
- Identify unauthorised network connections, insecure protocols and potential attack paths.
- Support industrial network asset discovery and security monitoring.
- Assess industrial network architecture and recommend risk mitigation measures.
- Implement secure connectivity controls for third‑party vendors and maintenance providers.
- Support network access restrictions and least‑privilege security principles.
OT Threat Detection and Vulnerability Management
- Conduct cybersecurity risk assessments across industrial control systems and operational networks.
- Identify, analyse and prioritise OT vulnerabilities based on exploitability, operational impact and safety considerations.
- Implement and support OT security monitoring and threat detection technologies.
- Analyse industrial network traffic and investigate suspicious activity.
- Monitor emerging OT cybersecurity threats, vulnerabilities and industrial security advisories.
- Coordinate vulnerability remediation with engineering and operational teams.
- Support risk‑based patch management and compensating security controls.
- Conduct security assessments using methods appropriate for sensitive industrial environments.
- Avoid disruptive scanning or testing on production OT systems without appropriate authorisation and operational safeguards.
- Maintain OT vulnerability registers, risk assessments and remediation records.
OT Security Incident Response
- Support cybersecurity incident detection, investigation and response within operational technology environments.
- Assist with the development and maintenance of OT‑specific incident response procedures.
- Investigate suspicious activities affecting industrial control systems and OT networks.
- Coordinate incident response activities with cybersecurity, engineering and operations teams.
- Support containment and recovery activities while prioritising operational safety and system availability.
- Participate in OT cybersecurity incident simulations and tabletop exercises.
- Maintain incident investigation records and technical reports.
- Recommend security improvements based on incident findings and emerging threats.
OT Security Governance and Compliance
- Implement OT cybersecurity controls aligned with recognised industrial security frameworks.
- Support compliance with IEC 62443, NIST SP 800-82 and applicable industry security requirements.
- Conduct OT security gap assessments and maturity reviews.
- Develop and maintain OT security policies, procedures and technical standards.
- Support internal and external cybersecurity audits involving industrial systems.
- Maintain OT asset inventories, security documentation and network architecture diagrams.
- Assist with third‑party and industrial vendor cybersecurity assessments.
- Support cybersecurity awareness initiatives for engineering and operational personnel
- Recommend continuous improvements to OT security governance and operational resilience.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Cybersecurity, Computer Science, Electrical Engineering, Electronic Engineering, Industrial Automation, Control Systems Engineering or a related discipline.
- Typically 3–5 years of relevant experience in OT cybersecurity, industrial control systems security, industrial network security or a closely related technical specialisation.
- Proven hands‑on experience securing or assessing operational technology or industrial control system environments.
- Strong understanding of OT infrastructure, industrial automation systems and critical infrastructure security.
- Practical knowledge of SCADA, PLC, DCS and HMI technologies.
- Experience with industrial networking and IT/OT network segmentation.
- Understanding of industrial communication protocols such as Modbus, DNP3, OPC UA or EtherNet/IP.
- Experience conducting OT cybersecurity risk assessments and vulnerability reviews.
- Knowledge of industrial firewalls, secure remote access and network monitoring technologies.
- Understanding of OT‑specific cybersecurity threats and attack techniques.
- Familiarity with IEC 62443 and NIST SP 800-82.
- Knowledge of industrial asset management, security monitoring and incident response.
- Understanding of operational safety, system availability and change management requirements.
- Strong technical troubleshooting, analytical and documentation skills.
Technical Skills and Competencies
Operational Technology and Industrial Systems
- Operational Technology (OT)
- Industrial Control Systems (ICS)
- Supervisory Control and Data Acquisition (SCADA)
- Distributed Control Systems (DCS)
- Programmable Logic Controllers (PLCs)
- Human-Machine Interfaces (HMIs)
- Industrial automation networks
- Engineering workstations
- Industrial historians
- Critical infrastructure systems
Industrial Communication Protocols
Understanding of relevant protocols, including:
- Modbus TCP/RTU
- DNP3
- OPC UA
- EtherNet/IP
- PROFINET
- Siemens S7 communications
- IEC 60870-5-104
- IEC 61850
- Industrial Ethernet
- TCP/IP networking
OT Network Security
- Industrial firewalls
- IT/OT network segmentation
- Industrial DMZ architecture
- Purdue Enterprise Reference Architecture
- Secure remote access
- Network access control
- Industrial network monitoring
- Firewall rule management
- Network traffic analysis
- Zero Trust principles adapted for OT environments
OT Cybersecurity Platforms
Experience with one or more of the following would be advantageous:
- Claroty
- Nozomi Networks
- Dragos
- Microsoft Defender for IoT
- Tenable OT Security
- Forescout
- Fortinet OT Security solutions
- Palo Alto Networks industrial security solutions
- Other industrial cybersecurity monitoring and protection platforms
OT Threat Detection and Vulnerability Management
- OT asset discovery and inventory management
- Passive industrial network monitoring
- Industrial vulnerability assessments
- OT threat intelligence
- Risk-based vulnerability prioritisation
- Industrial intrusion detection
- Security incident investigation
- OT‑specific threat modelling
- MITRE ATT&CK for ICS
- Industrial security event analysis
Industrial Infrastructure and Automation
Familiarity with industrial platforms such as:
- Siemens SIMATIC
- Schneider Electric Modicon
- Rockwell Automation / Allen‑Bradley
- ABB industrial automation systems
- Honeywell industrial control systems
- Emerson automation platforms
- Industrial Windows and Linux systems
- Industrial network switches and communication gateways
Security Frameworks and Standards
- IEC 62443 series
- NIST SP 800-82 – Guide to Operational Technology Security
- NIST Cybersecurity Framework
- ISO/IEC 27001
- MITRE ATT&CK for ICS
- CIS Critical Security Controls, where applicable
- Industrial cybersecurity risk management
- Critical infrastructure protection principles
OT Security Incident Response and Resilience
- OT incident response planning
- Industrial cybersecurity incident investigation
- Operational risk assessment
- Secure system recovery
- OT backup and restoration principles
- Business continuity and disaster recovery
- Industrial system availability and reliability
- Safety‑aware cybersecurity response procedures
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- GIAC Global Industrial Cyber Security Professional (GICSP)
- GIAC Response and Industrial Defense (GRID)
- GIAC Critical Infrastructure Protection (GCIP)
- ISA/IEC 62443 Cybersecurity Certificate Programme credentials
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Certified SCADA Security Architect (CSSA)
- Relevant industrial networking or automation certifications
- Relevant Claroty, Nozomi Networks, Dragos or industrial cybersecurity platform training
- Relevant OT security, industrial automation or critical infrastructure certifications
Key Personal Attributes
- Strong analytical and technical problem‑solving abilities.
- Excellent understanding of industrial cybersecurity risks.
- High attention to detail and operational safety.
- Ability to assess security risks without compromising production environments.
- Strong troubleshooting and investigative skills.
- Excellent communication and stakeholder engagement abilities.
- Ability to collaborate effectively with engineering, operations, infrastructure and cybersecurity teams.
- Proactive approach to identifying industrial cybersecurity threats.
- Strong organisational and technical documentation skills.
- Ability to work within complex and operationally sensitive environments.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical OT cybersecurity, industrial control systems security and industrial network protection experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Industrial sectors and operational technology environments they have supported.
- Experience securing SCADA, PLC, DCS, HMI and industrial automation systems.
- Practical experience implementing IT/OT network segmentation and industrial firewalls.
- Industrial communication protocols and automation technologies they have worked with.
- OT cybersecurity risk assessments, vulnerability management and remediation projects.
- Experience with Claroty, Nozomi Networks, Dragos, Microsoft Defender for IoT or equivalent platforms.
- Familiarity with IEC 62443, NIST SP 800-82 and industrial cybersecurity standards.
- OT security monitoring, threat detection and incident response experience.
- Industrial cybersecurity implementations, infrastructure upgrades or security improvement projects.
- The size and complexity of OT environments they have secured or supported.
- Relevant OT cybersecurity, industrial automation and professional security certifications.
Important: This is a specialist Operational Technology Security opportunity requiring demonstrable practical experience with industrial control systems, OT networks or industrial cybersecurity. General IT security, network administration or cybersecurity experience without substantial OT exposure will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.