Job Description
OT / ICS Operations & Security Management
- Support the company's ICS/OT operations, including networks, systems, endpoints, and cybersecurity tools.
- Maintain OT system and network monitoring to ensure availability and reliability.
- Configure, troubleshoot, and provide day-to-day operational support for cybersecurity solutions within the ICS environment.
- Support day-to-day control system operations and troubleshoot issues to ensure reliable plant performance.
- Monitor systems for unusual or suspicious activities and respond to cybersecurity incidents, alerts, and threats.
- Maintain and enhance security controls for critical systems to meet operational and cybersecurity requirements.
- Manage CII system and network backup processes to ensure business continuity and recovery readiness.
Information Security Governance & Compliance
- Manage and maintain the organization's Information Security Management System (ISMS).
- Conduct annual reviews and updates of ISMS policies, procedures, and supporting documentation.
- Implement and maintain cybersecurity requirements in compliance with CSA, PSO, EMA, CCOP, ISO 27001:2022, and other applicable standards and regulations.
- Take ownership of ISMS-related activities and continuous improvement initiatives.
- Serve as the key liaison between the organization, customers, auditors, service providers, and internal information security stakeholders.
Risk, Vulnerability & Security Assessment
- Conduct annual cybersecurity risk assessments for Critical Information Infrastructure (CII) systems.
- Identify, assess, and mitigate cybersecurity risks to ensure critical systems remain secure and resilient.
- Perform vulnerability management and patch management activities for OT/ICS environments.
- Plan and execute cybersecurity activities including:
- Vulnerability Assessments (VA)
- Penetration Testing (VAPT)
- Threat Hunting
- Purple Team Exercises
- Tabletop Exercises
- Security Reviews and Assessments
- Review cybersecurity advisories and implement mitigation measures where necessary.
Audit & Regulatory Management
- Support and coordinate internal and external cybersecurity audits.
- Plan and execute annual cybersecurity audit programs.
- Coordinate CSA audits, vulnerability assessments, compliance reviews, and mandated regulatory audits.
- Ensure audit findings are tracked, remediated, and closed within agreed timelines.
- Support information security requirements during both internal and external audits.
Security Projects & Technology Improvement
- Review existing technology architecture and identify vulnerabilities, weaknesses, and improvement opportunities.
- Plan, implement, and oversee cybersecurity technology upgrades, enhancements, and major system changes.
- Develop technical solutions, cost estimations, budgets, and proposals to meet cybersecurity requirements for internal and external projects.
- Support the delivery, commissioning, and cybersecurity assurance of new projects and plant systems.
- Ensure all new systems meet operational, cybersecurity, and regulatory requirements before deployment.
Vendor & Stakeholder Management
- Work closely with business units, service providers, and external stakeholders to ensure OT cybersecurity requirements are met.
- Collaborate with internal IT security personnel and Site Information Security Officers (SITSO) on cybersecurity initiatives.
- Evaluate and monitor cybersecurity service performance and Key Performance Indicators (KPIs) of third-party vendors and contractors.
- Coordinate cybersecurity activities with the EC&I Department and support departmental objectives.
Training & Awareness
- Develop and deliver cybersecurity awareness programs and training sessions for employees.
- Promote cybersecurity best practices across the organization.
- Provide guidance and support to users oncybersecurity policies, procedures, and compliance requirements.
Job Requirements
Degree or Diploma in Cybersecurity, Information Technology, Computer Engineering, Electrical & Electronic Engineering, or a related discipline.
Experience supporting Industrial Control Systems (ICS), SCADA, DCS, or Operational Technology (OT) environments.
Knowledge of cybersecurity standards and regulations such as:
- CSA Cybersecurity Codes of Practice (CCOP)
- ISO 27001
- IEC 62443
- NIST Cybersecurity Framework
- EMA/PSO requirements
Experience with vulnerability management, security monitoring, risk assessments, and cybersecurity audits.
Strong troubleshooting and project management skills.
Relevant certifications such as CISSP, CISM, GICSP, ISA/IEC 62443, CEH, or equivalent will be advantageous.
Experience in information technology computer systems for end user support and scripting would be advantageous.
Experience in computer hardware troubleshooting and replacement would be beneficial.