Job Responsibilities:
OT / ICS Operations & Security Management
- Support the company's ICS/OT operations, including networks, systems, endpoints, and cybersecurity tools.
- Maintain OT system and network monitoring to ensure availability and reliability.
- Configure, troubleshoot, and provide day-to-day operational support for cybersecurity solutions within the ICS environment.
- Support day-to-day control system operations and troubleshoot issues to ensure reliable plant performance.
- Monitor systems for unusual or suspicious activities and respond to cybersecurity incidents, alerts, and threats.
- Maintain and enhance security controls for critical systems to meet operational and cybersecurity requirements.
- Manage CII system and network backup processes to ensure business continuity and recovery readiness.
Information Security Governance & Compliance
- Manage and maintain the organization's Information Security Management System (ISMS).
- Conduct annual reviews and updates of ISMS policies, procedures, and supporting documentation.
- Implement and maintain cybersecurity requirements in compliance with CSA, PSO, EMA, CCOP, ISO 27001:2022, and other applicable standards and regulations.
- Take ownership of ISMS-related activities and continuous improvement initiatives.
- Serve as the key liaison between the organization, customers, auditors, service providers, and internal information security stakeholders.
Risk, Vulnerability & Security Assessment
- Conduct annual cybersecurity risk assessments for Critical Information Infrastructure (CII) systems.
- Identify, assess, and mitigate cybersecurity risks to ensure critical systems remain secure and resilient.
- Perform vulnerability management and patch management activities for OT/ICS environments.
- Plan and execute cybersecurity activities including:
- Vulnerability Assessments (VA)
- Penetration Testing (VAPT)
- Threat Hunting
- Purple Team Exercises
- Tabletop Exercises
- Security Reviews and Assessments
- Review cybersecurity advisories and implement mitigation measures where necessary.
Audit & Regulatory Management
- Support and coordinate internal and external cybersecurity audits.
- Plan and execute annual cybersecurity audit programs.
- Coordinate CSA audits, vulnerability assessments, compliance reviews, and mandated regulatory audits.
- Ensure audit findings are tracked, remediated, and closed within agreed timelines.
- Support information security requirements during both internal and external audits.
Security Projects & Technology Improvement
- Review existing technology architecture and identify vulnerabilities, weaknesses, and improvement opportunities.
- Plan, implement, and oversee cybersecurity technology upgrades, enhancements, and major system changes.
- Develop technical solutions, cost estimations, budgets, and proposals to meet cybersecurity requirements for internal and external projects.
- Support the delivery, commissioning, and cybersecurity assurance of new projects and plant systems.
- Ensure all new systems meet operational, cybersecurity, and regulatory requirements before deployment.
Vendor & Stakeholder Management
- Work closely with business units, service providers, and external stakeholders to ensure OT cybersecurity requirements are met.
- Collaborate with internal IT security personnel and Site Information Security Officers (SITSO) on cybersecurity initiatives.
- Evaluate and monitor cybersecurity service performance and Key Performance Indicators (KPIs) of third-party vendors and contractors.
- Coordinate cybersecurity activities with the EC&I Department and support departmental objectives.
Training & Awareness
- Develop and deliver cybersecurity awareness programs and training sessions for employees.
- Promote cybersecurity best practices across the organization.
- Provide guidance and support to users on cybersecurity policies, procedures, and compliance requirements.
Job Requirements:
- Degree or Diploma in Cybersecurity, Information Technology, Computer Engineering, Electrical & Electronic Engineering, or a related discipline.
- Experience supporting Industrial Control Systems (ICS), SCADA, DCS, or Operational Technology (OT) environments.
- Knowledge of cybersecurity standards and regulations such as:
- CSA Cybersecurity Codes of Practice (CCOP)
- ISO 27001
- IEC 62443
- NIST Cybersecurity Framework
- EMA/PSO requirements
- Experience with vulnerability management, security monitoring, risk assessments, and cybersecurity audits.
- Strong troubleshooting and project management skills.
- Relevant certifications such as CISSP, CISM, GICSP, ISA/IEC 62443, CEH, or equivalent will be advantageous.
- Experience in information technology computer systems for end user support and scripting would be advantageous.
- Experience in computer hardware troubleshooting and replacement would be beneficial.