- Company Name
- Sword Group
- Job Title
- OT Security Consultant
- Job Description
-
**Job Title**
OT Security Consultant
**Role Summary**
Responsible for assessing, improving, and managing the security of operational technology (OT) and industrial control systems (ICS) across energy and critical infrastructure environments. Works directly with engineering, operations, and asset teams to deliver site surveys, risk assessments, and practical security roadmaps that align with regulatory standards and industry best practices.
**Expectations**
- Deliver end‑to‑end OT security engagements independently while collaborating with a wider network of experts.
- Engage stakeholders at all levels, including senior leadership, to provide clear, actionable findings.
- Contribute to the development and refinement of OT security standards and methodologies within the organization.
**Key Responsibilities**
- Plan and conduct on‑site assessments to catalogue OT assets, architectures, and vulnerabilities.
- Evaluate OT security posture against standards such as IEC 62443, NERC CIP, NESA, and OG 86.
- Develop and present pragmatic improvement roadmaps balancing security, safety, and operational continuity.
- Lead risk assessments, gap analyses, audits, and remediation planning.
- Advise on OT governance, policy, standards, and procedural controls.
- Assess and manage supply‑chain risk involving vendors and third parties.
- Mentor and support junior OT consultants and engineers.
- Serve as a trusted advisor throughout project delivery, from assessment to implementation.
**Required Skills**
- In‑depth knowledge of OT/ICS cyber security and industrial operational constraints.
- Experience across OT security domains: network architecture & segmentation, asset discovery, OT endpoint protection, governance, standards, and staff education.
- Proven ability to deliver assessments, reports, and actionable improvement plans.
- Strong stakeholder management, including presentations to senior leadership.
**Required Education & Certifications**
- Degree in a relevant discipline (e.g., Electrical Engineering, Computer Science, Information Security) or equivalent experience.
- GICSP certification (preferred).
- Familiarity with IEC 62443, NERC CIP, NESA, OG 86 frameworks.
- Additional cyber security certifications (CISSP, GCIA, GCIH, CEH, GCFE) considered valuable.