Key Responsibilities
• Conduct cybersecurity risk assessments for software, systems, and network infrastructure.
• Perform threat modeling using tools such as STRIDE.
• Conduct and support vulnerability assessments and penetration testing.
• Ensure compliance with relevant standards and regulations (e.g., ISO 27001, NIST SP 800-82, FDA, HIPAA, GDPR, PCI DSS, etc).
• Monitor and interpret changes in global cybersecurity regulations and standards, integrating them into client policies and procedures.
• Support internal and external audits, including remediation coordination at client sites.
• Collaborate with engineering and development teams to design secure system architectures.
• Experience with secure coding practices and encryption technologies.
• Guide teams in applying cybersecurity controls throughout the software development lifecycle (SDLC).
• Monitor cybersecurity threats and develop mitigation strategies.
• Respond to and investigate cybersecurity incidents, identifying root causes and recovery actions.
• Utilize and manage security technologies including:
o Firewalls
o Intrusion Detection/Prevention Systems (IDS/IPS)
o Endpoint protection
o Data Loss Prevention (DLP)
o SIEM systems
o Log aggregation tools
• Support the deployment and operational use of Governance, Risk, and Compliance (GRC) platforms.
• Work with cross-functional teams (e.g., Engineering, QA, IT), centralized corporate cybersecurity team, integrators and vendors to document and implement cybersecurity controls to achieve program requirements while enabling business outcomes.
• Subject Matter Expertise on security projects to ensure the timely, on-budget, and effective implementation of cyber security improvements that are operationally supported with validation methods in place to measure effectiveness.
• Looking for an ITOT/Engineer who can perform Cybersecurity Operations. And will perform Factory OT Cybersecurity, leaning a bit more on the Cybersecurity space.
• Day-to-day tasks include Cyber risk assessment, articulating them, buy-in to mitigate risk, prevent downtime.
• Looking for someone with industry experience rather than a PhD who can be pragmatic, persuasive, calm under pressure, good at translating security needs to operational language, strong at influencing without authority, and realistic.
• Respond with urgency but accuracy.
Qualifications
Education & Experience
• Bachelor’s degree in Computer Science, Engineering, Information Security/ cybersecurity, or related field.
• 5+ years of experience in cybersecurity, preferably in regulated industries such as food, beverage, healthcare/pharma, or medical devices.
• Experience with cloud security, network protocols (SSL/TLS, VPNs, IPsec), and secure cloud-based applications.
• Familiarity with regulatory compliance (SOX, HIPAA, GDPR, FDA cybersecurity guidance).
• Proficiency in threat modeling, risk management, vulnerability management, and incident response.
• Experience securing both software and hardware systems in manufacturing environments.
• Strong understanding of cybersecurity frameworks (ISO 27001, NIST, SOC 2, HITRUST, NIST SP 800-82).
• Looking for prior experience in tools, including Architecture in IT/OT, Ignition, OSI-Pi, DeltaV, FactoryTalk, PLCs, Emerson, OT applications, and Nucleus reports, ARM-S, or Splunk.
• Using GRC - ServiceNow, CMDB, Process X, RMS.
• Stakeholder Management is a definite must-have.
Certifications
• GICSP strongly preferred, CISSP will be ideal, CISM, or equivalent certification preferred
Interview:
• The interview will be conducted through an initial screening team panel interview, which can be onsite.