Support the company's ICS/OT operations, including networks, systems, endpoints, and cybersecurity tools.
Maintain OT system and network monitoring to ensure availability and reliability.
Configure, troubleshoot, and provide day-to-day operational support for cybersecurity solutions within the ICS environment.
Support day-to-day control system operations and troubleshoot issues to ensure reliable plant performance.
Monitor systems for unusual or suspicious activities and respond to cybersecurity incidents, alerts, and threats.
Maintain and enhance security controls for critical systems to meet operational and cybersecurity requirements.
Manage CII system and network backup processes to ensure business continuity and recovery readiness.
Information Security Governance & Compliance
Manage and maintain the organization's Information Security Management System (ISMS).
Conduct annual reviews and updates of ISMS policies, procedures, and supporting documentation.
Implement and maintain cybersecurity requirements in compliance with CSA, PSO, EMA, CCOP, ISO 27001:2022, and other applicable standards and regulations.
Take ownership of ISMS-related activities and continuous improvement initiatives.
Serve as the key liaison between the organization, customers, auditors, service providers, and internal information security stakeholders.
Risk, Vulnerability & Security Assessment
Conduct annual cybersecurity risk assessments for Critical Information Infrastructure (CII) systems.
Identify, assess, and mitigate cybersecurity risks to ensure critical systems remain secure and resilient.
Perform vulnerability management and patch management activities for OT/ICS environments.
Plan and execute cybersecurity activities including:
Vulnerability Assessments (VA)
Penetration Testing (VAPT)
Threat Hunting
Purple Team Exercises
Tabletop Exercises
Security Reviews and Assessments
Review cybersecurity advisories and implement mitigation measures where necessary.
Audit & Regulatory Management
Support and coordinate internal and external cybersecurity audits.
Plan and execute annual cybersecurity audit programs.