Role summary
Lead comprehensive cybersecurity risk and compliance management across IT and OT environments. Coordinate with multiple teams to ensure regular risk assessments, compliance standards, and control effectiveness validation.
Responsibilities
- Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
- Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
- Identify and document OT-relevant risk scenarios such as control system disruption, unauthorized access, and safety manipulation
- Coordinate risk reviews during major IT/OT changes including system upgrades and new deployments
- Reassess risk posture following major changes, incidents, and regulatory updates
- Review and validate existing controls to calculate residual risk and prioritize treatment actions
- Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams
- Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
- Track risk treatment progress and escalate overdue or high-priority items
- Coordinate with performance management to define and monitor key risk indicators to track cybersecurity risk exposure changes
- Maintain cybersecurity risk register including OT-specific entries with identified risks, ratings, plans, ownership, and status
- Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
- Serve as lead interface for external audits and regulatory inspections including preparation, execution, and response
- Conduct periodic compliance assessments of OT environments including SCADA, DCS, PLCs, and associated network infrastructure
- Maintain inventory of compliance-relevant OT assets and map to applicable control requirements and standards
- Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions
- Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure
- Validate effectiveness of implemented controls or mitigation plans before closing compliance gaps
- Review and validate configuration baselines for OT systems such as firewall rules and firmware versions
- Coordinate evidence collection, documentation, and remediation planning for compliance-related findings
- Report OT and IT cybersecurity compliance status and risks to leadership and governance
- Support compliance awareness and training for teams with control responsibilities in IT and OT
- Maintain centralized compliance register mapping regulatory requirements to policies, controls, teams, and evidence sources
- Govern third-party cybersecurity risk through standardized assessment processes and due diligence criteria
- Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers
- Review vendor-supplied OT systems and documentation to ensure security controls and standards compliance
- Ensure third-party risk findings are documented, risk-rated, and tracked through resolution
- Maintain register of assessed vendors, associated risks, control gaps, and remediation status
- Collaborate with procurement, legal, and compliance to embed cybersecurity requirements in third-party agreements
- Contribute to development and review of third-party security policy and minimum control requirements
Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field
- Master's degree preferred
Requirements
- 10–12+ years of cybersecurity experience
- Strong experience in cybersecurity risk management, compliance, assessments, and assurance
Education
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field. Master's degree preferred.
Experience
10–12+ years of cybersecurity experience with strong background in risk management, compliance, assessments, and assurance.