S&S Senior Security Analyst

UL SolutionsTaiwanOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

The Senior Industrial Cybersecurity Assessor is responsible for defining project scope, reviewing technical documentation, conducting gap and risk assessments, coordinating security testing, determining conformity, managing technical findings, and preparing formal assessment reports.

This position serves as a senior technical point of contact for customers and internal stakeholders. The assessor handles complex technical issues, ensures project quality and timely delivery, reviews the work of junior assessors and engineers, and provides technical coaching and training.

Depending on individual qualifications and authorization, the position may act as a Project Handler, Technical Assessor, or Technical Reviewer.

Minimum Qualifications

- Bachelor’s degree or higher in Cybersecurity, Electrical Engineering, Electronics Engineering, Instrumentation and Control, Automation, Computer Engineering, Computer Science, Information Technology, or another related technical discipline.
- At least five years of relevant experience in cybersecurity, OT/IACS security, product security, embedded systems, industrial automation, or a related field.
- Demonstrated experience independently conducting cybersecurity assessments, audits, certification projects, or technical reviews.
- Practical project experience with the IEC 62443 series, particularly IEC 62443-4-1, IEC 62443-4-2, IEC 62443-3-2, or IEC 62443-3-3.
- Knowledge of industrial control system architectures, including PLC, SCADA, DCS, HMI, SIS, IIoT gateways, and common OT communication protocols.
- Ability to review cybersecurity plans, risk assessments, security architectures, threat models, SSDLC documentation, and security testing reports.
- Strong knowledge of core cybersecurity disciplines, including risk management, asset security, network security, identity and access management, vulnerability management, and secure product development.
- Demonstrated ability to prepare formal technical reports, make defensible technical determinations, communicate with customers, and deliver technical presentations.
- Ability to manage multiple projects simultaneously, address complex technical matters, and coach junior engineers or assessors.
- Excellent written and verbal English skills, including the ability to lead technical meetings, review technical documentation, and prepare formal reports in English.
- Strong attention to detail, accuracy, accountability, and responsiveness to customer needs.
- Ability to work collaboratively in an international, fast-paced environment.
- Willingness to travel domestically and internationally based on project requirements.

Preferred Qualifications

- IEC 62443 or ISASecure training, certification, or assessor qualification.
- Professional certifications such as CSSLP, CISSP, GICSP, Security+, OSCP, or equivalent.
- Experience in product penetration testing, vulnerability analysis, fuzz testing, secure code review, firmware security, or hardware security analysis.
- Familiarity with ISO/SAE 21434, UNECE R155/R156, ETSI EN 303 645, the EU Cyber Resilience Act, UL 2900, UL 2941, EN 50742, or other applicable product cybersecurity standards and regulations.
- Experience working for a certification body, testing laboratory, or conformity assessment body.
- Experience in critical infrastructure sectors such as energy, water, oil and gas, chemicals, maritime, renewable energy, electric vehicle charging, transportation, telecommunications, smart manufacturing, or similar industries.
- Experience supporting or developing certification and assurance programs, including ISASecure, the CAP Scheme, and related cybersecurity services.
- Ability to support business development, lead generation, and the development of new cybersecurity services.