About this role
Key Responsibilities
• Own and evolve the OT security architecture framework, policies, standards, procedures and reference patterns.
• Update the UCF to align with the OT Tiering Framework designed with Capgemini and relevant KPMG CMA recommendations.
• Drive NIS2 and applicable regulatory alignment for OT environments in collaboration with Legal, Risk and business teams.
• Define control requirements proportionate to site criticality, zones, conduits and operational risk.
• Support audits, maturity assessments, risk acceptances, exceptions and remediation governance.
• Provide architecture assurance for programmes, designs and major OT security investments.
• Maintain implementation guidance that enables repeatable adoption across clusters and plants.
Qualifications
• Bachelor's or master's degree in engineering, cyber security, information systems, risk or a related field, equivalent senior experience accepted.
• Deep understanding of OT frameworks, security architecture, industrial control systems and risk-based control design.
• Working knowledge of NIS2, IEC 62443, NIST CSF, ISO 27001 and industrial network segmentation principles.
Experience
• 10+ years in cybersecurity, architecture, governance, risk or audit, including 5+ years focused on OT/ICS.
• Experience developing enterprise policies, control frameworks, reference architectures and assurance processes.
• Experience translating assessments and regulatory obligations into implementable technical requirements.
Certifications
• GICSP and/or IEC 62443 certification strongly preferred.
• CISSP, CISM, CRISC, SABSA, TOGAF or ISO 27001 Lead Implementer/Auditor preferred.