OT Cyber Security Manager
Job Title: OT Cyber Security Manager
Department: IE Cyber Security
Reports To: Head of Cyber IE
Dotted line To Technical Manager CME
Location: National Train Control Centre, Heuston Station
Employment Type: Full-time
Applications are invited for the above position. Reporting to the Head of Cyber the role will have responsibility for all aspects of Operating Technology Cyber Security within the CME, CCE, Rosslare and Capital Investments
Job Summary:
The operational technology (OT) Cyber Security Manager is responsible for protecting the security of Iarnród Éireann Operating Technology in the CME, CCE Rosslare and Capital Investments. They will also manage and maintain the relationships, data flows, and system integrations with external OT partners, including the Infrastructure Management Department and GITT. The Cyber OT Manager will develop and implement security strategies, policies, and procedures in collaboration with the Head of GRC and Architecture for IE to safeguard critical operations. This includes OT security strategy development, OT security policy and standard development aligned to IEC62443 and working towards compliance with the NIS2.0 directive and other cyber legislations. The ideal candidate will have deep expertise in OT systems, a strong understanding of cyber risk management, and the ability to collaborate across IT, engineering, and operational teams.
Key Responsibilities:
- Design, implement, and manage comprehensive OT security strategies, policies, and procedures that align with Iarnród Éireann’s objectives, industrial standards and regulatory requirements
- Develop, manage and monitor OT Cyber Security Standards in accordance with Safety Management System Requirements and IEC 62443
- Ensure compliance with relevant industry standards and regulations, such as IEC 62443, NIST800 etc
- Establish an OT Cyber Security Programme with consideration for the following:
- Development and Maintenance of an OT asset register for in scope locations
- Conduct risk assessments on the systems identified in the asset register
- Ensure cyber security requirements are considered at the design stage of any future OT system or piece of equipment for in scope locations
- Recommend and champion various projects and BAU activities that need to be carried out to attain and thereafter maintain a low cyber risk profile overall
- Implement incident response procedures and plans in collaboration with the Security Operations manager
- Lead incident response and recovery efforts specific to OT systems including root cause analysis and post incident reviews
- Maintain a BCP and BIA for each of the subsystems detailed in the OT asset register and periodically test in collaboration with the BCM Manager
- Ensure there are mechanisms and systems in place to monitor, detect and prevent cyber-attacks on the OT systems and equipment in scope
- Carry out third party risk reviews periodically with the suppliers/maintainers of the equipment and system in the OT asset register in collaboration with the Third party risk management lead
- Ensure the life cycle of OT system accounts are appropriately managed to minimise opportunities for attackers to leverage them
- Monitor OT networks for unusual activity and recommend/implement network segmentation and access controls
- Carry out a program to periodically test OT cyber defences and identify gaps
- Setup an OT vulnerability management programme
- Ensure OT Cyber Security support for projects and maintenance renewals is delivered in accordance with the Organisational OT standards and principals
- Collaborate with engineering, operations, and IT teams to ensure secure integration between IT and OT networks
- Ensure all Systems, Procedures, Policies & Supports are fit for the intended purpose, reflect the legal statutory requirements and are in accordance with agreed schedules & deliverables
- Manage all external contractors & support providers associated with OT Cyber Security in collaboration with the Third-party Risk management Lead
- Conduct risk assessments and threat modelling for OT environments to identify vulnerabilities/ and develop mitigation plans to protect critical OT assets on production systems and on projects working with the GRC team.
- Work closely with project engineering and technical teams to integrate cyber security measures into OT processes and technologies
- Working with the awareness and training lead, Develop and deliver security awareness training programs for the engineering functions to foster a culture of security and compliance
- Stay current with the latest cyber security trends, threats, and technologies to continually improve the organisation's OT security posture
- Provide cyber security advice and assistance to the engineering and other relevant teams
- Own production of technical documentation for software architecture, design, verification plans
- Represent the IE Cyber Team at meetings with internal & external bodies and to ensure that corporate policy is followed in the decision/actions taken regarding the outcome of such interaction where OT Cyber Security is a consideration
Safety
- Undertake audits, aligned to your key risk areas, to ensure robust safety management systems and emergency arrangements are in place
• Identifying the key risk areas under your control and ensure that staff, contractor, consultants and outside bodies comply with relevant company policy, standards and procedures
Key Qualifications:
Education:
- Degree level qualification in Electrical, Electronic, Mechanical Engineering or a related field (or equivalent qualifications)
- Experience in cyber security management, specifically within an OT environment.
Experience - 5 to 10 years in a senior engineering role
- Knowledge of the design of secure OT solutions aligned to the Purdue network model
- Knowledge of the design and delivery of solutions that must conform to IEC-62443 SL3 requirements
- In-depth knowledge of the design and delivery of Industrial Control Systems across a geographically dispersed organisation.
Skills and Competencies:
- Strong understanding of cyber security frameworks and standards, such as IEC62443, NIST, CIS and others.
Excellent analytical, problem-solving, and decision-making skills - Strong leadership and communication skills, with the ability to work effectively in cross-functional teams
- Experience of working with Cybersecurity tools like Wireshark, NESSUS, Burp Suite