Location
Riyadh
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
About the Role
As a Senior Consultant – Senior Manager, you will play a pivotal role in designing and implementing operational technology (OT) security measures. Your primary responsibilities will include defining OT security architectures, assessing OT environments, testing both OT and connected IT environments, managing OT security operations, and governing and reporting on OT security compliance and posture.
Key Responsibilities
- Design OT Security
- Define the OT security architecture and reference designs, including Purdue-model zoning and IEC 62443 frameworks.
- Set cybersecurity requirements for OEMs, system integrators, and contractors, and review their designs prior to installation.
- Ensure systems are delivered hardened and documented during new builds, eliminating default credentials and unused services.
- Define secure IT/OT integration patterns for systems sharing data with business and smart-city platforms.
- Assess OT Environments
- Build and maintain an OT asset inventory, including controllers, HMIs, servers, and network devices.
- Conduct IEC 62443 risk assessments to identify zones, set security levels, assess gaps, and recommend controls.
- Ensure compliance with NCA OTCC and NCA ECC for OT systems and track remediation efforts.
- Test OT and Connected IT Environments
- Perform configuration reviews of PLCs, HMIs, SCADA systems, and industrial firewalls against vendor hardening guides.
- Conduct firewall and segmentation testing to ensure proper blocking of unauthorized paths.
- Analyze OT network traffic to identify unknown assets and insecure protocols.
- Test IT systems supporting OT, including patch management, hardening, and account privileges.
- Examine vendor remote access paths for weak authentication and ensure safe testing procedures.
- Manage OT Security Operations
- Deploy and manage OT network monitoring solutions like Nozomi, Claroty, or Dragos.
- Collaborate with SOC and operations teams to create incident response playbooks and conduct joint exercises.
- Oversee OT vulnerabilities and patching in accordance with vendor support and safety requirements.
- Control and monitor third-party access to OT systems.
- Govern and Report
- Develop OT security policies, standards, and procedures that align with NCA OTCC and IEC 62443.
- Partner with operations and engineering teams to communicate security matters in operational terms.
- Report the OT risk posture and compliance status to management.
Leadership Capabilities
- Builds understanding of organizational purpose and values, seeking opportunities for impact.
- Demonstrates a commitment to personal learning and development while attracting top talent.
- Takes personal accountability for performance and development goals.
- Focuses on effective communication and relationship-building skills.
Qualifications
- 5-10 years of total experience.
- Bachelor's degree in electrical, control, computer engineering, or a related field.
- Hands-on experience with OT/ICS environments including PLCs, DCS, SCADA, and industrial networks.
- Knowledge of industrial protocols such as Modbus, BACnet, and DNP3.
- Practical experience with IEC 62443 and NCA OTCC standards.
- Skills in technical testing of OT and IT environments, including network traffic analysis tools like Wireshark and Zeek.
- Familiar with at least one OT monitoring platform (e.g., Nozomi, Claroty, Dragos).
- Comfortable operating on live sites under safety rules.
- Experience with smart-city IoT, ride or show control, and securing new-build projects is preferred.
- Knowledge of Windows/Active Directory hardening in OT environments is advantageous.
- Network engineering skills, particularly with industrial firewalls and segmentation, are preferred.
- Proficiency in Arabic is preferred.
- Certifications such as GICSP, GRID, ISA/IEC 62443 Cybersecurity Expert/Specialist, along with others such as CISSP, GCIP, GPEN, are valued.
- Familiar with NCA and IEC frameworks and standards, including NIST SP 800-82 Rev 3 and MITRE ATT&CK for ICS.