ICS Cybersecurity Specialist RLP
Qatar
Parttime: 0 hrs a week
Experience: Not applicable
Conventional Energy
Qatar
Parttime: 0 hrs a week
Experience: Not applicable
Conventional Energy
Hands-on responsibility for Industrial Control Systems (ICS) Cyber Security inclusive of protection, detection, response, and recovery for Windows-based operating systems and network levels 0 through 3.5 as per ISA/IEC 62443. Ensure compliance with company standards for both networked and standalone ICS/OT devices.
Establish a Cybersecurity management system and framework for the company. Develop and implement necessary Cybersecurity standard/policy/procedure/risk assessment framework.
Plan and facilitate internal/external audits to identify the ICS Cybersecurity gaps and vulnerabilities. Manage patch deployment for Windows devices in network levels 0 through 3.5 as well as standalone devices.
Identify obsolete Operating Systems (OS) and plan for necessary upgrades through vendor consultation. Consolidate standalone devices (e.g., laptops used for PLC configuration).
Prepare for the company's internal ICS audit by completing configuration review sheets for all workstations, servers, switches, firewalls, and routers in the OT environment. Correct deficiencies and document deviation/remediation plans. Prepare for the company's internal ICS audit by participating in and documenting compliance of all workstations, servers, switches, firewalls, and routers in the OT environment with company policies and procedures.
Participate in the design of cyber solutions for the OT environment (e.g. SIEM, IPS, ATP). Monitor patch deployment, anti-virus, SIEM, IPS, ATP and related systems and respond/investigate alerts.
Perform detailed, post event analysis of cyber events, and direct needed Incident response procedures. Perform detailed technical analysis of industrial control systems (ICS) and cyber security controls.
Participate in vulnerability assessments and administrative audits on client computer systems and network devices considering the sensitivity of operational technology testing. Identify cyber security gaps and recommend mitigation strategies to address gaps.
Maintain knowledge of the cyber security capabilities of operating systems, networking devices, control systems, and vendor offerings. Maintain a broad knowledge of current and emerging state-of-the-art computer/network systems technologies, architectures, and products.
Resolve technical issues considering operating impact and be able to communicate issue resolutions to OT organizations. Secure operational technology networks.
Design comprehensive technical solutions that meet compliance requirements and implement the appropriate software to mitigate critical security risks (e.g., system and antivirus software, encryption modules, patch management programs, insider threat protection, incident response plans, forensic capabilities, and regulation compliance). Lead collaboration efforts with other cyber security experts on team to develop well-constructed approaches to ICS risk management, mitigation, and monitoring strategies.
Responsible for securing systems running ICS-related communications protocols (e.g., MODBUS, PROFIBUS, etc.). Develop simulated ICS environments within a virtual infrastructure.
Participate in MOC / PSSR process.
Required: Bachelor's degree in Electrical Engineering, Electronic Engineering, Process Control Engineering, Instrumentation Engineering, Engineering Technology, Physical Engineering, Automation Engineering, Mechatronics Engineering, Cyber and Networking Security, Computer Engineering or Science majoring in Information Technology.
Preferred: Master's Degree Electrical Engineering, Electronic Engineering, Process Control Engineering, Instrumentation Engineering, Engineering Technology, Physical Engineering, Automation Engineering, Mechatronics Engineering, Cyber and Networking Security, Computer Engineering or Science majoring in Information Technology.
Experience
Required: 5+ years' experience in control systems engineering, DCS/PLC/SIS support, instrumentation maintenance, or related operational role Oil & Gas or chemical manufacturing environment. 3+ years' experience in ICS/OP Cyber Security
Preferred: 7+ years' experience in control systems engineering, DCS/PLC/SIS support, instrumentation maintenance, or related operational role in Oil & Gas or chemical manufacturing environment. 5+ years' experience in ICS/OP Cyber Security.