Core Responsibilities
- Conduct Risk Assessments: Execute initial high-level risk assessments (per IEC 62443-3-2) to identify worst-case unmitigated risks and detailed risk assessments where threats exceed tolerable levels.
- Impact & Consequence Analysis: Evaluate the physical, safety, environmental, and financial impacts of a potential cyber disruption on critical industrial processes and plant operations.
- Zone and Conduit Definition: Collaborate with engineering teams to segment networks into secure zones and conduits based on data flows and target Security Levels (SL-T).
- Vulnerability & Gap Analysis: Review system architectures, existing countermeasures, network drawings, and asset inventories to locate security gaps.
- Documentation & Remediation: Produce risk registers, security requirements specifications (CRS), and actionable, time-bound remediation roadmaps for stakeholders.
Key Requirements & Qualifications
- Standard Knowledge: Deep familiarity with the IEC 62443 framework
- OT/ICS Experience: Understanding of industrial network architectures, SCADA systems, and the Purdue Model.
- Soft Skills: Ability to translate complex technical risks into clear business impacts for non-technical leadership.
Seniority Level:
Not Specified