Senior OT Cyber Security Analyst/Engineer
Ontario region pay information
The salary range for this position in Ontario is $120,000 to $140,000. The determination of an applicant’s base salary within this range is based on the individual’s location, skills and competencies, and unique qualifications.
Notice on the use of artificial intelligence in our recruitment process
To ensure our hiring process is transparent, we want to inform all applicants that we utilize Artificial Intelligence (AI) technologies, including those integrated into our recruitment vendors' platforms. We are committed to an equitable process where applicants are evaluated based on job-related knowledge, skills, and abilities. AI technologies do not replace human judgment in the candidate selection process. All final hiring decisions are made by our hiring managers and recruitment teams.
Your day-to-day
Lead cyber security Governance Risk and Compliance (GRC) activities, including:
Navigate and interpret Operational Technology (OT) cyber security industry standards, including identifying and understanding the purpose for revision changes;
Architect OT cyber security programs from scratch;
Consult with clients as an OT Cyber Subject Matter Expert (SME);
Review client OT cyber security programs to compare against any implemented industry standards;
Review and guide clients to implement defensive cyber security architecture best practices;
Review and guide the implementation of risk assessments against client OT systems;
Develop and conduct organizational cyber security training to clients.
Mentor and coach junior and intermediate staff and review their deliverables when conducting Alithya Cyber Security Services;
Continuously contribute to and improve the processes and procedures of Alithya’s OT cyber security practice;
Suggest new OT cyber security services and contribute to their development;
Contribute to sales and marketing initiatives, including attending conferences, presenting webinars, writing blogs, writing proposals, estimating project costs, and meeting with potential clients;
Participate in cyber security research and development (R&D) activities, including software and hardware development;
Perform Factory Acceptance Testing (FAT) and Site Acceptance Testing (SAT) as required with the ability to diagnose issues and communicate solutions effectively;
Work independently as well as a member of a team in a project-based environment as needed.
Keys to your success
Post-secondary degree in Computer Science, Engineering, Information Security, or a related field;
CISSP certification;
8+ years of experience working in the field of cyber security, preferably in an OT environment, I&C, manufacturing, or nuclear;
Experience implementing CSA N290.7 standard, NEI 08-09 and NEI 13-10, IEC 62645, ISA/IEC 62443, NIST SP 800-82 or other OT-related cyber security standards;
Experience implementing defensive cyber security architecture best practices;
Experience writing cyber security governance documentation;
Experience conducting risk assessments to assess and remediate the risks of a system;
Experience reviewing and coaching junior or intermediate staff when preparing client deliverables;
Ability to obtain a Level 2 Secret Security Clearance from the Government of Canada (Standard on Security Screening- Canada.ca);
Comfortable in client-facing environments with a high level of attention to detail.
Extra edge
Professional Engineering (P.Eng.) designation and additional cyber security certifications, including GICSP or ISA/IEC 62443;
Experience with OPG or Bruce Power Engineering Change Control (ECC), consulting with and guiding clients, presenting and delivering cyber security training, and estimating project effort while supporting new client engagements;
CSIS Level 2 security clearance, preferably at OPG or Bruce Power;
Working knowledge of any of the following:
Harmonized Threat and Risk Assessment (HTRA) methodology;
Industrial Control Systems (ICS), computer Operating Systems (OS) and Virtual Machine (VM) technologies;
The Purdue model;
ICS communication protocols, ICS security components, physical and logical hardening controls.
Language skills
English: Proficient