About the Company
On behalf of our client, Affinity is in search of a Senior Analyst, Cyber Security Operational Technology (OT) to join its cybersecurity team. This role serves as a key technical bridge between cybersecurity, engineering, and field operations, ensuring the security, reliability, and resilience of industrial control environments.
The successful candidate will play a pivotal role in protecting critical operational systems, including SCADA, ICS, DCS, and PLC environments, through the implementation of cybersecurity controls, incident response leadership, risk management initiatives, and secure architecture design.
This is an opportunity to contribute to the protection of essential infrastructure while driving innovation and modernization across a complex operational technology landscape.
About the Role
This role serves as a key technical bridge between cybersecurity, engineering, and field operations, ensuring the security, reliability, and resilience of industrial control environments.
Responsibilities
- Lead the design, implementation, and maintenance of cybersecurity controls within Operational Technology (OT) environments, including ICS, SCADA, DCS, and PLC systems.
- Develop and execute cybersecurity initiatives focused on securing critical infrastructure and industrial control networks.
- Design and support network segmentation strategies to reduce cyber risk across operational environments.
- Collaborate with engineering, field operations, and technology teams to incorporate cybersecurity requirements into OT architecture and system design.
- Establish and enforce secure remote access controls for vendors, contractors, and internal users, leveraging least-privilege access principles.
- Monitor OT security systems and coordinate cybersecurity incident response activities affecting operational environments.
- Lead investigations, containment, remediation, and recovery efforts for OT-related cybersecurity incidents.
- Integrate OT telemetry, logs, and security data into enterprise monitoring and threat detection platforms.
- Support the development and enhancement of OT-specific detection use cases, threat hunting methodologies, and response playbooks.
- Embed cybersecurity controls throughout the OT asset lifecycle, including design, procurement, deployment, maintenance, and decommissioning.
- Perform cybersecurity risk and vulnerability assessments for industrial control systems and operational assets.
- Develop pragmatic remediation strategies that account for operational constraints, uptime requirements, and legacy technology considerations.
- Assess cybersecurity risks associated with industrial protocols, unsupported operating systems, and third-party technologies.
- Support regulatory compliance, internal audits, and security assessments against recognized industry frameworks and standards.
- Contribute to the development, maintenance, and enforcement of OT cybersecurity policies, procedures, and governance practices.
- Deliver cybersecurity awareness, training, and guidance to field operations and engineering stakeholders.
- Evaluate emerging threats, vulnerabilities, and technology solutions to continuously improve the organization's OT cybersecurity posture.
- Participate in strategic cybersecurity planning and contribute recommendations that improve operational resilience and business continuity.
- Support an organizational culture focused on safety, operational excellence, diversity, and continuous improvement.
Qualifications
- Bachelor's degree in Computer Science, Cyber Security, Engineering, Information Technology, or a related technical discipline, or an equivalent combination of education and experience.
- 5-10+ years of progressive experience in Cyber Security, Operational Technology (OT), Industrial Control Systems (ICS), or Critical Infrastructure environments.
- Demonstrated experience leading cybersecurity programs, projects, or initiatives involving industrial control systems and operational networks.
- Extensive knowledge of Industrial Control Systems (ICS), SCADA, Distributed Control Systems (DCS), Human Machine Interface (HMI), and Programmable Logic Controllers (PLCs).
- Hands-on experience implementing OT security technologies such as industrial firewalls, intrusion detection systems (IDS), endpoint protection platforms, network access controls, and passive monitoring solutions.
- Proven experience designing and securing segmented OT network architectures within highly regulated or critical infrastructure environments.
- Strong understanding of industrial communication protocols including Modbus, OPC, Ethernet/IP, Profinet, DNP3, or similar protocols.
- Experience conducting OT-focused risk assessments, vulnerability assessments, and remediation planning.
- Knowledge of secure remote access methodologies and privileged access management within OT environments.
- Experience supporting OT cybersecurity incident response efforts and coordinating with operations and engineering stakeholders during active security events.
- Familiarity with cybersecurity frameworks and standards including NIST Cybersecurity Framework (CSF), ISA/IEC 62443, NERC CIP, and ISO 27001.
- Understanding of cybersecurity governance, risk, and compliance (GRC) processes and security control validation.
- Experience working with enterprise ticketing and workflow management platforms such as ServiceNow is considered an asset.
- Knowledge of major industrial automation vendors including Rockwell Automation, Siemens, Schneider Electric, Honeywell, ABB, Emerson, or similar platforms.
- Relevant professional certifications such as CISSP, GICSP, ISA/IEC 62443, CISM, GIAC, or equivalent are strongly preferred.
- Experience within the energy, oil & gas, utilities, pipeline, power generation, or critical infrastructure sectors is highly desirable.
- Strong analytical, troubleshooting, and problem-solving capabilities with the ability to assess complex technical and operational risks.
- Excellent communication and stakeholder management skills with demonstrated ability to engage both technical and non-technical audiences.
- Self-motivated professional with a demonstrated passion for cybersecurity, operational excellence, and continuous learning.
Pay range and compensation package
Affinity Earn: Know someone who’s great for this, or any of our open roles? Earn up to $4,000/year for each successful referral through Affinity Earn. You can also earn up to $50,000 for helping us find new clients. Learn about our referral program at https://affinity-group.ca/earn/ or browse our jobs & follow us at https://www.linkedin.com/company/affinity-staffing/jobs/.
Equal Opportunity Statement
Affinity is committed to diversity and inclusivity.