Our client Scottish Power are currently recruiting for a Cyber Compliance & Disaster Recovery Engineer to join their team based in Prenton on a contract basis initially. Ideally for this role they are looking for a candidate with Cyber Security and disaster recovery expertise as well as experience in developing and implementing Cyber Security Compliance Programmes. For further information on this role see below:
Role Title
Cyber Compliance & Disaster Recovery Engineer (Real Time Systems)
Role Purpose
In this emerging team, you will sit within a close-knit function of Real Time System (RTS) team, with the focus on Cyber Security and Disaster Recovery.
As the Cyber Compliance & Disaster Recovery Engineer within our Operational Technology (OT) RTS department, you will have dual objectives to lead and ensure the implementation of and adherence to robust Cyber Security compliance and our Disaster Recovery standards on behalf of OT RTS. Operating from Scotland, you will play a critical role in safeguarding our RTS infrastructure, setting out measures, implementing and testing adherence to standards, mitigating risks threats, contributing to the setting of requirements for cyber-related projects/programmes and consulting with the SPEN OT Security Operations Centre (SoC)
Responsibilities
Cyber Leadership and Management:
• Collaborate with cross-functional teams and foster relationships between RTS, Cyber Operations (OT SoC), Business Continuity and UK IT Disaster Recovery, in additional to our 3rd party support partners
• Shape Cyber and Disaster Recovery activity ensuring changes align to business objectives and compliance standards.
• Support the development of the wider Cyber Security and OT Disaster Recovery strategy, including backup and restoration procedures, to minimise downtime and data loss by staying updated on Cyber Security and Disaster Recovery trends and assess appropriate application.
• Champion awareness of RTS Cyber Security and OT Disaster Recovery standards, requirements, behaviours and practices.
Network Compliance Monitoring and Vulnerability Remediation:
• Support the definition of RTS Cyber Security and OT Disaster Recovery objectives and KPIs.
• Conduct regular assessments, audits, dependency management, and risk & issues management of RTS Cyber Security and OT Disaster Recovery compliance and vulnerability posture and define projects to address related network vulnerabilities / required security enhancements.
• Enable continuous monitoring of security vulnerabilities for prompt detection of deviations.
• Champion the RTS Cyber Security and OT Disaster Recovery standards within designs and test plans to ensure requirements are incorporated to meet standards.
• Managing the RTS Cyber Security and OT Disaster Recovery documentation and reporting, ensuring that plans, procedures and results up to date, reviewed and communicated to the relevant stakeholders.
Testing and Exercises:
• Integrate and automate active security testing and auditing into the operational and development processes using various tools and technologies following Cyber Security and OT Disaster Recovery.
• Co-ordinate, create and update the runbooks for OT RTS, ensuring that they cover all the necessary steps, roles and responsibilities for Conventional and Cyber scenarios.
• Support the Conventional and Cyber testing schedule, ensuring that the tests are conducted regularly, effectively and in compliance with the Cyber Security and OT Disaster Recovery standards, ensuring that the organisation can recover critical data and resume operations as quickly as possible.
Compliance Reporting:
• Generate regular reports on network compliance, vulnerabilities, and remediation progress.
• Reporting key performance indicators on the security status, trends, and metrics, integrate security incidents back into automated pipelines to proactively prevent reoccurrence
• Advocate security and vulnerability improvements and communicate insights.
Skills/Experience/Capabilities
• Cyber Security and Disaster Recovery expertise: In-depth knowledge of Cyber Security principles, practices, and technologies. Awareness of current and emerging cyber threats, trends, and best practices
• Sector expertise: Previous experience in critical national infrastructure or similar sector, involving the delivery of security engineering
• Compliance management: Proven experience in developing and implementing Cyber Security compliance programs.
• Conventional & Cyber Exercise experience: Exposure to Disaster Recovery and BCM, creating plans, training, and exercising, and conducting post incident reviews.
• Risk management: Ability to assess and mitigate Cyber Security and Disaster Recovery risks.
• Policy development: Experience in developing and enforcing Cyber Security and Disaster Recovery policies and procedures.
• Audit coordination: Familiarity with coordinating and facilitating Cyber Security and Disaster Recovery audits.
• Training and communication: Effective communication and presentation skills for conducting training sessions and communicating effectively Cyber Security and Disaster Recovery measures with technical and non-technical audiences
• Continuous improvement mindset: Initiative to identify and implement continuous improvements in Cyber Security and Disaster Recovery compliance. Ability to rapidly learn deeply technical subjects related to product security, and an ability to keep abreast of security impacts to critical, high-impact environments.
Key Interactions
• Operations Teams: Collaborate with operations teams to ensure compliance measures are integrated into daily activities.
• Audit Teams: Work closely with internal and external audit teams for Cyber Security assessments.
• Cyber Security Teams: Coordinate efforts with OT Cyber Security and Cyber Operation teams for the implementation of Cyber Security measures.
• Business Continuity: Collaborate with Business Continuity in the alignment of regulatory certification and Conventional and Cyber testing exercises
• UK IT: Collaborate with Business Continuity in the alignment of Corporate testing exercises
Success Metrics
• Compliance Success: Achieve and maintain a high level of compliance with Cyber Security and Disaster Recovery standards and regulations.
• Risk Mitigation: Successfully mitigate identified Cyber Security and Disaster Recovery risks, leading to a reduction in incidents.
• Training Effectiveness: Positive feedback on the effectiveness of Cyber Security and Disaster Recovery training sessions.
• Continuous Improvement Impact: Number of successful continuous improvement initiatives implemented.