Cyber Security Specialist
Krakow, PL
Job Purpose
Reporting to the OT/IACS Assurance & Engineering Sr. Manager, the Cybersecurity Specialist is responsible for providing cybersecurity support and oversight for product development groups and industrial control system environments within TechnipFMC. This includes defining, managing, and enforcing IACS security controls, processes and procedures. Relies heavily on experience in both information security and automation technologies focusing on industrial controls systems. Additional responsibilities include serving as a member of the IACS Cybersecurity team, the information and digital services team, working closely with sites, services, technical teams and product groups to ensure that security requirements and support are provided. In this role, the IACS Security Specialist will be a member of the global Information Security team, within the CISO’s department, serving as regional IACS Security representative for Norway and Poland while providing Global support for projects and initiatives from the Security team.
Job Description
- Provide secure design, development, and architecture requirements for Industrial Control Systems (ICS) environments and information and digital systems as they relate to ICS and automation.
- Provide cybersecurity awareness and training within product development and ICS environments.
- Provide support to write, review, and maintain documents, policies, and standards governing the cybersecurity requirements for the ICS environment.
- Provide secure architecture requirements for lab and development networks.
- Perform security reviews and assessments of systems, networks, and processes/procedures in ICS environments.
- Assist with testing, selection and implementation of security technologies in ICS environments.
- Provide support for projects and initiatives that enables sites to accomplish project goals in a secure manner.
- Provide support for management and remediation of vulnerabilities identified in ICS environments.
- Acts as subject matter expert in Industrial Automation and Control Systems security.
- Support on the development of cybersecurity technology implementation strategies for ICS environments with clear understanding of the differences between IT and OT environments (e.g. Anti-virus on HMIs, application whitelisting, security policies for firewalls in ICS environments, etc.).
- Support the execution of risk based methodologies for cybersecurity assessments of ICS systems, including remote sites, onsite, third party, and on vessels.
- Support on the creation of technical design documentation and to write technical reports for both technical and management consumption and understanding.
- Follows the established metrics and key performance indicators to monitor the overall health and effectiveness of the ISC cybersecurity program.
- Stays informed about the latest cyber threats to the ICS environment including threats towards the organization.
- Supports on the development of strategies and plans to mitigate emerging cyber threats.
You are meant for this job if:
- Bachelor’s degree or equivalent
- Strong technical ICS experience (5 years +): ability to review configurations of ICS (e.g. HMIs, engineering software, PLCs, etc.), identify best practices for backup and recovery of ICS, and understand industrial protocols.
- Good general technical knowledge: Applications technologies, networks, protocols, databases, operating systems (Windows/Linux)
- Understanding of Industrial Networks
- Experience using ICS software including:
- Engineering Software
- Version Management Software
- HMI Software
- OPC Software
- Working knowledge of networking concepts, ability to review network designs, and perform security assessments of network devices (e.g. switches, routers, firewalls).
- Good writing/presentation skills
- Fluent in English
- Cybersecurity certifications (e.g.: CISSP)
- ICS Security Certifications (SANS GICSP, ISA/IEC 62443 Risk Assessment Specialist)
- Experience implementing security controls, hardening, and technologies in automation systems and networks.
- Experience implementing vulnerability and patch management in ICS environments.
- Working knowledge of IACS Security standards.
- Willingness to travel to other TechnipFMC sites (5%).
Skills