OT Vulnerability Analyst

Company: Scotia Gas Networks
Apply for the OT Vulnerability Analyst
Location:
Job Description:

Overview

In this role you will identify and manage OT vulnerabilities across cyber tools, assessments, and audits within SGN’s OT/ICS environment. You will collaborate with third-party security partners, deliver security assurance, and support OT security projects to align with policy and risk appetite. You’ll translate security requirements into architecture and design decisions and report on remediation progress to the vulnerability manager. This opportunity lets you contribute to safe, reliable energy delivery in a growing, mission-driven team.

Pay / Benefits

  • Joint-contribution pension 6% (12% total)
  • Enhanced maternity & family leave
  • Life assurance
  • HolidayPlus
  • Virtual GP
  • Employee Assistance Programme

Responsibilities

  • Ensure cyber security assurance by aligning solutions with approved architecture definitions
  • Coordinate mitigating actions with MSSP, penetration testers, SOC operators, and third-party vendors
  • Contribute to delivering new security tooling with the technical security and assurance team
  • Provide security consultations to Project Business Analysts and Project Management for OT projects
  • Review architecture documents for compliance with OT security policies and regulatory requirements
  • Participate in Architecture Review Board and Technical Design Authority meetings
  • Define in-flight security requirements and embed them into processes
  • Post-implementation/security audits for OT projects and verify design vs delivery
  • Collaborate with IT/OT Security Leads and Corporate IT to deploy solutions
  • Configure vulnerabilities management tools and identify vulnerabilities across IT/OT estate
  • Triage, prioritize, and track remediation; report metrics and risk/exceptions to Security Assurance
  • Support service improvements initiatives

Key requirements

  • 2 years’ cyber security experience in an OT environment with strong OT/ICS knowledge
  • Expertise in at least three domains: Vulnerability Assessment and Management, Security Risk and Compliance, Security Architecture, Endpoint Protection, Network Security, or Security Engineering
  • Knowledge of cyber security frameworks and standards (NCSC, NIST, ISO 27001/27005, IEC 62443)
  • Understanding of Cyber Assurance Framework and experience with regulators for OT compliance
  • Knowledge of Purdue model and network segmentation in OT systems
  • Security Clearance (required)
  • collaboration and stakeholder management
  • clear communication with technical and non-technical audiences
  • ability to coordinate with vendors and cross-functional teams
  • Vulnerability Assessment and Management
  • Security Architecture
  • Security Engineering

…

Posted: September 15th, 2026