OT Cybersecurity Manager
9 days ago
Valencia
Founded in 2003, Prosolia Energy is a leading business group in the renewable energy sector, with operations in Spain, Portugal, Italy, France, Germany and Mexico. Desplácese hacia abajo para encontrar una descripción detallada de este trabajo y lo que se espera de los candidatos. Envíe su solicitud haciendo clic en el botón "Solicitar". Prosolia Energy is an Independent Power Producer (IPP) specialised in providing decarbonisation services to our customers. We control the entire value chain of the projects through which we provide energy to our customers, developing, constructing, operating and maintaining a range of renewable generation and storage sources. We are committed to leading the transition of the industrial and productive sector towards a decarbonised, sustainable and competitive model. Our strategic objectives for the coming years include growing our asset base and expansion into new markets and products. Prosolia Energy now has a project portfolio of more than 4 GW. In order to build and develop this portfolio, as well as to achieve its strategic objectives, we are looking for talented, high potential professionals who wish to join our team and contribute to our continued success. We are looking for an OT Cybersecurity Manager to lead and implement cybersecurity strategies across our OT environments, ensuring robust risk management and compliance. Responsibilities: 1. Cybersecurity strategy Define and update the corporate OT cybersecurity strategy, aligned with the objectives of the Prosolia group, the risk strategy and the applicable regulations (IEC 62443, ISO 27001, NIS2, GDPR, etc.). Develop and maintain the framework of security policies, standards and procedures (remote access, communications, backups, use of accounts, etc.), ensuring their implementation in all countries and assets of the company, according to size and type. Carry out periodic cybersecurity risk assessments in OT infrastructures and control systems (SCADA, PLC, RTU, plant networks), identifying vulnerabilities and prioritizing mitigation actions. Develop and follow risk management plans, including technical and organizational measures. Prioritize and track remediation plans from OT risk assessments and audits, including deadlines, owners, and completion indicators. 1. OT Security Architecture and Operations Design and validate OT network security architecture, including network segmentation, secure remote access systems, traffic monitoring, and IT/OT segregation. Align OT architectures and solutions avoiding silos and promoting shared security capabilities. Define security requirements for new plant projects, SCADA upgrades or communications, reviewing third-party designs and ensuring that deliverables meet defined cybersecurity standards. Lead remediation campaigns (patching, hardening, segmentation) in coordination with IT, OT, O&M and vendors, ensuring no operational regression. Participate directly in configuration reviews (firewalls, VPN, remote access, accounts), OT backup restoration tests, and business continuity exercises. 1. Monitoring, detection and response to incidents Establish and coordinate security monitoring capabilities applied to critical OT networks, defining use cases, alarms, and escalation procedures. Lead cybersecurity incident response, from detection to shutdown (containment, eradication, recovery, and lessons learned), including coordination with IT, Insurance, Legal, and Corporate Communication when necessary. Establish structured post-incident processes (Root Cause Analysis, action plans, tracking to closure) integrated into risk/security committees. 1. Regulatory compliance, audits and reporting Ensure compliance with the regulations applicable to critical infrastructure security, data protection and industrial cybersecurity in the countries where the company operates, coordinating internal and external audits. Prepare periodic cybersecurity status reports (KPIs), main incidents, level of maturity and progress of action plans for Management, Risk Committees and others. 1. Third-party management and supplier lifecycle Define and review cybersecurity clauses in contracts, RFPs, and SLAs with OT, communications, cloud, and O&M service providers, including hardening, support, patching, and incident management requirements. Assess and monitor the cybersecurity risk of critical third parties (SCADA integrators, communications providers, SOC services) and coordinate corrective actions when breaches or breaches are identified. 1. Awareness, training and safety culture Design and execute cybersecurity training and awareness programs, adapted to OT (plant operators, field technicians, O&M) and IT groups, promoting good practices in the use of credentials, remote access and mobile devices. 1. Remote access and communications management Design, implement and supervise the secure architecture of communications between plant assets (SCADA, PLC, inverters, trackers) and control centers, guaranteeing the integrity, confidentiality and availability of operational data at all times. Establish and maintain secure VPN tunnels (IPSec, OpenVPN) and protected remote connections for technical access, centralized monitoring, and OEM support, applying network segmentation, end-to-end encryption, and multi-factor authentication (MFA). Define policies and procedures for validated remote access. Coordinate with telecommunications and OT teams the implementation of secure gateways, industrial firewalls and intrusion detection systems (IDS/IPS OT‑aware), validating configurations and performing periodic connectivity and resilience tests. Continuously monitor and audit remote communications traffic by responding to detected incidents and reporting usage and security metrics (access KPIs, response time, detected vulnerabilities). Evaluate and negotiate with providers (telecom, SCADA integrators or similar) security requirements in communications, periodically reviewing their compliance and coordinating corrective actions. 1. Governance, KPIs and Roadmap Management Build and maintain a multi‑year OT cybersecurity roadmap (maturity levels, investments, NIS2 priorities), updated annually. Define and track OT security KPIs (open vulnerabilities, remediation progress, incident response times, patching/backup/DR test coverage). Govern remediation action plans through regular steering committees with IT, Asset Management external partners and vendors, ensuring accountability and closure. Requirements: University degree in Computer Engineering, Telecommunications, Industrial Engineering or similar. Qualifications that are assessed: Master’s Degree in Cybersecurity or similar. Languages mandatory: Spanish and English. Languages that are assessed: Portuguese, Italian, French and German. Minimum of 3 5-7 years in OT/ICS/SCADA environments or renewable/industrial infrastructures. (3+ years with demonstrated experience in remediation project management or OT cybersecurity implementation). Proven experience defining and implementing security policies, leading security project, managing incidents and piloting multi‑stakeholder action plans. Other requirements: Project management and action plan governance. Ability to challenge OT integrators/MSPs on technical/security delivery. Cross‑functional coordination (IT/OT/Asset Management) and committee animation. xcskxlj Hands‑on OT security operations (configuration reviews, incident leadership). What’s in for you at Prosolia International and rapidly expanding company Opportunities for professional growth Flexible working hours and hybrid work possibilities #J-18808-Ljbffr