Cyber Security Specialist.Information Technology
Indexed description
Description
Key Accountabilities:
Network Infrastructure & Connectivity Support
- Lead and oversee the secure design, implementation, operation, and continuous improvement of GDI’s network infrastructure to ensure availability, performance, resilience, and security across corporate and operational environments.
- Supervise network administration activities, including routers, switches, firewalls, VPN services, wireless networks, communication platforms, and related infrastructure technologies, to ensure compliance with approved security standards, operational requirements, and best practices.
- Ensure reliable and secure connectivity for users, systems, operational technologies, and external integrations through continuous monitoring, performance management, and proactive resolution of network-related issues.
- Enforce network security controls, including segmentation, access control, monitoring, logging, and secure communications, to protect organizational assets and support compliance with ISMS and regulatory requirements.
- Provide technical direction and oversight to Network Administration resources to ensure effective service delivery, compliance with service levels, and consistent implementation of operational and security procedures.
- Coordinate with internal stakeholders and external service providers to support communication systems, data center connectivity, VSAT services, internet services, and third-party connectivity requirements.
- Support incident response, business continuity, and disaster recovery activities by maintaining network resilience, availability, recoverability, and operational readiness.
- Ensure the security of Operational Technology (OT) and Industrial Automation and Control Systems (IACS) environments through network segmentation, secure remote access controls, monitoring activities, and implementation of applicable industrial cybersecurity requirements (including ISA/IEC 62443 standards).
- Lead and oversee the implementation, operation, and continuous improvement of network security controls and access management frameworks to protect GDI’s information assets, infrastructure, and operational environments.
- Define and enforce secure access requirements relating to authentication, authorization, network segmentation, privileged access, and remote connectivity in alignment with ISMS requirements, cybersecurity standards, and regulatory obligations.
- Oversee administration of identity and access controls across network and security environments and ensure adherence to the principles of least privilege and segregation of duties.
- Direct the configuration, management, and optimization of firewalls, VPNs, Network Access Control (NAC) solutions, intrusion detection and prevention technologies, and related security platforms in coordination with Network Administration resources.
- Monitor and review access rights, privileged accounts, network security events, and security logs to identify unauthorized activities and ensure compliance with approved security requirements.
- Coordinate periodic access reviews, access recertification activities, and remediation actions to maintain appropriate access governance and security compliance.
- Provide technical guidance on secure network architecture, access control design, and security requirements to support business needs while maintaining an effective security posture.
- Support incident investigations, forensic reviews, compliance assessments, and audit activities relating to network security and access management.
- Lead and govern the end-to-end incident management process for IT and security-related events, ensuring timely detection, response, resolution, and documentation in line with approved procedures and SLAs.
- Establish and maintain incident management processes, escalation procedures, communication protocols, and reporting mechanisms aligned with ISMS requirements and business continuity objectives.
- Oversee monitoring, triage, analysis, prioritization, and escalation of cybersecurity and operational incidents and coordinate response activities with internal teams and external service providers.
- Direct incident response and recovery activities, ensuring root cause analyses are completed and corrective actions are implemented to prevent recurrence and strengthen operational resilience.
- Provide technical leadership and guidance to IT support and Network Administration teams in resolving complex incidents and maintaining service availability.
- Ensure incident records, investigation findings, response activities, and closure documentation are accurately maintained to support audit, compliance, and performance monitoring requirements.
- Develop and maintain incident response playbooks, coordinate incident response exercises, and support disaster recovery and business continuity readiness activities.
- Lead and govern GDI’s vulnerability management program to ensure timely identification, assessment, prioritization, remediation, and reporting of vulnerabilities across systems, networks, applications, cloud environments, and operational technologies.
- Oversee vulnerability scanning, assessment, reporting, and remediation activities and ensure identified vulnerabilities are appropriately risk-ranked, assigned, tracked, and resolved through approved remediation processes.
- Direct implementation of corrective actions, patch management activities, configuration hardening initiatives, and security improvement measures in coordination with Network Administration and other IT resources.
- Provide analysis, reporting, and recommendations regarding security risks, vulnerability trends, threat exposure, and remediation performance to management and relevant stakeholders.
- Support incident investigations, audit activities, compliance assessments, and security reviews through provision of vulnerability management data, remediation evidence, and security assurance information.
- Oversee vulnerability identification and remediation activities relating to OT and IACS environments in alignment with industrial cybersecurity requirements and operational risk considerations.
- Ensure compliance with information security policies, standards, ISMS (ISO 27001) requirements, industrial cybersecurity requirements, and applicable regulatory obligations through effective implementation and monitoring of security controls and operational practices.
- Coordinate internal audits, external audits, cybersecurity assessments, certification activities, compliance reviews, and remediation programs to support audit readiness and ongoing compliance.
- Oversee identification, tracking, reporting, and remediation of audit findings, non-conformities, security observations, and control gaps and ensure corrective actions are completed within agreed timelines.
- Maintain security documentation, policies, procedures, access review records, vulnerability management records, incident documentation, and audit evidence required to support compliance and assurance activities.
- Conduct and coordinate security risk assessments, vulnerability risk assessments, and control reviews and ensure identified risks are appropriately documented and incorporated into relevant risk registers.
- Monitor implementation of risk treatment plans, mitigation activities, and corrective actions and provide reporting on residual risks, remediation progress, and risk exposure.
- Prepare and present security risk reports, compliance updates, assessment results, and cybersecurity insights to management and stakeholders to support informed decision-making.
- Conduct cybersecurity risk assessments relating to Operational Technology (OT) and Industrial Automation and Control Systems (IACS), considering operational impacts, safety implications, and applicable industrial cybersecurity requirements.
- IT Manager and IT Teams
- Operations, Technical, Finance, Internal Audit, Governance, HR, and QHSE Teams
- Infrastructure, Cybersecurity, Telecommunications and Managed Service Providers
- Cloud Service Providers and Technology Vendors
- Hardware, Software, Network, and Communication Systems Vendors
- External Technical Consultants
- Operates within a security-critical technology environment supporting GDI’s Information Security Management System (ISMS), cybersecurity strategy, network infrastructure, enterprise technology platforms, and Operational Technology (OT) environments.
- Leads cybersecurity operations, network security, vulnerability management, incident response, compliance, and risk management activities across corporate and operational technology environments.
- Provides technical leadership, oversight, and direction to Network Administration and IT support resources to ensure compliance with security standards, operational requirements, and approved procedures.
- Exercises professional judgment in assessing cybersecurity risks, directing incident response activities, implementing security controls, prioritizing remediation actions, and recommending security improvements within approved governance frameworks.
- Monitors emerging cybersecurity threats, vulnerabilities, regulatory developments, and industrial cybersecurity requirements and recommends actions to strengthen organizational security posture and resilience.
- Escalates significant cybersecurity risks, major incidents, control deficiencies, and compliance concerns to IT Management for resolution and strategic decision-making.
- Bachelor’s degree in information technology, Computer Science or a related field from an internationally recognized university or relevant proven experience.
- Professional certifications such as CISSP, CISM, CEH, Security+, GSEC, GIAC certifications, or equivalent are preferred.
- Knowledge of information security and industrial cybersecurity standards, including ISO/IEC 27001 and ISA/IEC 62443.
- Familiarity with Operational Technology (OT), Industrial Automation and Control Systems (IACS), and IT/OT convergence principles is advantageous .
- Minimum of 8 years of relevant experience in IT security or cybersecurity roles, including exposure to network security, vulnerability management, incident response, and familiarity with OT/IACS environments is an advantage.
- Strong knowledge of network security architecture, network administration, access control frameworks, and cybersecurity technologies including firewalls, VPNs, NAC, SIEM, endpoint security, and monitoring platforms.
- Strong understanding of incident response, vulnerability management, threat mitigation, security operations, risk assessment, and security governance practices.
- Knowledge of information security management systems, ISO 27001 requirements, cybersecurity compliance practices, and audit readiness requirements.
- Good understanding of Operational Technology (OT), Industrial Automation and Control Systems (IACS), industrial cybersecurity principles, ISA/IEC 62443 requirements, and IT/OT convergence environments.
- Ability to assess cybersecurity risks, analyze vulnerabilities, investigate incidents, and recommend practical mitigation and remediation strategies.
- Strong leadership, stakeholder management, communication, and coordination skills with the ability to guide technical teams and collaborate effectively with business and technology stakeholders.
- Strong analytical, problem-solving, decision-making, and incident management capabilities in complex operational environments.
- Ability to manage multiple priorities, security initiatives, incidents, and operational activities in a fast-paced environment.
- Language proficiency: English (required).
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search