Cyber Security Analyst
OT Cybersecurity Analyst
Position Summary
Level 1 (Entry):
Responsible for identifying OT (Operational Technology) cyber assets, applying basic security maintenance, and supporting incident response efforts. Assists in evaluating cybersecurity vulnerabilities and compliance gaps, and supports day-to-day cybersecurity functions, including patching, antivirus updates, and documentation.
Level 2 (Intermediate):
Maintains and improves OT cybersecurity posture by evaluating network architectures, system configurations, and applying cybersecurity standards. Provides planning, guidance, and mentorship to junior analysts, and assists with threat analysis and vulnerability remediation strategies.
Level 3 (Lead):
Leads the development and implementation of the OT cybersecurity framework, ensures compliance with industry standards (e.g., NERC CIP, NIST), and manages cybersecurity maintenance strategies. Serves as project lead, collaborates cross-functionally across IT and OT, and mentors cybersecurity personnel. Drives strategic initiatives and regulatory audit responses.
Key Responsibilities
Level 1 Responsibilities
- Identify and document OT cyber assets and configurations.
- Apply patches, antivirus updates, and system backups.
- Maintain baseline configurations of OT systems.
- Review and assess new CVEs (Common Vulnerabilities and Exposures) for OT assets.
- Support IT-related needs for OT systems (e.g., HMI, network appliances, remote connectivity).
- Update internal cybersecurity documentation and SharePoint site.
Level 2 Responsibilities
- Evaluate system architecture, configurations, and connectivity for compliance.
- Review vendor documentation and industry standards.
- Develop cybersecurity procedures and assist in policy enforcement.
- Mentor Level 1 staff and provide task planning and feedback.
- Evaluate new CVEs and assist in developing remediation strategies.
Level 3 Responsibilities
- Develop, maintain, and improve OT cybersecurity standards and frameworks.
- Translate cybersecurity standards (e.g., NERC CIP, NIST CSF, NIST 800-53) into procedures and controls.
- Conduct threat landscape assessments and risk analysis.
- Evaluate the criticality of OT assets and develop remediation plans.
- Lead cybersecurity audits and responses to regulatory data requests.
- Facilitate cross-departmental collaboration and team training.
Education
All Levels:
- Required: High School Diploma or equivalent.
- Preferred: Bachelor’s Degree in Computer Science, Information Systems, or related IT discipline.
Licenses/Certifications
All Levels:
- Required: At least one Information Security professional certification (or ability to obtain within 1 year of hire). Examples:
- Cisco, (ISC)², GIAC, ISA, ISACA, CompTIA, EC-Council.
- Preferred: Three or more certifications such as: CISSP, CISM, CISA, CEH, GPEN, GCIA, GCIH, GICSP, OSCP, etc.