About the Role
Our client is looking for an OT/IoT Security Lead to build and lead their Operational Technology and IoT security capability from the ground up. This is a foundational role within a well-established Security Operations function, offering genuine ownership over strategy, tooling, governance and incident response for OT/IoT environments.
You'll work cross-functionally with Threat Intelligence, Incident Response, Vulnerability Management, GRC and Security Architecture, as well as engineering and site teams, to embed proportionate, pragmatic security controls across operational environments — while also playing a key role in incident response when OT/IoT-related incidents occur.
Key Responsibilities
- Build and develop the organisation's OT/IoT security capability from the ground up
- Define the OT/IoT security strategy, roadmap, operating model and delivery priorities
- Create and maintain an accurate inventory of OT/IoT assets, systems, software and dependencies
- Identify security risks, control gaps and vulnerabilities across operational environments
- Evaluate, recommend and support procurement of OT/IoT security technologies and services
- Lead implementation, integration and ongoing management of selected security solutions
- Develop OT/IoT security policies, standards, procedures and governance processes
- Establish security monitoring use cases, alerting requirements and detection coverage
- Tune security controls to improve detection while reducing false positives
- Define secure configuration, network segmentation, access control and remote-access requirements
- Lead OT/IoT vulnerability identification, assessment, prioritisation and remediation
- Support incident preparation, investigation, containment, recovery and lessons-learned activities
- Translate threat intelligence into actionable detection, prevention and mitigation requirements
- Partner with IT, engineering, site leads, asset owners, suppliers and business stakeholders
- Assess new projects, technologies and architectural changes for OT/IoT security risk
- Define metrics and provide regular reporting on OT/IoT security risk, performance and maturity
- Support audits, regulatory obligations and continuous improvement initiatives
About You
- Relevant security certifications in OT/IoT or closely related areas of Security Operations
- Deep understanding of OT/IoT technologies, architectures, protocols, threats and controls
- Proven experience building a security capability, service or function from the ground up
- Strong knowledge of IEC 62443, NIST CSF and NIST SP 800-82
- Practical experience applying the Purdue model within manufacturing/engineering organisations
- Working knowledge of project management principles
- Willingness to travel internationally as required
- Comfortable operating within incident response processes, including on-call/escalation involvement during security incidents
Why Apply
This is a unique opportunity to shape an entire security function from day one, with real influence over tooling, strategy and how OT/IoT risk is managed across the business — working alongside experienced Security Operations, GRC and Architecture teams.