- Conduct cybersecurity risk assessments for IT and OT environments in accordance with industry standards and best practices
- Identify, analyze, and evaluate cybersecurity risks affecting business operations, industrial control systems, and critical infrastructure assets
- Assess the effectiveness of existing cybersecurity controls and recommend remediation measures
- Conduct gap assessments against relevant cybersecurity standards and regulations, such as NIST SP 800-82, IEC 62443, and ISO 27001
- Develop risk registers, risk treatment plans, and mitigation recommendations
- Collaborate with operational, engineering, IT, and cybersecurity teams to gather information and understand system architectures
Experience Needed:
- 5+ years of experience in cybersecurity risk assessment, cyber risk management, or security consulting
- Demonstrated experience performing cybersecurity risk assessments and developing mitigation strategies
- Proven experience conducting cyber risk assessments in enterprise IT environments.
- Strong understanding of cybersecurity risk management methodologies and control frameworks.
- Ability to analyze technical and operational risks and translate findings into business impacts
