
Opening with EY_OT Security
Full Job Description
EY- Cyber Security (OT Security) - Technology Consulting – Senior
About Global Delivery Services: Global Delivery Services (GDS) represents EY's worldwide network of service delivery centers, integral to EY’s strategy for supporting its growth agenda. GDS has expanded significantly since 2002, now comprising over 80,000 professionals across ten international locations. These centers deliver client services in Consulting, Assurance, Tax, Strategy & Transactions, and Knowledge, enabling account teams globally to provide high-quality, value-added support. Enablement Services within GDS provides cost-effective, skilled, and innovative solutions across various functions including Markets, Finance and Accounting, Risk Management, and IT Service Delivery. Innovation specialists within GDS collaborate with client service and enablement teams, as well as Service Lines, Core Business Services, and Sectors, to facilitate rapid prototyping and innovative thinking through expertise in analytics, digital, and infrastructure technologies.
The Opportunity: The GDS Cyber Architecture Operational Technology & Engineering (CAOE) team assists clients in addressing complex security challenges within their Operational Technology (OT) environments. We develop effective solutions leveraging people, processes, and technology to enhance security, improve risk decisions, and reduce costs. The CAOE team is seeking motivated individuals to play a direct role in delivering OT security engagements, developing proposals, and creating innovative OT security solutions. You will be instrumental in supporting our clients to secure their IT/OT environments through advisory and implementation services.
Your Key Responsibilities:
- Monitor OT networks utilizing specialized OT Security Operations Center (SOC) and network monitoring tools.
- Analyze alerts generated by OT security monitoring solutions (e.g., Nozomi, Claroty, Tenable.ot, Defender for IoT).
- Identify suspicious activities, anomalies, and Indicators of Compromise (IoCs) impacting Industrial Control System (ICS) environments.
- Perform Level 2 alert triage and in-depth investigation for OT security incidents.
- Support OT cybersecurity incident response activities.
- Demonstrate a strong understanding of security-related operational processes within OT-ICS environments.
- Exhibit knowledge of technologies (assets, communication protocols, technical architectures) common in OT-ICS systems and networks.
- Possess a solid understanding of cyber/information security concepts, risk assessment, and control frameworks.
- Understand aspects of functional safety, specifically Safety Instrumented Systems (SIS).
- Proficiently apply knowledge of TCP/IP, OSI layer concepts, protocols, networking, and security principles.
- Familiarity with technical security solutions deployed within OT-ICS systems and networks.
- Knowledge of OS (Windows/Linux) security and Database security.
- Prior experience working with delivery leads and architects to identify and manage risks is advantageous.
Skills and Attributes for Success:
- Completed higher technical education in industrial automation, computer science, electronics, or a related field.
- Possession of certificates or relevant education in industrial automation/engineering is beneficial.
- Knowledge of OT network monitoring solutions such as Nozomi, Claroty, Armis, DarkTrace, Azure Defender.
- Familiarity with tools like Nessus, BackTrack, NMAP, BurpSuite is a plus.
- In-depth knowledge of OT-ICS Security standards, including ISA/IEC 62443, NIST 800-82, NERC-CIP.
- Understanding of IT/OT/IoT communication protocols such as TCP/IP, UDP, DNP3, Modbus, IEC 61850, OPC, OPC UA, PROFINET, BLE, Zigbee.
- Knowledge of standards like ISO 27001/2, ISO 22301, ISO 27018, NIST Cybersecurity standards, HITRUST is a plus.
Company
EY
EY, a global leader in professional services, operates a worldwide network of service delivery centers known as Global Delivery Services (GDS). Since its inception in 2002 with a team of 200, GDS has ...