Security Engineer
Cyber Security Consultant for OT (Consulting)
Zagreb
Откликнуться на сайте работодателяОписание вакансии
At Marlink, we empower our customers worldwide by helping them digitalize and optimize their remote operations through advanced hybrid network solutions and cutting-edge digital technologies. Our teams operate globally, harnessing innovation, expertise, and applied technology to connect systems and people, driving success in today’s digital-first world. With 1,500 employees in over 30 countries, and customers in the maritime, energy, and government sectors, we push boundaries to deliver excellence.
As an Cyber Security Consultant for OT, you will provide technical cybersecurity expertise across client engagements, helping organizations assess and strengthen the security of their industrial environments. You will focus on security architecture, risk analysis, and regulatory compliance, while acting as a key bridge between OT/ICS environments and our GRC and RED service lines. You will translate complex OT security challenges into practical, risk-based solutions for our clients.
What you’ll do:
- Analyze and assess ICS/OT architectures at client sites, using the Purdue model as a reference for segmentation and communication flows.
- Develop and review OT architecture recommendations covering segmentation, trust zones, DMZs, conduits, and IT/OT separation.
- Assess OT environments, including control system architecture, process dependencies, and operational constraints.
- Advise clients on practical security controls, including remote and privileged access, vendor access, monitoring, hardening, and exposure reduction.
- Conduct site visits as needed, along with workshops, interviews, and evidence collection to validate how OT environments operate in practice.
- Contribute to OT risk assessments by identifying threats, attack paths, and operational impact, linking technical findings to process criticality and business risk.
- Assess client environments against IEC 62443, NIST, ISO 27001, NIS2, and sector-specific requirements, supporting GRC teams in translating requirements into practical controls.
- Support OT incident simulations, including tabletop and technical exercises.
- Support OT penetration testing and red teaming by defining safe testing scope, providing architecture context, and assessing operational risk.
- Work with engineering, operations, IT, and security teams to align security measures with safety, operability, and maintenance requirements.
- Prepare clear reports, architecture inputs, findings, and recommendations for technical teams and management.
What you bring:
- Solid experience in OT/ICS environments (industrial operations, automation, control systems, energy, utilities, manufacturing, marine systems, or other critical infrastructure).
- Good understanding of industrial system architecture and the Purdue model, including field-to-control-layer communication and typical security weaknesses at each layer.
- Understanding of the ICS lifecycle, safety and availability priorities, operational constraints, and change management practices.
- Familiarity with industrial protocols, system interfaces, and dependencies between operational systems.
- Working knowledge of networking fundamentals (routing, switching, VLANs, firewalls, DNS, DHCP, remote access).
- Understanding of regulatory frameworks relevant to OT (IEC 62443, NIS2, NIST, ISO 27001) and interest in working at the intersection of technical and compliance topics.
- Experience producing technical documentation, architecture diagrams, inventories, and assessment findings.
- A degree in electrical engineering, automation, computer science, or a related field is an advantage.
- Relevant OT, networking, or cybersecurity certifications (e.g. GICSP, IEC 62443 certifications) are an advantage.
- Fluent in English, written and spoken.
Your profile:
- Consulting mindset, with the ability to independently lead client conversations and engagements.
- Ability to build trust with operational, engineering, and management stakeholders.
- Willingness to travel domestically and internationally for client engagements.
- Pragmatic approach, with awareness of safety, uptime, and industrial operational realities.
- Clear communication of technical topics to both technical and management audiences.
- Strong facilitation skills for workshops, interviews, and discovery sessions.
- Analytical thinking and ability to structure incomplete information into clear findings and recommendations.
- Collaborative approach across multidisciplinary teams (GRC, RED, engineering, etc.).
- Strong ownership, reliability, and follow-through.
- Motivation to deepen expertise in cybersecurity governance, incident response, and OT security architecture, and grow into a broader OT cyber consulting role.
What’s in it for you:
- Growth in an open-minded culture and international work environment, with a high level of autonomy.
- Continuous development and advancement through industry-relevant certifications and internal/external training/workshops.
- Challenging local and global projects that include latest technical solutions.
- Learning and sharing experiences with well-known and respected experts in the field of information/cybersecurity.
- Hybrid work model with flexible working hours.
- Additional and supplementary health insurance.
- Monthly transportation and hot meal allowances.
- Multisport membership.
- Social events and team‑building activities.
Это сохранённая копия объявления, опубликованного в другом месте. Вакансии снимают без предупреждения — перед откликом проверьте сайт работодателя. mentors.coach не является нанимающей стороной.