Job Description
Title: Security Consultant (Operational Technology Security)
Location: Mumbai/ Bangalore/ Gurgaon
Experience: 4-8 Years
Work format: Work from office
Job Description summary:
Responsible for translating clients cybersecurity requirements and customizing and implementing security solutions into specific systems, applications and product designs. Identifies and develops the security solutions for clients using company products, outsourced technology solutions and technical tools. Consults with clients regarding secure product configuration, deployment, and security patches to minimize security vulnerabilities. Provides comprehensive scanning, penetration testing, vulnerability assessments, monitoring services and source code analysis and delivers detailed results to clients. Guides and supports clients in the development and implementation of product security controls. Often project-based and involves working at customer sites. Performance is typically measured by the capture of the consulting engagement, utilization (i.e., billable hours) and/or delivery of agreed solutions within budgeted hours.
The role of Security Consultant is to assess software, computer systems, and networks for vulnerabilities, then design and implement the best security solutions for an organizations needs. This role works on strategic projects that ensure the efficient and effective reaction to security breaches to mitigate immediate and potential threats.
Key Roles and Responsibilities:
- Work on strategic projects that ensure the efficient and effective reaction to security breaches to mitigate immediate and potential threats.
- Use mitigation, preparedness, response and recovery approaches to minimise business disruptions & commercial consequences.
- Offer detailed technical support investigation and analysis response activities and evaluate the effectiveness of and improvements to existing practices.
- Conduct regular threat and vulnerability assessments and determine deviations from acceptable configurations or policies.
- Participate in the assessment of the level of risk and support the development of appropriate mitigation countermeasures in operational and non-operational situations.
- Analyse evidence to support network vulnerability mitigation.
- Support peers in the management and implementation of the information security management system.
- Participate in the implementation of policies, processes and guidelines to ensure the standardisation of security management throughout the organisation.
- Apply tactics, techniques, and procedures to a full range of tools and processes related to administrative, criminal, and counterintelligence gathering (e.g., in-depth case analyses, continuous monitoring, malware analysis, clear documentation).
- Collaborates with stakeholders to guide and functional and security requirements.
- Proactively search through our critical infrastructure, systems and networks to detect and isolate advanced threats that may cause harm to our organisation.
- Use both manual approaches and automated tools to identify, analyse, and report events and support the development of countermeasures to proactively protect against these threats in the future.
Knowledge, Skills and Attributes:
- Strong understanding of information technology and information security
- Solid understanding of security risks and preventative controls
- Excellent understanding of security operational processes and controls
- Service consulting aptitude, focusing on the business, service and sales aspects
- Excellent verbal and written communication skills
- Demonstrate impeccable attention to detail are able to translate internal customer requirements into solutions
- Maintain up-to-date knowledge of security threats, countermeasures, security tools, and network technologies
- High level of drive and ability to work under pressure
- Ability to build and maintain cross-functional relationships with a variety of stakeholders
- Academic Qualifications and Certifications:
- An IT related or Engineering tertiary qualification will be highly regarded
- Industry relevant certifications such as CISSP, CISM, CEH, GSEC or CompTIA Security+
Required Experience:
- Demonstrable experience in the Information Technology Security Industry or relevant experience in similar role within a related environment
- Experience with security architecture design principles
- Experience with industry compliance and standards such as ISO 27000, PCI:DSS, NIST, HIPAA or others
- Specialist experience with security tools and techniques to cover SANS Top 25, OWASP or others
- Experience working in a multi-team environment across multiple geographies
Key Accountabilities
As a Security Consultant for OT Security domain in the APAC Security Consulting practice of NTT Ltd.s Security business, this role will execute and lead client engagements focusing on the delivering and management of Cybersecurity consulting practice work for India and wider APAC region. This position would be having following key responsibilities while reporting to the Regional Leader for India Security Consulting services:
- Performing OT maturity gap assessments, determining risks, and recommending mitigation actions
- Developing Industrial / Operational Security Architecture & Design services and programs (preferably for organizations managing or operating Critical Information Infrastructure)
- Implementation of IACS system security requirements as per IEC 62443/ISA 99, ISO 27001, NIST SP 800-82
- OT Security GRC Advisory work
- Design, configure, assess, deploy, and integrate OT Security solutions (such as but not limited to Nozomi, Claroty, CyberX/Azure Defender IoT)
- Working knowledge of Zero Trust Security Model and Architecture in the OT/IACS parlance
- Carry out pre-sales engagement for projects relating to OT
- Staying current with NIST OT/IIoT/IoT focused publications
- Working knowledge of security risk and control frameworks such as NIST CSF
- Support security consulting pre-sales work (e.g. writing SoWs, proposals etc.)
- Be flexible to acquire new skills and show willingness in learning/re-learning and un-learning things as needed for the success of this role and the overall security consulting practice
- Demonstrate strong skills in analysing customer business processes and technical environments
- Provide consultancy advices to client in closing technology control gaps / vulnerabilities in a practical way
- Demonstrate commitment to delivering projects within time and in budget and to a high level of customer satisfaction
- Be able to liaise and work closely with clients across multiple security consulting projects and handle stakeholder expectations
- Actively participate in knowledge sharing with all team members
- Keep all records complete and up-to-date, ensuring team leader/members are kept informed on progress
- Aid the security consulting practice in developing/maintaining its processes, methodologies and procedures
Experience Skills and Qualifications
As the Security Consultant your skills and qualifications will include:
- Possess at least 7 years of working experience related to information security consulting with a minimum of 5 years of hands-on experiences on OT Security practice areas.
- Required degree level education, or significant experience and track record with tertiary qualifications on relevant domains, including computer science, computer engineering and information security
- Working knowledge on IEC 62443/ISA 99, ISO 27001, NIST SP 800-82
- OT Security Domain Certs and/or OT Security Product Certifications
- Information security and audit certifications such as ISO 27001 LI, ISO 27001 LA, CISSP and/or IEC62443 Foundation
- Experienced in supporting consulting pre-sales work (e.g. writing SoWs, proposals etc.)
- Demonstrate excellent skills in structured problem solving techniques, creativity and intelligence in the development of solutions to customer problems
- Be self-motivated and self-disciplined with a demonstrable and successful track record in delivering consultancy projects to all sizes of organizations
- Must have good presentation skills with the ability to present to audiences of both business and IT stakeholders
- Must have good written communication and report writing skills
- Must be a good team player
- Demonstrates commitment to delivering projects within time and in budget and to a high level of client satisfaction
Job Classification
Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security
Role Category: IT & Information Security - Other
Role: IT & Information Security - Other
Employement Type: Full time
Contact Details:
Company: NTT DATA
Location(s): Noida, Gurugram
Keyskills:
DCS
PLC
OT Security
TFS
Safety PLC & RTU
Modbus