Cybersecurity Lead (IT/OT)
Job Title: “Senior” – based on years of experience
Location: New Delhi, India (Aerocity)
Reports to: Head of IT Leadership responsibility:
As part of ASE’s IT team located in New Delhi, India and various locations in
Europe, manage all aspects of DevOps for the company with a focus on
Cybersecurity. This includes IT cybersecurity within ASE’s Microsoft and Azure
environments, and Operational Technology (OT) related cybersecurity for ASE’s
Solar/BESS physical assets located in the UK, the Netherlands and Germany.
As part of a close-knit team, the individual in this position will also be
expected to cover other team members in various aspects of IT support, though
focus will be on Cybersecurity.
The position is located in ASE India’s New Delhi offices, Aerocity.
Job responsibilities:
A.
Cybersecurity
Lead and manage all cybersecurity requirements related to ASE’s IT and OT
environment.
In general terms, define ASE’s cybersecurity posture across IT and OT. Develop
and maintain an appropriate and consistent cybersecurity framework across the
company.
European (and individual European country) cybersecurity requirements are
continually changing. The incumbent will be required to work closely with the
Compliance Manager to translate EU and Country regulations into cybersecurity
actions.
Specific cybersecurity requirements include:
▪
Daily security and threat monitoring and investigation
▪
Vulnerability management
▪
IT environment: Firewalls, Networks, Bastion, overall security structure
▪
Azure environment cybersecurity management (Bastion and other)
▪
M365 security (policies etc)
▪
Change Advisory Board management
▪
Training, Test Phishing, Security newsletters, cyber insurance standards
compliance
▪
Mail flow management and Email security policies – Exchange, Mimecast
▪
Internet access management / web filtering
▪
Conditional Access management
▪
Certificate life cycle
▪
Patch management
▪
Data Governance & Cybersecurity, ensuring compliance with:
a.
ASE common IT policies
b.
Vendor security guidelines
c.
Ensure secure credentials, API keys, and server access.
▪
Incident management, resolution, reporting (internal and external, external in
conjunction with Compliance), development and implementation of mitigation
actions and training
▪
Business Continuity Planning, Disaster Recovery Planning, Incident Response
Planning
▪
OT environment
a.
Open VPN, routers, SIM/Landline requirements
b.
Networking architecture and administration
c.
Firewall management
d.
VPN management
e.
Access management
f.
Overall Resilience
g.
Database management
h.
Virtualisation (VPN)
i.
Server management
j.
Plant Architecture & Data Flow Management (cybersecurity around end-to-end
SCADA-related architecture: Sensors, Inverters/WMS, Data loggers, PLC/RTU,
SCADA, On-prem/cloud servers.)
k.
Communication Network Reliability, implement redundancy strategies.
l.
NIS2 compliance (ISO 27001, training, SOC, Reporting)
m.
SOC: Rule setting, maintenance, monitoring
n.
Remain up to date on European and UK cybersecurity requirements, coordinating
closely with ASE’s Compliance Manager. Adapt ASE’s cybersecurity posture as
necessary.
▪
Monthly/Quarterly reporting
B.
IT/OT management (support, secondary)
M365 environment management
1)
License and user management, Guest account management
2)
On/offboarding (administrative + GDPR)
3)
User monitoring (security)
4)
Data storage (SharePoint usage, external access management)
5)
Data governance (GDPR, ISO and NIS2-related, Categorisation, Loss prevention)
6)
Data backup management: monitoring and monthly testing
Azure environment management
1)
Cloud administration including access management
2)
Server/VM management
3)
VPN management
This role will work closely with Desktop Support in the UK and provide cover
during vacation and sick leave absences.
This is not an exhaustive list of responsibilities for this role.
Minimum Requirements:
•
Degree in a relevant IT field.
•
Minimum 10 years of experience in IT functions with minimum 7 years managing
cybersecurity.
•
Experience in:
➢
Management of Microsoft 365 and Azure environments in a company of 75+
employees
➢
Cybersecurity experience
o
Cybersecurity in a Microsoft 365 and Azure environment
o
Renewable Industry, particularly Solar/BESS
o
Operational Technology and SCADA-related security measures
o
AI technology usage around cybersecurity
•
Knowledge of international standards, particular ISO 27001
Experience implementing standards, infrastructure and controls for ISO 27001
certification and maintenance.
➢
Information Standards Management System development and maintenance
➢
Networking
➢
Renewable Industry, particularly Solar/BESS
➢
Operational Technology and SCADA-related experience
o
Inverters, Power Plant Controllers (PPC) and Data logger (e.g., Bluelogger)
structures, architecture and interdependencies
o
SCADA-related data flows and Database management
o
Kepware and other similar
o
BESS EMS/BMS
•
Willingness to operate out of hours and provide cybersecurity incident
management coverage where required
•
International experience, particularly Europe
•
IT in an operating renewable industry (OT/SCADA)
•
SharePoint and NetSuite knowledge
•
Ability to work independently and in a team environment.
•
Excellent communication and interpersonal skills.
•
Collaborative spirit
•
Ability to work with individuals in Europe and manage cultural differences
•
Fluency in spoken and written English
Nice to have:
•
Knowledge of European cybersecurity regimes such as NIS2 (EU) and CSRB (UK)
•
German or Dutch language skills a plus. give me a brief of this role
Apply through whichever channel suits you best.