OT Cyber and Compliance Manager

Support Services / Destek HizmetlerHybride à distance, UK, United Kingdom


Description

General – Internal

Job Title  OT Cyber & Compliance Manager

 

Reporting to

Director, OT, Data & Analytics

Location

UK Remote

Hours

Full Time

 

The position

As the global renewable energy sector scales at pace, the systems connecting our wind, solar, and battery assets — SCADA platforms, remote monitoring environments, and OT networks — are increasingly targeted by sophisticated threat actors. The emergence of AI-enabled attack toolkits has lowered the barrier to large-scale OT intrusions, while a rapidly tightening regulatory landscape across the UK, Europe, the US, and Australia is placing new and binding compliance obligations on operators of energy infrastructure.

To address this challenge, we are creating a new role of OT Cyber & Compliance Manager within the OT & SCADA function. This is a high-impact role combining governance, technical delivery, and commercial development. The post-holder will be the owner of OT cyber security across our managed portfolio — building the compliance programmes, the technical controls, and ultimately the client-facing service capability that positions the business as a trusted partner on cyber resilience in renewables.

This role will ultimately ensure that:

•  Our OT infrastructure and managed sites meet all applicable regulatory requirements across every jurisdiction in which we operate

•  Clients receive confident, accurate responses to cyber and compliance questions during procurement and throughout contract delivery

•  The Jupiter OT tenant and site-level OT networks are architected, hardened, and continuously maintained to industry-leading standards

•  A new, revenue-generating OT cyber compliance service offering is built, launched, and led from within the OT team

•  Patching, vulnerability management, and penetration testing happen systematically, with clear ownership and evidence trails

The post-holder will work in close partnership with the Head of OT Architecture, regional OT managers, and the Group Cyber team. The role requires occasional site visits to wind, solar, and battery assets across the portfolio.

Key Accountabilities

OT Cyber Governance & Compliance

•  Design, build, and own a global OT cyber compliance programme covering NIS2 (Europe), the UK Cyber Resilience Act, NERC CIP Low-Impact (US), and the Security of Critical Infrastructure Act (SOCI, Australia)

•  Ensure local compliance managers and regional teams have the systems, policies, procedures, and evidence repositories in place to meet their respective local regulatory requirements

•  Maintain the OT risk register, track remediation actions, and provide OT input into the enterprise cyber risk framework

•  Own audit readiness across all regulatory programmes; lead self-certification processes and support external audits with structured, credible evidence

•  Liaise with the Group Cyber function to ensure consistency between IT and OT compliance approaches

Client Engagement & Business Development

•  Lead the OT cyber response to client RfP processes and vendor risk assessments, providing technically authoritative and commercially compelling answers to cyber and compliance questionnaires

•  Build the internal business case for, and lead early client engagements in, a new OT cyber compliance services offering for assets owners

•  Work with Business Development leads to define contractual language around OT cyber obligations, clarifying what we do and do not offer in client agreements

•  Shape and articulate our OT cyber services proposition to clients, positioning the organisation as a market leader in OT security for renewables

Technical OT Security

•  Configure, maintain, and continuously evolve the Jupiter OT tenant in Azure, including security architecture, firewall rules, VPN/IPSEC configurations, and vendor remote access controls

•  Establish and own systematic programmes for OT patching, vulnerability scanning, and penetration testing across managed assets and centralised infrastructure

•  Lead OT incident response and recovery activities in relation to cyber events, working closely with Group Cyber colleagues

•  Develop and implement OT-specific cyber security standards, hardening baselines, and monitoring controls aligned to recognised frameworks (NIST CSF, IEC 62443, ISA/IEC)

•  Maintain an OT asset inventory and manage vulnerability risk across the portfolio

OT Network & Architecture

•  Conduct site visits to wind, solar, and battery power plants to assess the current state of OT network equipment and infrastructure

•  Lead OT network deployment activities at sites, ensuring security-by-design is embedded from the outset

•  Support the Head of OT Architecture on OT network design standards, patterns, and architecture roadmaps, acting as the security authority on architecture decisions

•  Work with regional teams to standardise OT network configurations globally, reducing complexity and improving cyber posture across the fleet

 

Knowledge & Skills    

Experience & Qualifications

Knowledge

•  Extensive knowledge of OT/ICS cyber security principles, frameworks, and standards including NIST CSF, IEC 62443, NERC CIP, and ISO 27001

•  Deep understanding of OT network architecture, secure design patterns, and common vulnerabilities in SCADA, EMS, and DCS environments

•  Thorough knowledge of cyber regulatory regimes applicable to energy infrastructure: NIS2, UK Cyber Resilience Act, NERC CIP, and SOCI

•  Practical knowledge of Azure OT/IT security services including Microsoft Defender for IoT, Azure Firewall, and VPN/IPSEC configuration

•  Familiarity with industrial communication protocols: OPC UA/DA, Modbus, MQTT, DNP3, and IEC 61850

Skills

•  Able to translate complex cyber and compliance requirements into practical policies, controls, and audit-ready evidence

•  Strong commercial acumen; able to engage clients credibly on cyber risk and build proposals that grow revenue

•  Excellent written communication — able to produce clear, professional responses to RfP questionnaires, audit submissions, and board-level reports

•  Collaborative and influential; able to work across OT, IT, Legal, and Business Development functions without direct authority

•  Pragmatic and delivery-focused, with an ability to balance rigour and pace in a fast-moving operational environment

•  Comfortable working on-site at wind, solar, and battery assets, including in remote locations

Experience

•  7+ years' experience in OT/ICS cyber security roles, with demonstrable delivery across both governance and technical domains

•  Proven experience designing or managing compliance programmes under at least one of: NERC CIP, SOCI, NIS2, or equivalent CNI cyber regulation

•  Hands-on experience configuring and managing OT network infrastructure — firewalls, VPNs, remote access — in an operational energy or utilities environment

•  Experience conducting or commissioning vulnerability assessments and penetration tests on OT/SCADA systems and managing remediation

•  Track record of engaging clients or senior stakeholders on cyber topics — through RfP responses, audit support, or advisory engagements

•  Experience working in, or closely alongside, renewable energy, utilities, or other critical infrastructure operations

•  Experience designing or delivering OT cyber services to external clients, including scoping, commercial framing, and client management

•  Familiarity with Microsoft Azure OT security tooling (Defender for IoT, Sentinel) and cloud-connected OT architecture

•  Experience with OT site network assessments and deployment across wind, solar, or battery assets

•  Knowledge of SCADA platforms common in renewables (e.g. Siemens WinCC, GE iFIX, OSIsoft PI/AF, Ignition)

Qualifications

•  GICSP (Global Industrial Cyber Security Professional) or equivalent OT security certification

•  CISSP, CISM, or equivalent information security qualification

•  Azure security certifications (AZ-500 or SC-200)

•  Degree in Computer Science, Electrical/Electronic Engineering, Cyber Security, or related discipline

 

General - Internal

Confidential | OT & SCADA | RES Group O&M Services