The Opportunity
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of yourself.
As part of our Cybersecurity team, you will support leading organizations across critical infrastructure and industrial sectors in strengthening their Operational Technology (OT) security capabilities. You will work on challenging projects involving industrial control systems, critical infrastructure protection, cyber resilience, regulatory compliance and OT cybersecurity transformation initiatives.
This role offers exposure to international projects and the opportunity to collaborate with multidisciplinary teams across sectors such as Energy, Utilities, Manufacturing, Oil & Gas, Chemicals, Mining and Transportation.
Your Key Responsibilities
As an OT Security Consultant, you will be responsible for helping clients identify, assess and mitigate cybersecurity risks across industrial environments, including:
- Conducting OT cybersecurity maturity assessments, risk assessments and gap analyses against leading industry frameworks and standards.
- Assessing Industrial Control Systems (ICS), SCADA, DCS, PLC and IIoT environments.
- Supporting the definition of OT cybersecurity strategies, target operating models and transformation roadmaps.
- Reviewing industrial network architectures, segmentation models and secure remote access solutions.
- Supporting compliance initiatives related to NIS2, IEC 62443 and other relevant cybersecurity regulations and standards.
- Performing OT security assessments, vulnerability assessments and architecture reviews.
- Supporting the deployment and optimization of OT security monitoring, asset visibility and threat detection solutions.
- Collaborating with engineering, operations, maintenance and IT teams to implement cybersecurity improvements while minimizing operational impact.
- Contributing to cyber resilience initiatives, incident response planning and recovery capabilities for industrial environments.
- Preparing client deliverables, executive reports, technical documentation and presentations.
- Staying informed about emerging threats, attack techniques and cybersecurity trends affecting industrial environments and critical infrastructure.
Skills and Attributes for Success
To qualify for the role, you should have:
- 3 to 6 years of experience in Cybersecurity, Operational Technology (OT), Industrial Automation or related fields.
- Previous experience working within industrial environments such as: Energy & Utilities; Oil & Gas; Manufacturing; Water Utilities; Chemicals; Mining; Transportation.
- Strong understanding of industrial cybersecurity concepts, including: Purdue Enterprise Reference Architecture (PERA / Purdue Model); Industrial Control Systems (ICS); Distributed Control Systems (DCS); SCADA environments; Safety Instrumented Systems (SIS).
- Knowledge of one or more cybersecurity frameworks and standards: IEC 62443; NIST Cybersecurity Framework (CSF); NIST SP 800-82; C2M2; MITRE ATT&CK for ICS; CIS Controls (OT Context).
- Understanding of industrial networking technologies and protocols, including: Modbus TCP/IP; Modbus RTU; DNP3; OPC Classic; OPC-UA.
- Experience with OT security technologies, such as: Nozomi Networks; Claroty; Dragos; Armis; Industrial Defender; TXOne Networks.
- Strong analytical, communication and stakeholder management skills.
- Ability to work in multicultural environments and international projects.
- Fluency in English, both written and spoken.
Ideally, You'll Also Have:
- Degree in Cybersecurity, Computer Science, Electrical Engineering, Industrial Automation, Telecommunications or a related field.
- Professional certifications such as: GICSP; GRID; ISA/IEC 62443 Cybersecurity Expert; CISSP; CISM; Security+; CCNA / CCNP.
- Experience supporting Industry or digital transformation initiatives.
- Knowledge of cloud-connected industrial environments.
- Understanding of Zero Trust principles applied to Operational Technology environments.
- Familiarity with industrial safety and functional safety standards such as IEC 61511 and IEC 61508.
What We Look For
We are seeking professionals who are passionate about cybersecurity and critical infrastructure protection, with a collaborative mindset and a strong desire to solve complex challenges. The ideal candidate combines technical expertise with business understanding and is motivated to help organizations build secure and resilient industrial environments.
What working at EY offers
EY offers a competitive remuneration package commensurate with your work experience. Plus, we offer:
Support, coaching and feedback from some of the most engaging colleagues around;
Opportunities to develop new skills and progress your career;
The freedom and flexibility to handle your role in a way that’s right for you.