OT Compliance Manager (m/f/d)
Imagine a future where you increase resilience towards cyber threats and help demonstrate that green energy is a stable and trusted energy source
Join us in this role where you’ll work closely with offshore windfarm engineering, OT experts, IT, corporate functions as well as locations and regions to develop and manage cyber security compliance activities in global offshore windfarm operations.
You’ll be part of Ørsted Generation, where you, together with your colleagues, will help ensure that our offshore wind operations comply with international and national cybersecurity regulations and standards. As wind energy continues to mature globally and becomes recognised as critical infrastructure in key markets, owners and operators must meet increasing regulatory and cybersecurity requirements, including standards such as ISO 27001 and IEC 62443.
In this role, you’ll act as a technically oriented compliance expert with strong project management skills, supporting the continuous compliance of OT operations in critical infrastructure environments. You’ll contribute to the application and improvement of information security management processes, lead compliance and audit activities on a global level, and help strengthen Ørsted’s overall security and compliance posture. You’ll also collaborate closely with and support a community of Regional Cyber Security Officers across Ørsted’s locations worldwide.
As a team, we collaborate across borders, share knowledge openly, and support each other in protecting secure, reliable, and sustainable energy generation.
You’ll play an important role in:
- managing the compliance baseline documentation system and related artifacts
- developing methodologies and tooling concepts to improve automate the compliance management (cyber GRC concepts and tooling)
- establishing cybersecurity frameworks, policies, and procedures tailored for offshore wind farm environments to address risks related to industrial control systems (ICS) and SCADA systems etc.
- performing control assessments and risk assessments from the compliance perspective
- maintaining and facilitating internal and certification audits and governmental inspection activities
- managing the community of Regional Cyber Security Officers to coordinate and support their local compliance activities
- establish operational compliance reporting (e.g. KPIs, KRIs, assessments, maturity assessments, compliance risk reporting)
- consulting the operations teams regarding compliance.
To succeed in the role, you:
- have experience with governance, risk and compliance approaches
- very good knowledge and understanding about industrial standards like ISO27001, -2, -5 and IEC62443
- are capable to fully understand and get familiar with national and/or energy market specific standards and regulations like NIS2, UK NIS CAF, German IT Sicherheitskatalog and KRITIS regulations and US NERC CIP and understanding of how it applies to OT environments and how different authorities audit and inspect across jurisdictions.
- have experience with security and compliance in the OT area (e.g. ICS & SCADA systems and components, i.e. PLCs, HMIs, RTUs, and auxiliary system like HVAC, LV Systems, UPS etc.)
- have project management skills
- have good communication skills and are capable of stakeholder engagement in a matrix organisation
- very good analytical and methodological skills.
Employment in this role may be subject to the successful candidate being able to obtain the required security clearance.
Maybe you’ve read the above and can see you have some transferable skills, even though they don’t quite match all the points. If you think you can bring something to the team, we still encourage you to apply.
Shape the future with us
Send your application to us as soon as possible. We’ll be conducting interviews on a continuous basis and reserve the right to take down the advert when we’ve found the right candidate.
As an applicant or employee, you may request reasonable work and position accommodation or adjustments via accommodation@orsted.com.
Please note that for your application to be taken into consideration, you must submit your application via our online career pages and answer the screening questions relevant for your country. We don't take applications or inquiries from external recruiters or agencies into account for this position.
Gentofte, DK Barrow-in-Furness, GB Hamburg, DE Skærbæk, DK Grimsby, GB Warsaw, PL