About this role
<p><strong>Manager / Assistant Manager – OT Cyber Security</strong></p> <p> </p> <p><strong>Overview</strong></p> <p> </p> <p>EY South Africa is looking to strengthen its Operational Technology (OT) Cyber Security capability with experienced OT cybersecurity professionals at Assistant Manager and Manager level.</p> <p>We are specifically seeking candidates with hands-on OT, ICS and critical infrastructure experience who are comfortable working in operational environments such as mining, utilities, power generation, manufacturing and oil & gas.</p> <p>This role will require regular travel and, in some cases, extended periods at client sites across South Africa and the broader Africa region.</p> <p> </p> <p><strong>What We Are Looking For</strong></p> <p> </p> <p><strong>Assistant Manager</strong></p> <ul> <li>5–8 years relevant experience.</li> </ul> <p> </p> <p><strong>Manager</strong></p> <ul> <li>8–12 years relevant experience.</li> </ul> <p>Candidates must have practical experience in one or more of the following sectors:</p> <ul> <li>Mining</li> </ul> <ul type="disc"> <li>Utilities</li> <li>Power Generation</li> <li>Oil & Gas</li> <li>Manufacturing</li> <li>Critical Infrastructure</li> </ul> <p> </p> <p><strong>Required Technical Experience</strong></p> <ul> <li>OT Cyber Security Assessments</li> </ul> <ul type="disc"> <li>ICS Security</li> <li>SCADA Security</li> <li>OT Risk Assessments</li> <li>Vulnerability Assessments</li> <li>Security Architecture Reviews</li> <li>Network Segmentation</li> <li>Asset Discovery</li> <li>OT Governance and Compliance</li> <li>Incident Response within OT environments</li> </ul> <p> </p> <p><strong>Preferred Framework Experience</strong></p> <ul> <li>IEC 62443</li> </ul> <ul type="disc"> <li>NIST CSF</li> <li>NIST 800-82</li> <li>C2M2</li> <li>ISA Standards</li> <li>ISO 27001</li> </ul> <p> </p> <p><strong>Preferred Technologies</strong></p> <ul type="disc"> <li>Nozomi</li> <li>Claroty</li> <li>Microsoft Defender for IoT</li> <li>Tenable.ot</li> <li>Splunk</li> <li>Microsoft Sentinel</li> </ul> <p> </p> <p><strong>Preferred Certifications</strong></p> <p>One or more of the following:</p> <ul> <li>ISA/IEC 62443 Specialist Certifications</li> </ul> <ul type="disc"> <li>GICSP</li> <li>CISSP</li> <li>CISM</li> <li>CCNA</li> <li>Security+</li> <li>Nozomi Certifications</li> <li>Claroty Certifications</li> </ul> <p> </p> <p><strong>Additional Requirements</strong></p> <ul> <li>Must be willing to travel extensively.</li> </ul> <ul type="disc"> <li>Must be comfortable spending extended periods at remote client locations.</li> <li>Strong report writing and client engagement skills.</li> <li>Ability to conduct workshops, interviews and site assessments.</li> </ul> <p> </p> <p><strong>Key Success Factors</strong></p> <ul type="disc"> <li>Deep OT and ICS knowledge.</li> <li>Ability to work effectively in operational environments.</li> <li>Strong understanding of IEC 62443 and OT security principles.</li> <li>Practical experience rather than purely governance-focused experience.</li> </ul> <p style="text-align:justify"> </p> <p style="text-align:justify"> </p>