Deskripsi Pekerjaan
At Henkel, we come from a broad range of backgrounds, perspectives, and life experiences. We believe the uniqueness of all our employees is a key driver of our innovation and success. As a global leader in adhesives, sealants, and functional coatings, we are dedicated to creating sustainable value for our customers and communities.
We are currently seeking a skilled and motivated OT Security Control Testing Analyst to join our dynamic Information Security team in Makati City, Metro Manila. In this critical role, you will be responsible for ensuring the resilience and security of our Operational Technology (OT) environments across the globe. This is a unique opportunity to safeguard critical industrial infrastructure while advancing your career in a multinational, innovation-driven company.
Key Responsibilities:
- Perform comprehensive security control assessments and vulnerability testing on OT networks, systems, and applications.
- Develop, maintain, and execute detailed test plans aligned with industry standards such as IEC 62443 and NIST CSF.
- Identify, document, and track security weaknesses, providing clear and actionable remediation guidance to global teams.
- Collaborate closely with IT, engineering, and operations teams to implement security improvements and best practices.
- Monitor the evolving threat landscape to proactively address risks to OT infrastructure.
- Support security incident response and forensic analysis activities for OT environments.
- Contribute to the continuous improvement of our OT security testing framework, tooling, and methodologies.
What You Bring:
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, or a related field.
- 3+ years of experience in information security, with a specific focus on OT/ICS security control testing or assessments.
- Deep understanding of industrial control systems, SCADA, DCS, and common OT protocols (e.g., Modbus, DNP3, OPC).
- Hands-on experience with vulnerability assessment tools (Nessus, Qualys) and penetration testing frameworks (Metasploit, Kali Linux).
- Sound knowledge of relevant security frameworks (NIST CSF, ISO 27001, IEC 62443).
- Excellent communication skills in English, with the ability to explain complex technical concepts to diverse stakeholders.
- Relevant professional certifications (CISSP, GICSP, CISA, CEH, OSCP) are highly regarded.
- Demonstrated ability to work independently and collaboratively within a global, cross-functional team.
Ready to make an impact? Join Henkel and help us secure the future of our industrial operations. We look forward to your application.
Tanggung Jawab
- Perform comprehensive security control assessments and vulnerability testing on OT networks, systems, and applications.
- Develop, maintain, and execute detailed test plans aligned with industry standards such as IEC 62443 and NIST CSF.
- Identify, document, and track security weaknesses, providing clear and actionable remediation guidance to global teams.
- Collaborate closely with IT, engineering, and operations teams to implement security improvements and best practices.
- Monitor the evolving threat landscape to proactively address risks to OT infrastructure.
- Support security incident response and forensic analysis activities for OT environments.
- Contribute to the continuous improvement of our OT security testing framework, tooling, and methodologies.
Kualifikasi
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, or a related field.
- 3+ years of experience in information security, with a specific focus on OT/ICS security control testing or assessments.
- Deep understanding of industrial control systems, SCADA, DCS, and common OT protocols (e.g., Modbus, DNP3, OPC).
- Hands-on experience with vulnerability assessment tools (Nessus, Qualys) and penetration testing frameworks (Metasploit, Kali Linux).
- Sound knowledge of relevant security frameworks (NIST CSF, ISO 27001, IEC 62443).
- Excellent communication skills in English, with the ability to explain complex technical concepts to diverse stakeholders.
- Relevant professional certifications (CISSP, GICSP, CISA, CEH, OSCP) are highly regarded.
- Demonstrated ability to work independently and collaboratively within a global, cross-functional team.