For Employers
OT Security Engineer
Job post no longer accepts applications
Company logo (non-clickable)
Shell
16 days ago
Posted date
16 days ago
N/A
Minimum level
N/A
OtherJob category
Other
Where you fit In

Shell has been a partner in Oman's remarkable development and progress over the past several decades. Shell has provided pioneering technologies and expertise to Oman's energy industry helping to create value for the wider community of which we have proudly been a part.

Position Purpose:

The Operational Technology Security Engineer has the direct responsibility for the Security and the overall management of the Operational Technology in the OT Landscape. The incumbent will work with the Main Automation Contract vendor, Maintenance contractor and the asset to setup and secure the OT landscape, create the procedures, SOP's and implement all requirements.

The incumbent will represent the operational technology OT security discipline and possess an expert level of understanding of industrial automation and control systems (IACS) and process control networks (PCN) as well as sound understanding of cyber risk management and how it applies to industrial environments and drive the implementation of security programs/projects within Oman Shell.

What's the role?

Position Responsibilities

The position reports to the Senior MRTA Engineer within the Production Organisation. The position responsibilities span a range of desired outcomes and include:

Role key deliverables
  • Ensure ownership and delegations of authority for OT equipment, systems and applications in OT is clearly defined and documented.
  • Have an overview of security measures implemented and documented non-compliance to information security requirements.
  • Develop, maintain, and execute any site-specific procedures and SOP's required to maintain OT security compliance.
  • Create/Maintain logical and physical network drawings of OT components.
  • Define and rollout Preventative Maintenance plans
  • Responsible for all OT security related aspects of the OT comprising of major systems including DCS, IPS/FGS, Electrical and Sub-Systems
  • Review OT Security aspects of all data communication channels and technology selections for data transfers between systems in the PCN and systems in other networks.
  • Maintain an overview of the security measures that have been implemented for each system. For systems that do not comply with the documented information security requirements, ensure that deviations are in place and effectively managed and remediated.
  • Assure that all systems equipment and network components have appropriate backup/restore arrangements and related disaster recovery capabilities.
  • Assure stringent access control management for all OT systems and arrange as appropriate with the various stakeholders to ensure competence management of all authorized users.
  • Monitor servers, networks and communication equipment for any security alert using implemented tools, systems and applications.
  • Monitor and execute user access control and user profile management for servers and networks based on documented business approval.
  • Review security logs and provide reports for identifying potential intrusion into systems and networks, and escalate potential incidents as necessary, and to ensure the incident is properly investigate, remediated, reviewed and closed.
  • Manage antivirus solutions to ensure all OT nodes receive effective and up-to-date endpoint protection.
  • Perform security updates of operating systems based on recommended frequency.
  • Authorize system and user access to applications and systems in the OT through the Secure Site.
  • Manage passwords for the applications and systems in the OT.
  • Regularly verify that only authorized users have access to relevant systems and applications.
  • Ensure users who leave the company, change their internal positions, or no longer have business needs for access immediately have their access rights revoked
  • Evaluate and document the need for back-ups
  • Handling and Reporting of OT Security incidents.

Ways of working
  • Consistently apply, standard methods, tools, and templates for delivery.

Stakeholder Management
  • Maintain interface with Oman Shell IT, Global IT, MAC vendors, ICE discipline, Asset, and engineering departments
  • Deliver OT Security training programs for users of the OT systems.

Specific Challenges
  • Ensure that OT risk profile and Local Management System (LMS) objectives are achieved and develop fit for purpose solutions to maintain compliance.
  • Ensure no production loss, plant trip or quality non-conformance result from tasks performed.
  • The role will be rotational field based at Block 10 & 11 concession.
What we need from you

Industrial and Automation & Control Systems
  • Engineering degree or equivalent field/industry experience.
  • Experience in a Shell operating asset, IACSs vendor/supplier or equivalent external industry experience.
  • Expert level understanding of Shell's OT environments.

Operational OT Cyber Security
  • Proven experience or certification in server/desktop infrastructure design, deployment and maintenance.
  • Proven experience or certification on networks including firewalls, routers and switches or hosting/storage infrastructure design and implementation for production systems (CCNA).
  • Proven experience or certification in virtual hosting design and deployment (VMWare)
  • Proven experience or certification in information risk management such as CISSP, GICSP, CISA, CISM
  • Skilled in network and hosting/storage infrastructure design and implementation.
  • Experience in Asset Inventory management systems, Intrusion Detection systems, backup systems, Disaster Recovery Services is highly desired.
  • Awareness of IEC 62443-2-4 standards and its implementation in the OT.
  • Good knowledge of the OT risk management methodology particularly with Business Impact Analysis for infrastructure and applications.
  • Good knowledge and understanding of Secure Site and associated services like anti-virus updates, WSUS Patching Service and Shell IT services.
  • Experience in working with Infrastructure Service Providers , and Production Operations staff is desirable.

Leadership
  • Ability to work with virtual teams
  • Ability to perform under pressure and to handle multiple high priority activities simultaneously
  • Must be a self-starter with willingness to learn new skills and a personal drive to meet targets.

Behaviors
  • Matriculate, precise, leading to high quality delivery
  • A HSSE driven mind-set.
  • Excellent interpersonal, influencing, presentation, communication, and analytical skills

COMPANY DESCRIPTION

An innovative place to work

There's never been a more exciting time to work at Shell.

Join us and you'll be adding your talent and imagination to a business with the ambition to shape the future - whether by investing in oil, gas and renewable energy to meet demand, exploring new ways to store energy, or developing technology that helps the world to use energy more efficiently, everyone at Shell does their part.

An inclusive place to work

To power progress, we need to attract and develop the brightest minds and make sure every voice is heard. Here are just some of the ways we are nurturing an inclusive environment - one where you can express your ideas, extend your skills, and reach your potential.

  • We're creating a space where people with disabilities can excel through transparent recruitment process, workplace adjustments and ongoing support in their roles. Feel free to let us know about your circumstances when you apply, and we'll take it from there.
  • We're closing the gender gap - whether that's through action on equal pay or by enabling more women to reach senior roles in engineering and technology.
  • We're striving to be a pioneer of an inclusive and diverse workplace, promoting equality for employees regardless of sexual orientation or gender identity.
  • We consider ourselves a flexible employer and want to support you finding the right balance. We encourage you to discuss this with us in your application.

A rewarding place to work

Combine our creative, collaborative environment and global operations with an impressive range of benefits and joining Shell becomes an inspired career choice.

We're huge advocates for career development. We'll encourage you to try new roles and experience new settings. By pushing people to reach their potential, we frequently help them find skills they never knew they had, or make career moves they never thought possible.
Related tags
-
JOB SUMMARY
OT Security Engineer
Company logo (non-clickable)
Shell
Bawshar
16 days ago
N/A
Full-time