Company
Merck KGaA, Darmstadt, Germany
Merck KGaA, Darmstadt, Germany
As OT Security Engineer you will work in collaboration with the Sector Cyber Organization to assure the secure operations of a site, protecting against business interruption due to internal and external incidents. Reporting to the Automation manager you will be a member of the Engineering site team. Key Responsibilities:Lead implementation of site Cybersecurity initiatives in alignment with global standards, policies, and guidelines.Promote security culture and drive continuous improvement efforts in the area of cybersecurity.Provide cybersecurity direction to local Manufacturing, Engineering, Automation, QC Labs and Digital teams.Manage cybersecurity in site Business Continuity Plan, site risk register, follow up with stakeholders and provide global visibility.Carry out of internal OT cybersecurity assessments and represent the site in cybersecurity audits.Orchestrate Security Incident Management process as a Single Point of Contact for a local site and the CISO Organizations.Management of OT security risk situation, elaborating a roadmap for cybersecurity mitigation and remediation actions.Implementation of the actions defined in the cybersecurity roadmap for OT equipment and systems.Support local OT teams focusing on patching, antivirus, backup & restore, remote maintenance and asset inventory.Support local OT teams on the integration of equipment and systems of the Production and Lab areas to existing industrial communication networks following the global and local standards. Who you are:You have a Graduate Degree in the field of Automation, Industrial IT/OT, Cybersecurity, or comparable. You have experience around 5 years in pharmaceutical industry or similar, as a project manager commissioning and troubleshooting of automation systems and assets, taking part in projects for the integration of OT equipment in the IT/OT networks, managing cybersecurity risks and defining and implementing cybersecurity mitigation and remediation actions.You have experience in a GxP regulated environment, defining functional specifications, SOP’s, and maintaining it updated.You have experience in life cycle management of applications, incident management and change management protocols. knowledge of industry leading cybersecurity standards: ISA, IEC, ISO, NIST, Namur, ENISA, BSI will be appreciate.You have experience in cybersecurity assessments and audits.You have experience working with Siemens PLC´s, Wonderware SCADA’s, Siemens HMI systems. Furthermore, Virtual Infrastructures, Industrial communications, Databases.You have strong stakeholder management, communication, and organizational skills to work with local and global colleagues.You are fluent in Spanish and English.
Mollet del Vallès
Our jobs portal is fully automated and finds daily new job opportunities related to the companies listed on EVE Score.
Please remember that we do not endorse any websites related to these jobs opportunities and stay alerts to avoid scams.
A few reminders:
- Never, ever pay anything to apply for a job. Companies should be the one paying, not you
- Never agree to buy equipment in order to start a job - this includes buying a laptop, work from home equipment
- Never agree to pay for mandatory training to onboard for a new position (even if they say that they will reimburse you for later)
- If the recruiter sends you an email from a domain that is different from the company website, ask them to communicate with you via email belonging to the company. Stay away from Gmail, Hotmail, Yahoo or domain that looks close to the company they are portraying
- Don’t give personal information during the application process - social security number, bank account, home address, date of birth - this could be used to target you through a social engineering attack later on
- Don’t complete a project for free. Many companies might ask you to get through a test, that’s one thing. But less scrupulous companies will actually ask you to deliver a project for free