Job description Posted 31 May 2024

Role Title: OT Risk Analyst

Duration: 6 Months

Location: GSK House (London, Remote Working Available)

Rate: £610 per day Inside IR35 via Umbrella

Who Are We - GSK?

We are a science-led global healthcare company with a special purpose: to help people do more, feel better, live longer. GlaxoSmithKline plc was formed in 2000 as a result of a merger between Glaxo Wellcome plc and SmithKline Beecham plc, although our history can be traced back more than 300 years to London’s Plough Court Pharmacy in the 1700s.

Our goal is to be one of the world’s most innovative, best performing and trusted healthcare companies. Our strategy is to bring differentiated, high-quality and needed healthcare products to as many people as possible, with our three global businesses, scientific and technical know-how and talented people. Our values and expectations are at the heart of everything we do and form an important part of our culture:

• Our values are Patient focus, Transparency, Respect, Integrity

• Our expectations are Courage, Accountability, Development, Teamwork

Role purpose / summary

• Conduct a risk assessment for each in-scope service

• Review system architecture documentation and diagrams

• Review configuration information for systems considered to be in scope of the risk assessment such as firewalls, routers, switches, and workstations

• Review policies, standards, and procedures relating to how systems are used and accessed

• Conduct interviews (via email, telephone, web conference as can arranged) with personnel who use, interact, and manage in-scope systems as considered necessary

• Make an informed and objective determination of vulnerabilities, threats, and the overall risk status of each in-scope system

• Make an informed and objective determination of the activities and recommendations necessary to mitigate risks

• Write a report for each risk assessment to include an executive summary, detailed results of the assessments, and the recommendations

• Present the risk assessments to the appropriate governance bodies such as OT ARB

Key Skills/ requirements

• Strong Background in Cyber Security, with prior experience on managing OT Risk in an Engineering/ Manufacturing environment

• Clear experience of working with accordance to the ISA/IEC 62443 suite of standards

All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!

Join GSK’s vision to do more, feel better and live longer:

https://www.youtube.com/user/gskvision/

Who will I be working with?

http://www.gsk.com/en-gb/careers/meet-our-people/