Job description Posted 14 February 2019

The Senior Operational Technology (OT) Security Specialist is a senior member of the GMS OT Security team focused on GMS manufacturing automation systems. The role is accountable for defining, developing, assessing, approving and delivering complex and innovative solutions to reduce OT Cyber security related risks across GMS, which may inhibit GSK manufacturing operations, resulting in safety, quality, financial or reputation impact.

This person will act as a Subject Matter Expert for the technology & processes related to OT Cyber Security, will ensure that good security practices are embedded across GMS manufacturing sites (currently circa 70 sites), make recommendations for improvement / oversight and set the direction of the OT security strategy.

• Act as the technical authority, develop or contribute to cyber training, processes and standards for manufacturing automation systems across GMS

• Develop in depth knowledge of the GSK technology, systems and processes deployed to protect our manufacturing automation systems from cyber security threats

• Work with GMS Tech groups to deliver the required secure network infrastructure and segmentation based on recommended reference architectures and industry standards

• Work with sites to ensure alignment with direction of strategic OT security solutions such as secure remote access, network segmentation and OT access management (workflow, OT Active Directory, password management)

• Work with sites and GSK Tech to ensure that the appropriate cyber security and system monitoring tools are in place and in use

• Technical authority or SME on GSK OT architecture and infrastructure with broad general knowledge on IT applications and infrastructure with specific knowledge on several of the following

Main Skills & Background:

  • IT Networks (switches, routing, firewalls)
  • Firewall rules, logging, monitoring, IDS/IPS and troubleshooting (Checkpoint & Palo Alto)
  • Microsoft Active Directory
  • Enabling services (e.g NTP, SMTP, patching, AntiVirus)
  • System integration technologies (OPC, XML, middleware)
  • Database knowledge (SQL, Oracle, data warehousing, architecture)
  • Current and legacy operating systems (Microsoft Server, Microsoft Clients, Linux)
  • Server infrastructure (VMWare ESXi, storage)
  • Technical authority or SME on manufacturing automation systems, device and applications with specific knowledge on several of the following
  • Specific knowledge on control systems from a wide range of vendors (PLC, DCS, SCADA)
  • Manufacturing Execution Systems (Data historians, EBR, OEE, SAP)
  • ISA Standards (ISA 99/IEC62443, S95, S88)
  • Communication networks and protocols (Serial, Profibus, Ethernet)
  • Coach and / or Mentor OT Security Specialist / Engineers and site based teams to develop appropriate levels of capability
  • Develop and support delivery of cyber security training for OT systems across GMS
  • Specialist training in OT Cyber Security (e.g. IEC62433)
  • In depth expert knowledge of diverse range of manufacturing automation systems
  • Manufacturing Automations System, IT Infrastructure & Cyber Security
  • 10+ years manufacturing automation experience with several years in technical roles with exposure to IT infrastructure and Cyber Security risk reduction
  • Effective communication skills with the ability to interface with operational, capital projects and senior management within the organization
  • Broad knowledge and practical experience of computer and application validation (preferably using GAMP methodology), cGMPs, and 21 CFR Part 11 in an FDA regulated environment
  • Working knowledge and understanding of current Good Manufacturing Practices including Good Documentation Practices
  • Capable of working in multi-disciplinary teams across engineering projects, new product introduction and technology projects.
  • Excellent written and oral communication skills

Additional information about the process

All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!