About the role: The Information Security Professional (ISP) supports the secure operation of the organization's information technology (IT) and operational technology (OT) environments. The ISP serves as the local point of contact for information security matters and coordinates the implementation of applicable cybersecurity policies, standards, controls, and risk-treatment activities.
The role works closely with Asset Owners, Asset Management Coordinators, IT and OT Operations, Product and Solution Security Experts, business departments, Compliance, Audit, and external service providers. The ISP provides security guidance, monitors compliance, follows up on cybersecurity risks, and promotes continuous improvement of the site's cybersecurity maturity.
What will you do? - Serve as the local point of contact for IT and OT information security matters.
- Advise business, operational, and technical stakeholders on cybersecurity policies, risks, requirements, and control implementation.
- Support the secure operation of IT and OT environments in cooperation with Asset Owners, Asset Management Coordinators, IT/OT Operations, and software development team.
- Support and continuously improve the local implementation of the Information Security Management System and applicable security policies and standards.
- Coordinate cybersecurity risk assessments, compliance reviews, security-control assessments, and risk-treatment activities.
- Coordinate internal and external audits, maintain required evidence, track findings, and follow up on corrective actions.
- Drive vulnerability and patch-management governance, including remediation tracking, prioritization, security exceptions, compensating controls, and risk escalation.
- Support identity and access management, privileged access, network security, third-party access, and other required technical and organizational controls.
- Review security requirements for new systems, infrastructure changes, projects, suppliers, and IT/OT services.
- Support cybersecurity incident response by coordinating stakeholders, providing asset and risk context, tracking corrective actions, and applying lessons learned.
- Develop and deliver cybersecurity awareness activities, communications, and role-specific training.
- Monitor cybersecurity risks, control effectiveness, vulnerabilities, incidents, audit findings, and compliance status through reports, dashboards, and defined performance indicators.
- Identify gaps and emerging threats and coordinate improvements to processes, controls, tools, documentation, and site cybersecurity maturity.
- Maintain current knowledge of applicable cybersecurity regulations, industry standards, threats, technologies, and Siemens requirements.
What will you need to succeed? - Diploma or bachelor's degree in cybersecurity, information technology, computer science, engineering, information systems, or a related field, or equivalent experience.
- Over 2 years of relevant experience in information security, IT/OT cybersecurity, governance, risk, compliance, security operations, or a related role.
- Knowledge of information security governance, risk assessment, security controls, policy compliance, audit support, and risk-treatment processes.
- Working knowledge of vulnerability management, patch management, security exceptions, access management, network security, and incident-response processes.
- Understanding of IT infrastructure, operating systems, networks, firewalls, cloud services, identity systems, and industrial or OT environments.
- Experience coordinating security assessments, audits, findings, remediation activities, and supporting evidence.
- Ability to interpret security requirements and translate identified risks into practical actions with accountable owners and target dates.
- Strong analytical, problem-solving, documentation, communication, facilitation, and stakeholder-management skills.
- Ability to communicate cybersecurity risks clearly to technical and non-technical audiences.
- Effective written and spoken English.
Preferred Qualifications - Experience in a manufacturing, industrial, OT, critical-infrastructure, regulated, or audit-intensive environment.
- Knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, IEC 62443, or comparable cybersecurity standards.
- Experience with governance, risk and compliance platforms, vulnerability-management tools, security dashboards, or reporting solutions.
- Experience with security awareness programs, incident-response coordination, supplier security, or third-party risk management.
- Relevant certification such as CISSP, CISM, CISA, CRISC, Security+, GICSCP, or an IEC 62443 qualification.
- Experience working in a global or highly matrixed organization.
Salary is commensurate with experience, and ranges between $ 76,000 CAD - $ 100,000 CAD, excluding bonus and benefits. In addition to base salary, this role includes eligibility for an annual discretionary bonus of 10% of base salary, based on Company performance metrics.
#LI-Hybrid