Adani Enterprises Limited
Website:
adanienterprises.com
Job details:
Lead – OT Cybersecurity Controls will be responsible for the implementation, ownership, governance and lifecycle management of OT cybersecurity controls across the plant/site environment. The role ensures secure, reliable and compliant operation of critical Operational Technology systems while maintaining DC availability, safety and business continuity.
As the designated OT Asset Owner representative, this role will coordinate with Operations, IT, Cybersecurity, OEMs, and third-party vendors to implement and sustain cybersecurity controls including Active Directory (AD), Patch Management, CrowdStrike Endpoint Protection (AV/EDR), Backup & Recovery, Identity & Access Management, Network Security, Incident Response, and Technology Lifecycle Management.
The position is accountable for ensuring OT systems remain resilient against cyber threats while ensuring operational continuity and regulatory compliance.
Education
- Bachelor's Degree in any disciple / Engineering (Computer Science, IT, Cybersecurity).
- Master's Degree preferred.
Experience
- 8–18 years of experience in Industrial Control Systems (ICS), SCADA, Data Centers, or Critical Infrastructure environments.
- Experience in managing OT Cybersecurity programs at Critical Infrastructure environments.
OT Cybersecurity Governance & Ownership
- Act as the primary owner of OT cybersecurity controls for assigned site assets.
- Ensure implementation and compliance of OT cybersecurity policies, standards, and procedures as directed by Group.
- Drive adherence to applicable frameworks and standards including:
- IEC 62443
- NIST 800-82
- ISO 27001
- NCIIPC Guidelines
- CEA Regulations
- Coordinate between Operations, IT, Cybersecurity, and OEM teams for risk management activities.
Patch & Vulnerability Management
- Own vulnerability remediation activities for OT systems.
- Plan, coordinate, test, and deploy security patches in consultation with OEMs and Group Cybersecurity teams.
- Conduct impact assessments before patch deployment.
- Develop maintenance schedules minimizing operational downtime.
- Track patch compliance and remediation closure.
- Maintain patch deployment documentation and audit evidence.
Endpoint Security & Antivirus Management
- Operate and monitor OT/ICS security controls including anti-virus or allowlisting, signature updates, segmentation checks and secured remote-access enforcement.
- Manage deployment and ongoing operation of Antivirus (AV) / Endpoint Detection & Response (EDR) solutions.
- Ensure endpoint protection controls remain operational across servers, workstations, HMIs, and engineering stations.
- Coordinate testing and validation of cybersecurity solutions before deployment.
- Monitor endpoint security health and compliance.
- Support malware containment and remediation activities with IT governance teams.
Identity & Access Management (AD & Access Controls)
- Manage OT Active Directory environments and related security controls.
- Ensure proper user provisioning, modification and deprovisioning.
- Implement least-privilege and role-based access principles.
- Coordinate privileged account reviews.
- Support identity governance, authentication and authorization controls.
- Ensure timely review of dormant and unauthorized accounts.
Backup & Recovery Management
- Define and manage backup strategies for OT infrastructure and applications.
- Ensure successful completion of scheduled backups.
- Conduct restoration testing and recovery validation exercises.
- Maintain backup retention compliance.
- Support disaster recovery readiness and emergency restoration activities.
Incident Response & Operational Resilience
- Act as site focal point during OT cybersecurity incidents.
- Investigate, coordinate and handle BU cybersecurity incidents as per incident management process, ensuring timely containment, escalation, reporting and closure within SLA.
- Coordinate containment, eradication, recovery, and business restoration activities.
- Execute predefined cyber incident response playbooks.
- Participate in incident investigations and root cause analysis.
- Ensure lessons learned are implemented to improve resilience.
- Coordinate crisis communication with stakeholders.
Network Security Management
- Ensure secure configuration of OT network infrastructure.
- Manage security requirements for firewalls, switches, remote access gateways, and segmentation controls.
- Support network security assessments and risk mitigation initiatives.
- Coordinate secure connectivity between OT and IT environments.
- Monitor compliance with network security architecture standards.
Remote Access & OEM Connectivity Management
- Govern remote access provided to OEMs, vendors, and third-party contractors.
- Ensure secure access mechanisms are implemented and monitored.
- Validate business justification and approvals before access provisioning.
- Maintain access logs and audit trails.
- Periodically review active vendor connections and user privileges.
Vendor & OEM Cybersecurity Management
- Coordinate cybersecurity implementation & third party Audits with multiple OEMs and system vendors.
- Validate vendor compliance with cybersecurity requirements.
- Support risk assessments of third-party suppliers.
- Ensure cybersecurity requirements are incorporated in contracts and support agreements.
- Escalate unresolved cybersecurity risks impacting site operations.
Disaster Recovery & Business Continuity
- Develop and maintain OT disaster recovery plans.
- Conduct periodic recovery drills and table-top exercises.
- Ensure recovery objectives meet operational requirements.
- Support business continuity planning for critical OT assets.
Compliance, Audit & Reporting
- Perform annual cybersecurity risk assessments for the BU and prepare risk assessment reports with observations, risk rating, owners and remediation recommendations.
- Support OT security assessments by collecting evidence, validating control status, documenting gaps and coordinating remediation with ACX OT, IT and O&M teams.
- Maintain ACX exception, waiver and change records with clear justification, owner, expiry date, current status and supporting evidence.
- Support audit, compliance and leadership reviews by providing accurate records, remediation status, exception ageing and control compliance evidence.
- Prepare periodic dashboards, evidence packs and status updates covering risk assessment, vulnerability closure, incidents, OT control tasks, and project progress.
- Prepare sites for internal and external cybersecurity audits.
- Maintain cybersecurity documentation and compliance records.
- Track audit observations and closure status.
- Generate periodic cybersecurity dashboards and management reports.
- Ensure regulatory compliance requirements are met.
Technology Lifecycle Management
- Manage technology lifecycle of OT assets.
- Track End-of-Life (EOL) and End-of-Support (EOS) equipment.
- Develop modernization and replacement strategies.
- Coordinate hardware and software refresh planning.
- Ensure cybersecurity risks associated with obsolete technologies are mitigated.
Key Accountabilities
- Availability and security of OT assets with Network switches.
- Successful implementation of OT cybersecurity controls.
- Timely closure of cybersecurity vulnerabilities.
- Compliance with regulatory and corporate cybersecurity requirements.
- Incident response effectiveness and recovery readiness.
- Promote cybersecurity awareness and disciplined operational hygiene across ACX OT stakeholders.
Click on Apply to know more.