Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Nhân viên
Ngành nghề
Kỹ thuật / Cơ khí
Mức lương
Từ 50tr
Địa điểm
Not Available, Hà Nội, Hà Nội
Tổng quan
- OT Security Architecture Review & Assurance
- Review the systems integrator's HLD/LLD network and security designs for the OT scope: zones and conduits per IEC 62443, firewall placement, and segmentation between IT, OT, and public-facing networks.
- Verify with L2/L3 evidence — VLAN, SVI, and routing records, management-plane and PAM design, wireless isolation proof — that no protected flow bypasses the designated firewalls.
- Review OT remote-access and patching paths (jump host, patch staging) to ensure no uncontrolled IT-to OT connectivity emerges.
- Track findings to closure through the project's decision and gap registers, distinguishing design risk from evidence gap.
- Airport OT Systems & Safety Boundaries
- Own the OT security view of the airport systems: baggage handling (BHS), building management (BMS/HVAC), fire alarm (monitor-only integration), physical access control (PACS), CCTV, master clock, lifts and escalators, and power management.
- Defend safety boundaries: hardwired interlocks sit below the software layer and must remain independent of any network or command path.
- Participate in FAT/SAT/SIT and commissioning: witness command-verification, failuremode, and interlock override testing with the M&E contractors and the Commissioning Authority, and hold security acceptance criteria at each gate through ORAT.
- Governance, Compliance & Regulatory Alignment
- Apply IEC 62443, NIST SP 800-82, and CIS Controls pragmatically to an airport OT environment.
- Operate within Vietnam's regulatory framework for critical information infrastructure: the Law on Cybersecurity, Decree 53, and personal data protection requirements, including reporting relationships with CAAV and the Ministry of Public Security.
- Prepare and defend OT security positions at the Architecture Review Board; produce documentation in both English and Vietnamese for the architecture team, contractors, and authorities.
- OT Visibility, Monitoring & SOC Integration
- Build and maintain a comprehensive OT asset inventory (wired, wireless, and IIoT) as the foundation for segmentation and monitoring decisions.
- Define requirements and acceptance criteria for passive OT network monitoring and anomaly detection, evaluating platforms capability-first: asset-discovery depth, protocol coverage, and SIEM export quality.
- Integrate OT telemetry into the enterprise SIEM (Splunk-based), and define alert ownership together with the SOC and the operations team.
- Secure Procurement & Supplier Gating
- Write capability-based security requirements for OT procurements and assess supplier responses.
- Operate device compliance questionnaires as procurement gates: protocol conformance, TLS support, authenticated access, safe-state behaviour on loss of communications, and interlock independence.
- Define proof-of-concept scope and acceptance criteria before any monitoring or enforcement platform is purchased.
- Wireless & IIoT Security
- Review wireless designs for the OT estate and verify isolation evidence for guest and public Wi-Fi against corporate and OT networks (WLC placement, SSID/VLAN separation, 802.1X, WPA3-Enterprise).
- Assess IIoT and telemetry radio proposals (LoRa, private 5G) as they arise, including Vietnamese spectrum constraints.
- Emerging OT Platform Security
- Contribute to security review of the next-phase OT platform: Unified Namespace (MQTT/Sparkplug B, OPC UA, Kafka), IT/OT Bridge with hardware data diode, and IEC 61499 software-defined automation — including engineering and deployment-plane security, recovery and IEC 61131-3 fallback, and autonomy governance.
- Your Skills and Experience
Yêu cầu
- Education
- Bachelor's or Master's in Computer Science, Electrical, Electronics, Industrial or Control Engineering, or equivalent experience.
- Experience
- Min 3–5 years in OT/ICS security, industrial networking, or building-automation security.
- Experience in airports, critical infrastructure, or large campus environments strongly preferred; greenfield construction-phase experience is a significant advantage.
- Languages
- Vietnamese and English at working proficiency (required).
- Certifications (Preferred)
- ISA/IEC 62443 Expert / Practitioner, SANS GICSP, GRID, CISSP, CISM, CWSP / CWNA (for wireless OT).
- Technical Competencies
- Proficient in BACnet/IP (mandatory building-systems protocol on this project), OPC UA, and IP networking and firewalling in segmented OT environments; TLS/PKI fundamentals.
- Working knowledge of MQTT/Sparkplug B, Modbus TCP (legacy-exception handling), and industrial wireless security.
- Hands-on experience with at least one passive OT monitoring / asset-discovery platform (e.g., Forescout, Nozomi Networks, Claroty, Dragos, Armis).
- Experience with enterprise SIEM (Splunk preferred), EDR in mixed IT/OT estates, and firewall review at both rulebase and architecture level.
- Familiarity with PLC/controller ecosystems (Schneider, Siemens, Rockwell) and exposure to IEC 61499 / IEC 61131-3 concepts.
- Familiar with risk management, threat modeling, and incident response for OT systems.
- Soft Skills
- Evidence-driven mindset: comfortable withholding acceptance until proof is provided, and able to state precisely what evidence would close a finding.
- Able to hold a security position under pressure from vendors or contractors, and to revise it when the evidence changes.
- Balances security rigour with operational uptime and a fixed opening date.
- Strong documentation habits: registers, decision records, and review comments that others can act on.
- Clear communication and stakeholder coordination across engineering, operations, and regulatory audiences.
- Why You'll Love Working Here
Quyền lợi
Chế độ thưởngDu lịchLaptop / Thiết bị
Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗
Quan tâm đến vị trí này?
Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.
Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn?
Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→