We are looking for candidates to develop and maintain product development processes and workflows, ensuring compliance with security frameworks. These processes need to be clearly understood and embedded within the development teams. The work environment is agile, where flexibility and effective planning are essential skills.
Responsibilities:
Implement security compliance in product development processes, focusing on standards such as IEC 62443-4-1 and other OT security standards.
Translate cyber security standards into easily understandable formats.
Understand the organizations ways of working and stakeholder requirements.
Conduct gap assessments and scale the organizations ways of working to comply with standards.
Formulate and document processes and procedures in line with standards, ensuring easy maintenance and intuitive execution by all stakeholders.
Establish user guides, work instructions, and templates to support compliance with derived processes and procedures.
Provide support and analysis on making solutions compliant with standards such as IEC 62443-4-2 and ETSI 303 645.
Perform internal audits and assessments to document process compliance.
Requirements:
10+ years of experience, with at least 2 years of relevant experience
Experience in developing and establishing IEC 62443-4-1 in a product development environment.
Good knowledge of other industrial security standards (e.g., EN 303 645, IEC 60730 Annex H, IEC 60335-1 Annex R & U, etc.). Knowledge of global regulations and legislation relevant to the OT industry, such as NIS2, NIST, UK PSTI, RED delegated act, EU Cyber resilience Act (CRA), etc.
Familiarity with the embedded product development life cycle.
The work location is Chennai, following a hybrid work model.