Role & responsibilities
- Establish and enforce OT security policies, procedures, and standards aligned with business objectives and industry best practices.
- Ensure adherence to the Central Electricity Authority (CEA) Cybersecurity Guidelines for the Power Sector.
- Implement and maintain compliance with relevant international standards and frameworks such as IEC 62443, NIST Cybersecurity Framework (CSF), and ISO 27001.
- Conduct regular risk assessments, vulnerability assessments, and penetration testing on OT assets to identify and mitigate potential security gaps.
- Lead and participate in internal and external cybersecurity audits for the OT landscape.
- Oversee the deployment and operation of OT-specific security solutions, including network firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), endpoint protection, secure remote access solutions, identity protection solutions and security information and event management (SIEM).
- Develop and lead the OT incident response plan, including detection, containment, eradication, and recovery processes. Act as the primary lead for investigating and managing security incidents in the OT setting.
- Monitor OT networks for malicious activity, security threats, and vulnerabilities.
- Lead and manage cybersecurity projects for new and existing power generation sites, substations, and other renewable assets.
- Collaborate closely with IT, Operations, Engineering teams,
and external vendors to integrate robust security controls into the entire lifecycle of OT systems.
- Provide expert guidance to project teams on secure architecture, network segmentation, and access control for industrial networks.
- Effectively communicate cybersecurity risks, strategies, and project status to technical teams and senior management.
- Develop and deliver cybersecurity awareness and training programs for plant personnel and OT engineers.
Preferred candidate profile
- In-depth knowledge of industrial control systems (SCADA, DCS, PLCs) and industrial network protocols (e.g., Modbus, DNP3, IEC 61850).
- Expertise in designing and implementing OT security architecture based on frameworks like the Purdue Model.
- Proven experience in designing and implementing security controls for OT environments, including network segmentation, firewalls (e.g., Palo Alto, Fortinet), IDS/IPS, and Endpoint Detection and Response (EDR) technologies.
- Hands-on experience with OT security monitoring and threat detection tools.
- Strong understanding and practical experience with ISA/IEC 62443, NIST Cybersecurity Framework, and ISO 27001.
- Demonstrable experience with regulatory compliance in a critical infrastructure sector;
experience with CEA guidelines is highly desirable.
Interested candidates please share your resume at
[email protected]
📌 Cyber Security Lead (Mumbai)
🏢 TATA Power
📍 Mumbai