OT Security Engineer
Stevenage, United Kingdom
GSK
At GSK, we unite science, technology and talent to get ahead of disease togetherThe newly formed R&D OT Services and Security Team, part of the Quality Engineering and Labs group in R&D Digital and Tech, are looking for an Operational Technology (OT) Security Engineer who will oversee the OT environment used for R&D operations and have the necessary operational knowledge to manage firewall policy and support OT security controls within the OT and IT environment. The OT Security Engineer will support down to a site level and take the lead in new system implementation and incident response.
It is key for the OT Security Engineer to have in-depth understanding of network architecture to design, implement, and manage secure and efficient segmentation and proficiency with cybersecurity tools (e.g., firewalls, intrusion detection/prevention systems) and respond to security incidents.
The OT Security Engineer will have ownership and responsibility to lead and drive security controls and initiatives in the delivery of secure and reliable operational technology environments.
This role will provide YOU the opportunity to lead key activities to progress YOUR career, these responsibilities include the following:
•Network security - Support the implementation of key network security controls, including segmentation, user access, wireless communication, and vendor access.
•Firewall policy - Deliver firewall policy as part of network security controls, engage with firewall change process and associated security engine policy, such as Zscaler / Dynamic Edge Segmentation (DES).
•Incident management - Act as a key point of contact to support technical response to OT related incidents, ensuring rapid resolution to minimise business impact.
•Device management - Work with key partners, both within R&D and global support functions to establish hardening controls around OT assets, ensuring compliance with GSK standards
•Continuous improvement - Work to enhance R&D's OT security posture through continuous improvement, efficiency improvements through automation and eliminating waste.
•Vulnerability - Support vulnerability management throughout the OT environment, identifying and triage of vulnerabilities and analysing business impact.
•Patch Management: Work with R&D lines and vendors to identify, test, validate and deploy security patches and updates for the OT environment.
•Security Controls - Lead the deployment of security controls within the OT environment, including training and awareness.
•Quality, risk and compliance - Support operational technology compliance with internal security and risk management policies and practices, as well as external regulatory and statutory requirements e.g. GxP and that Tech continuity plans are in place for all critical areas.
•People Management: Collaborate with internal owners of security technologies and act as an advocate for OT cybersecurity.
Why you?
Basic Qualifications:
We are looking for professionals with these required skills to achieve our goals:
•Bachelor’s Degree - Technical Degree e.g. Engineering, Information Technology
•In-depth understanding of network architecture to design, implement, and manage secure and efficient networks.
•Proficiency with cybersecurity tools (e.g., firewalls, intrusion detection/prevention systems) and techniques to protect network integrity and respond to security incidents.
•Strong ability to collaborate with cross-functional teams and communicate technical insights effectively to support secure file management and other security initiatives.
•Expertise in ensuring R&D adherence to OT security policies and standards. Skill in driving initiatives that support security, innovation, and efficiency within the R&D environment.
•Self-confident/assertive/dynamic/motivated behaviour & being able to work on multiple tasks/projects in parallel with supervision.
Preferred Qualifications:
If you have the following characteristics, it would be a plus:
•Master’s Degree – Technical Degree e.g. Engineering, Information Technology.
•Experience in network engineering roles.
•Completed relevant network related certifications (CompTIA Security+, GICSP, CISSP, ISA/IEC 62443) or equivalent.
•Experience supporting systems/applications used in pharmaceutical, clinical, or related fields would be an asset.
•Familiar with cloud computing and security standards for cloud first environment.
Closing Date for Applications – 25th April 2025 (COB)
Please take a copy of the Job Description, as this will not be available post closure of the advert. When applying for this role, please use the ‘cover letter’ of the online application or your CV to describe how you meet the competencies for this role, as outlined in the job requirements above. The information that you have provided in your cover letter and CV will be used to assess your application.
During your application, you will be requested to complete voluntary information which will be used in monitoring the effectiveness of our equality and diversity policies. Your information will be treated as confidential and will not be used in any part of the selection process. If you require a reasonable adjustment to the application / selection process to enable you to demonstrate your ability to perform the job requirements, please contact 0808 234 4391. This will help us to understand any modifications we may need to make to support you throughout our selection process.
#LI-GSK
Why GSK?
Uniting science, technology and talent to get ahead of disease together.
GSK is a global biopharma company with a special purpose – to unite science, technology and talent to get ahead of disease together – so we can positively impact the health of billions of people and deliver stronger, more sustainable shareholder returns – as an organisation where people can thrive. We prevent and treat disease with vaccines, specialty and general medicines. We focus on the science of the immune system and the use of new platform and data technologies, investing in four core therapeutic areas (infectious diseases, HIV, respiratory/ immunology and oncology).
Our success absolutely depends on our people. While getting ahead of disease together is about our ambition for patients and shareholders, it’s also about making GSK a place where people can thrive. We want GSK to be a place where people feel inspired, encouraged and challenged to be the best they can be. A place where they can be themselves – feeling welcome, valued, and included. Where they can keep growing and look after their wellbeing. So, if you share our ambition, join us at this exciting moment in our journey to get Ahead Together.
GSK is an Equal Opportunity Employer. This ensures that all qualified applicants will receive equal consideration for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), military service or any basis prohibited under federal, state or local law.
We believe in an agile working culture for all our roles. If flexibility is important to you, we encourage you to explore with our hiring team what the opportunities are.
Should you require any adjustments to our process to assist you in demonstrating your strengths and capabilities contact us on Ukdiversity.recruitment@gsk.com or 0808 234 4391. The helpline is available from 8.30am to 12.00 noon Monday to Friday, during bank holidays these times and days may vary.
Please note should your enquiry not relate to adjustments, we will not be able to support you through these channels. However, we have created a UK Recruitment FAQ guide. Click the link and scroll to the Careers Section where you will find answers to multiple questions we receive .
Important notice to Employment businesses/ Agencies
GSK does not accept referrals from employment businesses and/or employment agencies in respect of the vacancies posted on this site. All employment businesses/agencies are required to contact GSK's commercial and general procurement/human resources department to obtain prior written authorization before referring any candidates to GSK. The obtaining of prior written authorization is a condition precedent to any agreement (verbal or written) between the employment business/ agency and GSK. In the absence of such written authorization being obtained any actions undertaken by the employment business/agency shall be deemed to have been performed without the consent or contractual agreement of GSK. GSK shall therefore not be liable for any fees arising from such actions or any fees arising from any referrals by employment businesses/agencies in respect of the vacancies posted on this site.
Please note that if you are a US Licensed Healthcare Professional or Healthcare Professional as defined by the laws of the state issuing your license, GSK may be required to capture and report expenses GSK incurs, on your behalf, in the event you are afforded an interview for employment. This capture of applicable transfers of value is necessary to ensure GSK’s compliance to all federal and state US Transparency requirements. For more information, please visit the Centers for Medicare and Medicaid Services (CMS) website at https://openpaymentsdata.cms.gov/
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Automation CISSP Cloud Compliance CompTIA Firewalls GICSP IEC 62443 Incident response Intrusion detection Monitoring Network security R&D Risk management Vulnerabilities Vulnerability management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.