OT CyberSecurity Engineer
- Full-time
- Legal Entity: Bosch Global Software Technologies Private Limited
Company Description
Bosch Global Software Technologies Private Limited is a 100% owned subsidiary of Robert Bosch GmbH, one of the world's leading global supplier of technology and services, offering end-to-end Engineering, IT and Business Solutions. With over 27,000+ associates, it’s the largest software development center of Bosch, outside Germany, indicating that it is the Technology Powerhouse of Bosch in India with a global footprint and presence in the US, Europe and the Asia Pacific region.
Job Description
Roles & Responsibilities :
Seeking a highly technical, hands-on OT Cybersecurity Engineer to secure customer’s Battery Energy Storage Systems (BESS).
The candidate will be directly responsible for evaluating security tools, hardening systems, and implementing the cybersecurity stack required to protect critical infrastructure in alignment with the IEC 62443 standard.
1. IEC 62443 Alignment:
1. Directly map, design, and implement security controls in compliance with IEC 62443-3-3, 4-1, & 4-2 standards.
i. Design, implement, and validate cybersecurity controls aligned with:
1. IEC 62443-3-3 (System Security Requirements & Security Levels)
2. IEC 62443-4-1 (Secure Product Development Lifecycle)
3. IEC 62443-4-2 (Technical Security Requirements for IACS Components)
ii. Perform security architecture reviews and threat assessments.
iii. Develop security documentation, control mappings, and compliance evidence.
iv. Support internal and external cybersecurity audits.
2. Hands on configuration and deployment of security tools to meet product architecture requirements:
a. Identity & Access Management (IAM): Authentik (integrating RADIUS, LDAP, and SAML).
b. Centralized Logging: Log capture pipeline using Rsyslog and Wazuh to aggregate events from host virtual machines, applications, and BESS hardware devices.
c. OT Vulnerability Management: Conduct OT-safe passive and active scanning/vulnerability assessments utilizing Tenable and Wazuh.
d. Backup Services: configure and validate backup policies and data preservation workflows in the internal DMZ (iDMZ) and OT zones using Bacula.
e. Endpoint Hardening: Execute host based hardening across operating systems (Ubuntu), Docker microservices, container networks, and physical network devices utilizing CIS Benchmarks and vendor recommended best practices
3. OT Protocol Security: MQTT, Modbus, and ZMQ
2. OT Threat Detection & Tool Evaluation: Actively evaluate, test, and deploy OTspecific
threat intelligence and network security monitoring tools. You will lead Proof of Concepts for commercial platforms as well as evaluate open-source alternatives like Security Onion.
3. Comprehensive System Hardening: Execute hands-on security hardening across
all layers including physical devices, virtual environments, software components
, and network devices to mitigate risks and enforce secure configurations.
4. Identity & Access Management (IAM): Configure IAM solutions (e.g., Authentik) for
OT networks. Enforce Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and strict authorization policies.
5. Vulnerability Management: Perform OT-safe vulnerability scanning (e.g., Tenable).
Prioritize and remediate vulnerabilities in collaboration with engineering teams.
6. Security Monitoring: Maintain security monitoring platforms to support future Incident Response and recovery plans being built for OT environments. Build, evaluate, and integrate future security tools to support the broader incident handling capabilities.
Qualifications
Qualifications and Experience:
• Bachelor's degree in Computer Science, Cyber Security, Engineering, or a related field.
• Relevant OT CyberSecurity Experience of 6-10 years
• Hands-on experience configuring Linux operating systems, deploying security agents, and executing technical security controls.
• Hands-on experience with vulnerability assessment tools, penetration testing, and security analysis tools specific to ICS environments.
• Foundational knowledge of networking protocols, firewalls, VPNs, IDS/IPS, and other network security concepts, with a strong understanding of network segmentation and the Purdue Model applied to OT environments.
• Deep understanding of how industrial and application messaging protocols function, specifically MQTT, Modbus, and ZMQ.
• Familiarity with standards like NERC CIP and IEC 62443, coupled with the ability to translate a compliance requirement directly into a technical firewall rule, IAM policy, or OS configuration.
• Familiarity with scripting and automation tools, specifically Python and Ansible, to streamline configurations, deploy tools, and parse data.
• Strong analytical and problem-solving skills with an ability to think critically and innovatively in complex cyber security scenarios.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply