Role: OT Cyber Security Engineer
Location: Kharadi, Pune.
Life Unlimited. At Smith+Nephew, we design and manufacture technology that takes the limits off living.
The OT Security Engineer plays a critical technical role in securing the organization's industrial and manufacturing technologies. This role is responsible for the hands-on design, implementation, and validation of cybersecurity controls across OT environments, supporting a sustainable OT cybersecurity program aligned with recognized industry standards and enabling safe, reliable, and compliant operations across global medical manufacturing environments.
What will you be doing?
- Serving as a technical bridge between cybersecurity, engineering, IT, and manufacturing teams, the role focuses on translating OT cybersecurity strategy, standards, and architectures into practical, effective technical solutions.
- The OT Security Engineer provides expertise to identify, assess, and mitigate cyber risk within industrial environments, ensuring security controls are implemented in a way that preserves operational continuity, safety, and product quality.
- This position plays a key role in influencing OT system design, architecture, and risk decisions through direct technical contribution. The role supports threat modelling, secure architecture design, network segmentation, and system hardening efforts, while helping teams proactively address emerging threats and support modernization and digital transformation initiatives.
- Through strong technical collaboration, clear documentation, and consistent engagement with internal teams and external vendors, the OT Security Engineer helps embed cybersecurity best practices into the day-to-day design, deployment, and operation of industrial systems, making security an integral and practical component of how OT environments are built and maintained.
- (50%) Technical Cybersecurity Architecture and Engineering: Provide hands-on technical leadership for OT cybersecurity architecture and engineering activities across industrial environments.
- Perform OT threat modelling and system-level cyber risk assessments to identify, analyse, and mitigate security risks while preserving operational continuity and safety. Conduct detailed OT security architecture and design reviews to ensure systems align with internal standards and recognized industry frameworks, including IEC 62443.
- Design, implement, and validate network segmentation strategies and firewall rules to reduce attack surface and enforce defence-in-depth principles. Define, document, and maintain hardened configurations, golden images, and secure build standards for OT systems, and assess industrial assets for compliance with established cybersecurity requirements.
- (30%) OT Vulnerability Management and Incident Response: Support OT-specific vulnerability management and incident response activities in collaboration with Information Security, Manufacturing, and Engineering teams. Triage identified vulnerabilities, assess risk and operational impact, and support prioritization decisions appropriate for industrial environments.
- Coordinate remediation efforts, including patch validation and deployment planning, and implement compensating controls where patching is not immediately feasible. Provide technical support during OT cybersecurity incidents, contributing to investigation, containment, and recovery activities, and supporting root cause analysis and corrective action development.
- (20%) Stakeholder and Vendor Collaboration: Work closely with Manufacturing, Engineering, IT, Information Security, and third-party vendors to support the effective implementation of OT cybersecurity controls.
- Provide technical guidance to internal teams and vendors to ensure OT security requirements are understood and incorporated into system designs, deployments, and upgrades. Support awareness of OT-specific cybersecurity threats, risks, and mitigations at the engineering and site level through clear technical communication and collaboration.
What will you need to be successful?
- Education: Bachelor´s degree or equivalent experience in Computer Science or related subject preferred.
- Licenses/ Certifications: Current CISM, CISSP, or equivalent certification preferred.
- Experience: At least 3+ years of experience in OT cybersecurity role.
- This role will be based in Pune and will be working from office in Hybrid mode. Shift Timing (12:30 PM – 9:30 PM IST) Monday to Friday.
- Clear understanding of OT/ICS cybersecurity threats, risks, and controls. Awareness of FDA and other medical device regulatory requirements preferred but not required. Knowledge of cyber security standard frameworks such as IEC 62443, NIST SP 800-82, ISO 27001/2, NIST CSF, and OWASP.
- Understanding of network infrastructure, including firewalls - particularly as they apply in a mitigating control functionality. Ability to design, recommend, plan, guide, and support implementation of innovative security solutions.
- Understanding of IEC 62443 and the Purdue Model. Ability to define OT cyber standards and hardened configurations.
- Ability to oversee the OT architectural decisions and firewall segmentation approach. Excellent written and oral communication skills.
- Experience in being able to manage and prioritize multiple tasks in an effective manner. Ability to work independently and proactively without daily direction.
You. Unlimited.
We believe in crafting the greatest good for society. Our strongest investments are in our people and the patients we serve.
Inclusion + Belonging - Committed to Welcoming, Celebrating and Thriving. Learn more about our Employee Inclusion Groups on our website https://www.smith-nephew.com/
Other reasons why you will love it here!
- Your Future: Major Medical coverage + Policy exclusions and insurance non-medical limit. Educational Assistance.
- Work/Life Balance: Flexible Personal/Vacation Time Off, Privilege Leave, Floater Leave.
- Your Wellbeing: Parents / Parents in Law’s Insurance, Employee Assistance Program, Parental Leave.
- Flexibility: Hybrid Work Model (For most professional roles)
- Training: Hands-On, Team-Customized, Mentorship
- Extra Perks: Free Cab Transport facility for all employees, One Time Meal provided to all employees as per shift. Night Shift Allowances.
#YS1
Stay connected by joining our Talent Community.
We're more than just a company - we're a community! Follow us on LinkedIn to see how we support and empower our employees and patients every day.
Check us out on Glassdoor for a glimpse behind the scenes and a sneak peek into You. Unlimited., life, culture, and benefits at S+N.
Explore our website and learn more about our mission, our team, and the opportunities we offer.