Site Name: USA - Pennsylvania - Upper Providence
Posted Date: Apr 17 2025
The newly formed R&D OT Services and Security Team, part of the Quality Engineering and Labs group in R&D Digital and Tech, are looking for an Operational Technology (OT) Security Engineer who will oversee the OT environment used for R&D operations and have the necessary operational knowledge to manage firewall policy and support OT security controls within the OT and IT environment. The OT Security Engineer will support down to a site level and take the lead in new system implementation and incident response.
It is key for the OT Security Engineer to have in-depth understanding of network architecture to design, implement, and manage secure and efficient segmentation and proficiency with cybersecurity tools (e.g., firewalls, intrusion detection/prevention systems) and respond to security incidents.
The OT Security Engineer will have ownership and responsibility to lead and drive security controls and initiatives in the delivery of secure and reliable operational technology environments.
This role will provide YOU the opportunity to lead key activities to progress YOUR career, these responsibilities include the following:
- Network security - Support the implementation of key network security controls, including segmentation, user access, wireless communication, and vendor access.
- Firewall policy - Deliver firewall policy as part of network security controls, engage with firewall change process and associated security engine policy, such as Zscaler / Dynamic Edge Segmentation (DES).
- Incident management - Act as a key point of contact to support technical response to OT related incidents, ensuring rapid resolution to minimise business impact.
- Device management - Work with key partners, both within R&D and global support functions to establish hardening controls around OT assets, ensuring compliance with GSK standards
- Continuous improvement - Work to enhance R&D's OT security posture through continuous improvement, efficiency improvements through automation and eliminating waste.
- Vulnerability - Support vulnerability management throughout the OT environment, identifying and triage of vulnerabilities and analysing business impact.
- Patch Management: Work with R&D lines and vendors to identify, test, validate and deploy security patches and updates for the OT environment.
- Security Controls - Lead the deployment of security controls within the OT environment, including training and awareness.
- Quality, risk and compliance - Support operational technology compliance with internal security and risk management policies and practices, as well as external regulatory and statutory requirements e.g. GxP and that Tech continuity plans are in place for all critical areas.
- People Management: Collaborate with internal owners of security technologies and act as an advocate for OT cybersecurity.
Why you?
Basic Qualifications:
We are looking for professionals with these required skills to achieve our goals:
- Bachelor’s Degree - Technical Degree e.g. Engineering, Information Technology
- In-depth understanding of network architecture to design, implement, and manage secure and efficient networks.
- Minimum of 5 years of experience with cybersecurity tools (e.g., firewalls, intrusion detection/prevention systems) and techniques to protect network integrity and respond to security incidents.
- No less than 5 years of experience collaborating with cross-functional teams and communicate technical insights effectively to support secure file management and other security initiatives.
- At least 5 years of experience in ensuring R&D adherence to OT security policies and standards. Skill in driving initiatives that support security, innovation, and efficiency within the R&D environment.
Preferred Qualifications:
If you have the following characteristics, it would be a plus:
- Master’s Degree – Technical Degree eg Engineering, Information Technology.
- Experience in network engineering roles.
- Completed relevant network related certifications (CompTIA Security+, GICSP, CISSP, ISA/IEC 62443) or equivalent.
- Experience supporting systems/applications used in pharmaceutical, clinical, or related fields would be an asset.
- Familiar with cloud computing and security standards for cloud first environment.
- Self-confident/assertive/dynamic/motivated behaviour & being able to work on multiple tasks/projects in parallel with supervision.
Why GSK?
Our values and expectations are at the heart of everything we do and form an important part of our culture.
These include Patient focus, Transparency, Respect, Integrity along with Courage, Accountability, Development, and Teamwork. As GSK focuses on our values and expectations and a culture of innovation, performance, and trust, the successful candidate will demonstrate the following capabilities:
- Agile and distributed decision-making – using evidence and applying judgement to balance pace, rigour and risk
- Managing individual and team performance.
- Committed to delivering high quality results, overcoming challenges, focusing on what matters, execution.
- Implementing change initiatives and leading change.
- Sustaining energy and well-being, building resilience in teams.
- Continuously looking for opportunities to learn, build skills and share learning both internally and externally.
- Developing people and building a talent pipeline.
- Translating strategy into action - a compelling narrative, motivating others, setting objectives and delegation.
- Building strong relationships and collaboration, managing trusted stakeholder relationships internally and externally.
- Budgeting and forecasting, commercial and financial acumen.
hackajob is partnering with GSK to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.