> Markdown version of [/jobs/ext/2311369-information-technology-security-manager](https://www.wearedevelopers.com/jobs/ext/2311369-information-technology-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Technology Security Manager - **Company:** The Planet Group - **Location:** UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Supervisory Control and Data Acquisition (SCADA), Information Technology Operations, Information Systems Security Architecture Professional, Network Segmentation, Remote Access Technology, Security Information and Event Management, Software Vulnerability Management - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815446712-information-technology-security-manager ## About the Role * Proven experience in Cyber Security management, specifically within an OT environment. * Strong understanding of relevant security frameworks and standards, and ability to translate them into practical OT controls and evidence. * Strong stakeholder management across Engineering/Operations and IT; ability to drive adoption without disrupting production. * Excellent analytical, problem-solving, and decision-making skills. * Vendor management and delivery oversight experience. * Strong written and verbal communication skills, including producing clear technical and process documentation. * Degree qualified in a relevant discipline. * Knowledge of OT-focused standards (e.g., IEC 62443, NIST 800-82) and experience supporting regulated Defence environments. * Experience integrating OT telemetry into SIEM/SOC and developing OT detections and playbooks. * Experience with assurance/control testing approaches and evidence pack preparation. ## Description The OT Security Manager is responsible for establishing and managing the organisation's OT security operating model across manufacturing and engineering environments where downtime, safety, and regulatory compliance are critical risks. The role focuses on governance, security controls, remediation initiatives, and integrating OT monitoring and incident response with central security operations, while also supporting assurance and evidence for regulated requirements. The position covers OT/ICS security across manufacturing networks and related systems (e.g., OT endpoints, PLC/SCADA/MES interfaces) and provides risk-based oversight, security architecture guidance, and governance, without replacing site engineering ownership or acting as a general IT operations role., * OT Security Governance: Define and implement the OT security operating model, including standards, RACI, and escalation paths, in partnership with Engineering and Operations. * Strategy & Design: Develop and manage OT security policies, procedures, and strategies aligned with organisational goals, industrial standards, and regulatory requirements. * OT Risk Management: Maintain an OT risk register and site-level risk documentation, ensuring risks are tracked, owned, and escalated appropriately. * Asset Management: Build and maintain OT asset inventories, classification, and criticality mapping, with defined ownership and maintenance responsibilities. * Vulnerability Management: Apply OT-specific vulnerability management practices, including safe patching, compensating controls, and change validation. * Segmentation & Boundary Controls: Implement and assure IT/OT network segmentation, access controls, and remote access policies in collaboration with site teams. * Secure Architecture & Change Governance: Provide security input to architecture and change processes to ensure plant-impacting changes are safely assessed, scheduled, and executed. * Monitoring & Incident Readiness: Integrate OT monitoring with the SOC, define detections and incident runbooks, conduct tabletop exercises, and track follow-up actions. * Recovery & Resilience: Establish expectations for OT backup and recovery, supporting resilience planning for critical systems. * Compliance Support: Assist with Defence and corporate compliance for OT (e.g., DEFCON, CSM, CE+, CMMC), focusing on control implementation and evidence. * Limited IT Assurance: Perform OT-relevant control checks and evidence validation, coordinating with IT GRC/PMO on agreed controls. * Mentoring & Team Development: Guide and mentor team members to achieve individual and team objectives. * Documentation & Communication: Produce OT security standards, procedures, and site guidance in practical, stakeholder-friendly language. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [We are all part of the game](https://www.wearedevelopers.com/videos/406-we-are-all-part-of-the-game) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [A Hitchhikers Guide to Container Security - Automotive Edition 2024](https://www.wearedevelopers.com/videos/1119-a-hitchhikers-guide-to-container-security-automotive-edition-2024) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)