IT Security Consultant

Posted 28 Days Ago
Be an Early Applicant
Vadodara, Gujarat, IND
In-Office
Mid level
Professional Services • Consulting • Financial Services
The Role
Conduct IT and OT security audits for manufacturing clients, assessing infrastructure, access controls, vulnerabilities, segmentation, backups, and compliance with security frameworks. Document and present risk-rated findings, recommend remediation, track corrective actions, and support external audits. Collaborate with plant operators, maintenance teams, and IT leadership while traveling 30–40% to manufacturing sites.
Summary Generated by Built In

Key Responsibilities

IT Security Audit Execution

·       IT (General controls ) testing with the GRC | Assurance Teams for the IFC compliance Perform

  • Plan, scope, and conduct internal IT security audits for 8–12 manufacturing clients annually.
  • Assess IT environments (Active Directory, firewalls, patch management, privileged access, MFA, logging/SIEM).
  • Evaluate OT/IoT security where IT systems connect to production networks (PLCs, HMIs, SCADA, historians).
  • Review compliance with ISO 27001, NIST CSF, IEC 62443-2-1, and GDPR (where applicable).
  • Perform audit procedures including:
    • Control testing (technical & administrative)
    • Vulnerability assessment (non-intrusive)
    • Configuration reviews (switches, firewalls, servers)
    • Access control & user entitlement reviews
    • Backup & disaster recovery validation
  • Identify gaps in network segmentation between office IT and shop-floor OT.

Reporting & Remediation

  • Document findings with clear risk ratings (Critical, High, Medium, Low).
  • Provide manufacturing-specific recommendations (e.g., “air gap backup recovery,” “replace unsupported Windows 7 on HMI”).
  • Present audit reports to plant managers and IT leadership.
  • Track remediation progress and perform limited validation re-audits.

Compliance & Standards

  • Map audit findings to regulatory requirements (e.g., CMMC, NIS2 if applicable).
  • Support clients during external audits or insurance cyber assessments.

Collaboration

  • Work with client maintenance and controls engineers (non-security personnel) to explain risks without jargon.
  • Escalate critical findings (e.g., ransomware exposure via exposed RDP on a production server) immediately.


Requirements

Experience

  • 3–5 years in IT security auditing or security consulting – with at least 1 year directly auditing manufacturing, industrial, or logistics companies.
  • Hands-on experience auditing: Active Directory, firewalls (rule base review), Windows/Linux servers, backup solutions, and endpoint AV/EDR.
  • Familiarity with industrial protocols (Modbus, PROFINET, OPC UA) – not for deep testing, but to understand risk context.
  • Experience using audit frameworks: ISO 27001, NIST 800-53 or CSF, IEC 62443 (awareness level).

Certifications (at least one)

  • CISA (preferred)
  • ISO 27001 Lead Auditor
  • CISSP (or Associate)
  • Security+
  • Bonus: GICSP or ISA/IEC 62443 Cybersecurity Fundamentals

 

 

Technical skills

  • Auditing vulnerability scan results (Tenable, Qualys, or Rapid7)
  • Basic scripting for evidence collection (PowerShell, Python, or bash)
  • Familiarity with compliance tools (e.g., Vanta, Drata, or manual checklists)

Soft skills

  • Ability to interview plant operators and IT admins without creating friction.
  • Clear report writing – no excessive jargon.
  • Pragmatic risk mindset: “Secure enough for production uptime.”

Preferred (Nice to Have)

  • Past role in managed security services or internal audit for a manufacturer.
  • Understanding of ransomware impact on production schedules (e.g., downtime cost modeling).
  • Experience with NIST 800-82 or C2M2.

Work Environment & Travel

  • Up to 30–40% travel to manufacturing sites (safety training required – steel-toe boots, hearing protection, etc.).
  • Audits are typically 1–2 weeks on-site per client, then remote for reporting.


Benefits
  • Competitive base salary + audit completion bonuses.
  • Opportunity to shape security posture in critical infrastructure.


Skills Required

  • 3–5 years of experience in IT security auditing or security consulting
  • At least 1 year auditing manufacturing, industrial, or logistics companies
  • Hands-on auditing experience with Active Directory, firewalls, Windows/Linux servers, backup solutions, and endpoint AV/EDR
  • Familiarity with industrial protocols including Modbus, PROFINET, and OPC UA
  • Experience with ISO 27001, NIST 800-53 or CSF, and IEC 62443 frameworks
  • At least one relevant certification: CISA, ISO 27001 Lead Auditor, CISSP or Associate, or Security+
  • Ability to audit vulnerability scan results using Tenable, Qualys, or Rapid7
  • Basic scripting experience with PowerShell, Python, or Bash
  • Familiarity with compliance tools such as Vanta, Drata, or manual checklists
  • Ability to interview plant operators and IT administrators effectively
  • Clear technical report-writing skills with limited jargon
  • Pragmatic risk-management approach focused on production uptime
  • CISA certification
  • GICSP or ISA/IEC 62443 Cybersecurity Fundamentals certification
  • Experience in managed security services or internal audit for a manufacturer
  • Understanding of ransomware impacts on production schedules and downtime cost modeling
  • Experience with NIST 800-82 or C2M2
  • Willingness to travel 30–40% to manufacturing sites and complete required safety training
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Vadodara
625 Employees
Year Founded: 1934

What We Do

Sharp & Tannan is an Indian chartered accountant firm providing full-service assurance, governance, risk and compliance (GRC), tax, and business consulting services. Founded by Charles Ruxton Sharp and Bodh Raj Tannan, the partnership serves major Indian businesses across sectors through 10 offices, combining multidisciplinary expertise, local market knowledge, and cross-border reach. The firm emphasizes reliability, trustworthiness, independence, and ethical professional conduct.

Similar Jobs

In-Office or Remote
2 Locations
175633 Employees
Remote or Hybrid
2 Locations
175633 Employees

Mondelēz International Logo Mondelēz International

Manager, Project Engineering

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
India
90000 Employees

Capco Logo Capco

Alteryx Developer - PC

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account