About this OT Assurance Consultant role at Sword Group
Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.
About the role:
As an OT Assurance Consultant, you will play a key role in strengthening cyber security assurance across complex Operational Technology (OT) environments, supporting major energy organisations responsible for critical national infrastructure.
You will be responsible for developing, implementing and delivering structured OT cyber assurance programmes, assessing the effectiveness of security controls, identifying potential risks and providing practical recommendations to improve cyber resilience across critical operational systems and assets.
Working closely with OT engineers, asset owners, cyber security specialists and senior stakeholders, you will help translate cyber security requirements and recognised industry standards into effective assurance activities, supporting risk management, regulatory compliance and continuous improvement.
This is a consultancy role suited to someone with a strong background in OT cyber security assurance, experience developing and delivering assurance frameworks and the ability to engage confidently with both technical and non-technical stakeholders.
Candidates will be required to successfully complete BPSS screening.
As an OT Assurance Consultant, you will:
- Design, develop and embed OT cyber assurance frameworks, translating strategic security objectives into structured assurance programmes.
- Plan and deliver cyber assurance activities, including stakeholder interviews, workshops, documentation reviews, security assessments and technical audits.
- Assess the effectiveness of existing cyber security controls across OT environments, identifying control gaps, vulnerabilities and opportunities for improvement.
- Evaluate OT security arrangements against recognised cyber security standards and frameworks, including NCSC Cyber Assessment Framework (CAF), IEC 62443 and NIST.
- Undertake evidence gathering and control validation, ensuring assurance findings are supported by clear and appropriate documentation.
- Identify and assess cyber security risks across operational systems and infrastructure, providing practical, risk-based recommendations and supporting mitigation planning.
- Produce clear, actionable assurance reports, communicating technical findings, risks and recommendations to both technical and non-technical audiences.
- Work closely with OT engineers, asset owners, cyber security specialists and operational teams to understand existing environments and facilitate assurance activities.
- Provide subject matter expertise on OT cyber security threats, vulnerabilities, attack vectors and appropriate compensating controls.
- Present assurance findings, recommendations and progress updates to stakeholders and senior management.
- Contribute to the continuous improvement of cyber assurance methodologies, governance processes and ways of working.
Requirements
- Proven experience designing, developing and implementing cyber security assurance frameworks and structured assurance programmes.
- Strong experience planning and delivering cyber assurance activities, including security assessments, audits, stakeholder interviews, evidence gathering and control validation.
- A strong understanding of Operational Technology environments, including industrial control systems (ICS), SCADA, operational networks and supporting infrastructure.
- Experience working with OT stakeholders, asset owners, engineers and operational teams, ideally within complex industrial or critical infrastructure environments.
- Good knowledge of cyber security governance, risk management, security control frameworks and assurance methodologies.
- Understanding of OT-specific cyber security threats, vulnerabilities, attack vectors and the operational constraints associated with securing industrial environments.
- Experience assessing security control effectiveness, identifying assurance gaps and developing practical, risk-based recommendations.
- The ability to interpret technical documentation, security policies, risk assessments and supporting evidence.
- Strong analytical and report-writing skills, with the ability to communicate complex technical findings clearly to a range of stakeholders.
- Excellent communication, facilitation and stakeholder management skills, with the confidence to lead assurance workshops and present findings to senior management.
- The ability to work collaboratively across engineering, cyber security and operational teams, building effective working relationships and gaining stakeholder engagement.
Knowledge or experience of recognised cyber security frameworks, standards and regulatory requirements would be beneficial, including:
- NCSC Cyber Assessment Framework (CAF)
- IEC 62443
- NIST Cybersecurity Framework
- Network and Information Systems (NIS) Regulations
- ISO 27001
Experience working within critical national infrastructure, utilities, energy, manufacturing or other industrial environments would be advantageous, particularly where you have supported regulatory or compliance-driven cyber assurance programmes.
Benefits
At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. Here's what you can expect as part of our benefits package:
- Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
- Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
- A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.
At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.
If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.
#LI-PD1