Senior OT/ICS Cybersecurity Expert – BESS / Energy Storage

To apply, send your CV to hr@krdrenewables.com OR use the automated application below.

Please attach your CV to your application email

ABOUT THE ROLE

KRD Renewables is seeking an experienced Senior OT/ICS Cybersecurity Expert to lead cybersecurity and IT/OT architecture assessments for large-scale Battery Energy Storage System (BESS) projects.

The role focuses on Technical Due Diligence, technical advisory and cybersecurity risk assessment for energy infrastructure projects.

The successful candidate will take ownership of the cybersecurity workstream, reviewing complex IT/OT architectures, assessing compliance with applicable standards and client requirements, identifying material risks, and developing professional recommendations for investors, lenders and energy companies.

This is not a traditional SOC or IT security administration role. It is a senior technical advisory position focused on industrial cybersecurity and critical energy infrastructure.

KEY RESPONSIBILITIES

Cybersecurity Due Diligence

Lead cybersecurity assessments for utility-scale BESS projects.
Review IT/OT architecture, cybersecurity design and technical documentation.
Identify material cybersecurity risks, technical gaps and non-compliance.
Assess the maturity and security of proposed OT environments.
Develop technical recommendations and risk mitigation measures.
Support investment and transaction decision-making from a cybersecurity perspective.

Standards & Regulatory Compliance

Assess projects against relevant standards, regulatory requirements and industry good practice, including:

ISA/IEC 62443
NIST SP 800-82
ANSI/ISA-95
Applicable Polish cybersecurity regulations
Critical infrastructure requirements
Client-specific IT, OT and cybersecurity standards

IT/OT Architecture

Review network architecture and security zoning.
Assess IT/OT segmentation.
Review DMZ and iDMZ implementation.
Assess WAN and SD-WAN connectivity.
Review communications between OT systems and external networks.
Identify unauthorised or insufficiently controlled communication channels.
Assess dependencies on cloud platforms, vendor infrastructure and third-party services.
Verify compliance with on-premises architecture requirements.

SCADA, EMS, BMS & PCS

Review the cybersecurity architecture and technical documentation of key energy control systems, including:

SCADA
Energy Management Systems (EMS)
Battery Management Systems (BMS)
Power Conversion Systems (PCS)

Responsibilities will include:

Reviewing communication protocols.
Assessing system interfaces.
Assessing logging and monitoring capabilities.
Reviewing integration with central supervisory systems.
Assessing remote monitoring and control capabilities.
Reviewing technology vendors and system origin where required.

Remote Access

Assess vendor remote-access architecture.
Verify that remote access is controlled through secure intermediary infrastructure.
Confirm appropriate separation between external networks and OT assets.
Review authentication, authorisation and access-control mechanisms.
Assess the scope of vendor diagnostic and maintenance access.
Identify risks associated with remote administration and control.

Cybersecurity Monitoring

Assess integration capabilities with:

SIEM platforms
IDS/NIDS
Vulnerability Management Systems
Central cybersecurity monitoring platforms

The role will also include reviewing:

System logs
Log formats
Log transmission capabilities
IDS sensor architecture
Security monitoring interfaces
Integration with central SOC infrastructure

Licensing & Vendor Dependency

Review software and firmware licensing models.
Assess vendor lock-in risks.
Identify unnecessary subscription dependencies.
Review long-term system usage rights.
Assess implications for cybersecurity, maintenance and operational continuity.
Deliverables

The Senior Expert will be expected to lead or prepare:

Cybersecurity and IT/OT Architecture Assessment Reports
Executive Summaries
Cybersecurity Risk Registers
Non-Compliance Registers
Risk Criticality Assessments
Mitigation Recommendations
Lists of Missing Documentation
Technical Questions for Project Q&A
Proposed Technical Conditions Precedent
Report updates following receipt of additional project documentation

Reports will primarily be prepared in Polish.

Client Interaction

The role includes:

Participation in technical meetings.
Discussions with technology suppliers and EPC contractors.
Participation in client calls.
Preparation and management of technical Q&A.
Presentation and defence of cybersecurity findings.
Collaboration with electrical engineers, BESS specialists and Technical Due Diligence teams.
Required Experience

We are looking for a senior professional with strong practical experience in industrial cybersecurity.

Candidates should have:

Significant professional experience in OT/ICS cybersecurity.
Experience conducting cybersecurity audits or technical assessments.
Strong understanding of industrial network architecture.
Practical knowledge of ISA/IEC 62443.
Practical knowledge of NIST SP 800-82.
Experience working with SCADA environments.
Knowledge of network segmentation and DMZ/iDMZ architecture.
Understanding of SIEM, IDS/NIDS and vulnerability management platforms.
Ability to independently review complex technical documentation.
Ability to identify, assess and classify cybersecurity risks.
Ability to produce professional technical reports.
Ability to communicate technical findings to both technical and non-technical stakeholders.
Excellent Polish language skills.
Professional working proficiency in English.

Highly Desirable

Experience in one or more of the following would be advantageous:

Energy sector projects.
Battery Energy Storage Systems.
Power generation or grid infrastructure.
Critical infrastructure.
EMS, BMS and PCS systems.
Technical Due Diligence.
Advisory work for investors, banks, utilities or energy companies.
OT/ICS or IEC 62443-related cybersecurity certifications.
What We Offer
Senior responsibility within major energy infrastructure projects.
Work on utility-scale BESS portfolios.
Direct interaction with investors, lenders and energy companies.
International project exposure.
Collaboration with experienced energy-sector engineers.
Flexible cooperation model.
Opportunity to lead and develop KRD Renewables’ OT/ICS cybersecurity capabilities.

About KRD Renewables

KRD Renewables is an independent technical advisory consultancy supporting the development, financing and delivery of renewable energy and energy infrastructure projects.

We work with developers, investors, lenders, utilities and energy companies across:

Battery Energy Storage Systems
Solar PV
Wind Energy
Hybrid Energy Infrastructure

Our services include Technical Due Diligence, Owner’s Engineering, bankability assessments, technical risk analysis and support throughout project financing and investment processes.

Scroll to Top