OT Cybersecurity Compliance Lead – EMEA Projects and Systems
Job Summary
We are looking for an OT Cybersecurity Compliance Lead who will be responsible for driving the cybersecurity of the operational technology (OT) systems delivered within the EMEA region. This covers Dematic systems throughout their lifecycle from solution design and engineering to commissioning handover and ongoing operation. You will work closely with project teams solution engineering customers and suppliers to embed security by design manage cyber risk and ensure that delivered automation systems meet customer requirements company standards and applicable regulations.
As the OT Cybersecurity Compliance Lead you will drive monitor and report on the compliance of OT systems with the EU Cyber Resilience Act and the Machinery Regulation (EU) 2023/1230 and apply ISA/IEC 62443 across projects in order to prevent mitigate and / or detect cyber risks to delivered systems. You will be responsible for system-level security architecture assurance and documentation within dedicated projects a scope distinct from corporate IT security and from product-level cybersecurity which are owned by separate functions.
Career Development
Competitive Compensation And Benefits
Pay Transparency
Global Opportunities
Learn More Here: base pay range for this role at the time of posting is estimated to be the following should this role be filled in the respective country:
Italy: 55125 - 80850(Compensation will be aligned with the applicable National Collective Labour Agreement namely the CBA Metalmeccanico Industria)
Lithuania: 54000 - 79200
Final compensation will be determined by various factors such as work location education experience knowledge and skills.
What youll be responsible for:
Regulatory Compliance (Cyber Resilience Act & Machinery Regulation):
Translate the EU Cyber Resilience Act and Machinery Regulation (EU) 2023/1230 cybersecurity requirements into practical auditable engineering and project requirements for OT systems.
Maintain readiness for the regulatory milestones (CRA vulnerability/incident reporting from September 2026 and full application December 2027; Machinery Regulation from January 2027).
Demonstrate system-level conformity where both regimes apply reusing product-level assurance and closing the remaining integration gaps.
Secure-by-Design across the Project Lifecycle:
Embed OT cybersecurity into the project lifecycle as gated repeatable activities from design and engineering through FAT/SAT commissioning and handover.
Author and review security requirements architecture and risk assessments for bids and live projects and advise project and solution teams.
Produce handover security documentation and the operations and maintenance security baseline inherited by the customer and Dematic Service.
OT Systems & Standards (IEC 62443):
Apply ISA/IEC 62443 across OT systems zones and conduits network segmentation secure remote access hardening patch and backup strategy.
Define reference architectures hardening standards and reusable security building blocks so projects start from a compliant baseline.
Risk Assurance and Testing:
Conduct OT-specific risk assessments security testing and assurance reviews; track findings and mitigations to closure across projects and the installed base.
Support OT security incident readiness and response for delivered systems in coordination with IT Security and the customer.
Stakeholder Collaboration:
Act as the OT cybersecurity point of contact for project engineering quality legal/compliance and customer stakeholders.
Provide guidance and training to project teams on OT security requirements and expectations.
Continuous Improvement:
Capture lessons learned and feed them back into standards reference designs and training.
Help build Dematics OT cybersecurity capability so it scales with the project pipeline.
Compliance:
Ensure compliance with relevant industry standards regulations and company policies.
Participate in internal and external audits as required.
What were looking for:
Bachelors degree in Engineering Automation Computer Science Cybersecurity or a related field (or equivalent practical experience).
Minimum of 5 years of relevant experience in OT / ICS cybersecurity or industrial automation ideally in a systems-integration intralogistics manufacturing or OEM environment.
Working knowledge of ISA/IEC 62443 and OT/ICS security fundamentals (network segmentation hardening secure remote access OT/IT interface).
Familiarity with the EU Cyber Resilience Act and Machinery Regulation (EU) 2023/1230 (and the legacy Machinery Directive 2006/42/EC); awareness of NIS2.
Familiarity with material handling systems automation solutions industrial control technology (PLC SCADA industrial networks) and supply chain logistics.
Proven ability to write and produce technical and compliance reports.
Experience embedding cybersecurity into the project and engineering lifecycle.
Ability to oversee internal and external security and compliance audits.
Strong analytical problem-solving and communication skills.
Ability to work independently and manage multiple projects in a fast-paced environment.
Ability to influence and collaborate with cross-functional teams in an international and matrix organization.
Fluency in English (additional European languages are a plus).
ISA/IEC 62443 certification (e.g. Cybersecurity Fundamentals Risk Assessment or Design Specialist) GICSP or an equivalent OT-security credential is an advantage.
Willingness to travel internationally as required to support the role up to 25% of the time.
About Company
We are a leading supplier of forklifts and warehouse equipment as well as automation technology and software solutions for the optimization of supply chains.