MingYang Smart Energy is a global clean-energy technology company and one of the world’s leading wind turbine manufacturers, delivering integrated solutions across wind power, solar, energy storage, hydrogen, marine energy and smart energy systems. From our European organisation in Hamburg we support the energy transition by combining proven technology, international engineering capability and strong local partnerships.
MingYang Europe is building out its operational technology security capability for the wind assets it delivers and services across Europe. As OT Security Engineer you will own the detection and response side of that capability: investigating security events in SCADA and control system environments, driving patch and vulnerability remediation through to asset-owner approval, and operating the OT monitoring platform that gives us visibility across turbines, plant controllers and remote access paths.
This is a hands‑on engineering role in a small, senior European security function. You will work directly with plant operations, R&D in China, asset owners such as utilities and independent power producers, and our external OT security service provider. It is well suited to someone who wants technical depth in industrial security rather than a purely coordinating position.
An important characteristic of this role: MingYang is a manufacturer and service provider, not the asset owner. Much of your work involves qualifying and recommending change into environments governed by service and maintenance agreements, where the owner holds final approval. Getting technically correct remediation accepted by a utility is as much a part of the job as identifying it.
Key responsibilities
- Investigate and respond to security events affecting OT assets — ICS, SCADA, plant controllers, remote access and OT network infrastructure — including hands‑on triage, containment and forensic support.
- Develop, maintain and exercise OT‑specific incident response playbooks, escalation paths and communication templates, differentiating clearly between MingYang‑operated systems and customer‑owned assets.
- Produce incident documentation and post‑incident reviews, and feed findings into architecture, R&D and service processes.
- Support manufacturer‑side vulnerability handling and incident reporting obligations under the EU Cyber Resilience Act (Art. 13–14), and provide the technical input customers need for their own NIS2 reporting duties.
Patch and vulnerability governance
- Track vulnerabilities affecting MingYang turbine and SCADA components, assess exploitability and operational impact, and prioritise remediation.
- Qualify patches and firmware updates for OT environments — test planning, regression considerations, rollback strategy, maintenance‑window design — balancing security against turbine availability and yield.
- Prepare and present change packages to asset owners for approval where service or maintenance agreements require written owner consent before any modification of SCADA or control systems, and coordinate execution with service teams once approved.
- Maintain the OT asset and software inventory underpinning vulnerability management, in alignment with SBOM data provided by R&D.
OT monitoring and detection engineering
- Configure, operate and continuously improve OT monitoring and SIEM capability — for example Microsoft Sentinel, Microsoft Defender for IoT, Nozomi Networks or Claroty — including sensor placement, asset discovery, use‑case and detection rule development, and alert tuning.
- Define the OT security data that is collected, retained and forwarded, and specify the access model for that data where it is stored centrally. Platform operation of the underlying cloud data storage sits with IT Infrastructure; you define the security requirements and consume the data.
- Manage the technical relationship with our external OT security service provider: onboarding, use‑case backlog, alert quality and service performance.
Standards, assurance and stakeholders
- Contribute to OT security policies, procedures and technical standards, aligned to IEC 62443 (in particular ‑2‑1, ‑2‑4 and ‑3‑3) and to certification commitments already held by MingYang products.
- Support customer security assessments, third‑party audits, risk assessments and emergency exercises for European wind assets.
- Work closely with operations and engineering teams, HQ R&D in China, and customer security organisations at utilities and IPPs.
- Degree, vocational qualification or equivalent professional experience in IT security, computer science, electrical engineering, automation or a related discipline.
- Four or more years in IT or OT security, with at least two years of demonstrable hands‑on work in industrial, energy or other operational technology environments.
- Practical incident response experience — you have personally investigated and contained real security events, not only written procedures for them.
- Working knowledge of industrial protocols and control system architecture (for example Modbus, IEC 61850, OPC UA, DNP3) and of network segmentation and zone/conduit design in OT.
- Solid grasp of patch and change management under availability constraints, including test requirements and rollback planning.
- Familiarity with IEC 62443 and with the EU regulatory landscape for connected products and critical infrastructure (CRA, NIS2, and the national implementations affecting our customers, including German KRITIS obligations on the operator side).
- Fluent English, written and spoken.
- Structured, analytical working style, and the ability to stay effective and communicate clearly under time pressure.
- Experience in the wind industry, renewable generation or turbine technology.
- Hands‑on experience with an OT monitoring platform (Microsoft Defender for IoT, Nozomi, Claroty or comparable) and with SIEM use‑case development.
- Scripting for automation and analysis (PowerShell, Python).
- Working knowledge of Microsoft Azure security services.
- Certifications such as GICSP, GRID, GCIA, CISSP, CISM or comparable.
What we offer
- A genuinely formative role: you will build the European OT incident response and patch governance capability rather than inherit a finished one.
- Direct technical ownership and short decision paths in a small senior team, with visible impact on real generating assets.
- An international environment spanning Europe and Asia, working with major European utilities and independent power producers.
- Meaningful contribution to the energy transition and to the protection of critical renewable‑energy infrastructure.
- Professional development, certification support and conference participation within a fast‑growing global clean‑energy technology company.
#J-18808-Ljbffr
Operational Technology (OT) Security Engineer (m/w/d) in Hamburg Arbeitgeber: Ming Yang Smart Energy
Ming Yang Smart Energy ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern in Hamburg eine dynamische und unterstützende Arbeitsumgebung bietet. Mit einem starken Fokus auf berufliche Weiterentwicklung und Schulungen im Bereich Cybersicherheit fördert das Unternehmen eine Kultur des kontinuierlichen Lernens und der Zusammenarbeit. Die Möglichkeit, an internationalen Projekten zu arbeiten und innovative Sicherheitsarchitekturen zu gestalten, macht diese Position besonders attraktiv für Fachkräfte, die einen bedeutenden Beitrag zur Sicherheit der erneuerbaren Energien leisten möchten.