Sr Engineer
MAIN DUTIES AND RESPONSIBILITIES
SPECIFIC
- Maintain a comprehensive and up-to-date inventory of all operational technology (OT) assets and submit this list monthly to the NHG MDOT taskforce.
- Track devices across their full product lifecycle — procurement, deployment, operation, maintenance, and decommissioning.
- Advise both technically and in layman terms to both internal and external stakeholders, the technical essence and nature of potential and associated cybersecurity risks for facilities M&E systems and equipment.
- Perform risk assessments together with the trades and their vendors for devices at different lifecycle stages to identify vulnerabilities.
- Devise solutions and methods to mitigate such risks to negotiate and see through with vendors directly to effect good outcomes and balance between strict compliance and operational needs.
- Oversee, report, account and ensure progress per the workgroup committee directives and requirements to FE fulfilment of its respective MDOTs target goals, including representing FE in such workgroups to front TTSH FE efforts and present achieved results in such endeavours to management.
- Ensure vendor and third-party compliance during acquisition, onboarding, and decommissioning of devices.
- Coordinate with the trades and their vendors to deploy and manage firewalls, intrusion detection/prevention systems and anomaly detection tools for OT networks.
- Coordinate with the trades and their vendors to implement network segmentation and access controls to protect devices from external and internal threats according to Healthtech Instruction Manual (HIM) policy requirements.
- Coordinate with device manufacturers/vendors to ensure security updates and patches are applied in a timely manner otherwise ensure device manufacturers/vendors submit deviations for approval.
- Participate in the identification, reporting, and investigation of OT security incidents
- Support root cause analysis and recommend corrective/preventive measures.
- Ensure compliance with HIM’s incident escalation and reporting framework.
- Assist in business continuity planning and system recovery procedures to minimize downtime of critical devices.
- Carry out periodic internal audits and prepare for external audits or regulatory inspections.
- Document with Works instructions (WI) and update standard operating procedures (SOPs) for device security and risk management.
- Liaise with vendors and contractors to validate their compliance with HIM, cybersecurity, and hospital-specific requirements.
- Provide technical guidance and training to trade engineers and technicians on secure use and handling of devices.
GENERAL
- Assist the Department in drafting of policies, procedures, work instructions and continuous improvements.
- Any other duties as assigned.
- Inculcate a working environment of collegiality and effective teamwork.