OT Security Engineer
Key Responsibilities
OT Security & Asset Management
- Discover and maintain inventory of OT assets using non-intrusive monitoring tools.
- Maintain asset registers, network architecture diagrams, and data flow documentation.
- Identify unmanaged devices, network risks, and potential attack paths across IT and OT environments.
- Support security baseline maintenance and architecture reviews.
Security Operations & Monitoring
- Monitor and protect operational technology environments.
- Operate and manage SIEM solutions for threat detection and monitoring.
- Support security incident investigation, response, and remediation activities.
- Coordinate with internal stakeholders and relevant security teams on cybersecurity matters.
Risk Management & Compliance
- Conduct cybersecurity risk assessments and security reviews.
- Ensure compliance with industry security standards, cybersecurity frameworks, and organizational policies.
- Support business continuity and disaster recovery planning and testing.
Vulnerability Management
- Coordinate vulnerability assessments, penetration testing, and security audits.
- Manage patching activities and remediation programs.
- Work closely with infrastructure and application teams to address security findings.
Vendor & Supply Chain Security
- Evaluate third-party hardware, software, and service providers from a security perspective.
- Support vendor security reviews and secure procurement practices.
- Ensure cybersecurity requirements are adhered to by external partners and suppliers.
Security Awareness
- Develop and deliver cybersecurity awareness and training programs.
- Act as a subject matter expert for OT cybersecurity matters.
- Promote security best practices across stakeholders.
Mandatory Requirements
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
- Minimum 5 years of experience in IT Security or OT Security roles.
- Experience in critical infrastructure, government, scientific, industrial, or highly regulated environments.
- Hands-on experience with SIEM platforms, IDS/IPS technologies, and endpoint security solutions.
- Strong understanding of cybersecurity operations, incident response, and threat management.
- Ability to obtain and maintain the required security clearance.
Preferred Skills & Experience
- Experience securing SCADA, ICS, or Operational Technology environments.
- Familiarity with NIST, FISMA, IEC 62443, or similar cybersecurity frameworks.
- Experience supporting 24/7 mission-critical environments.
- Knowledge of cloud security technologies, including AWS or Azure environments.
- Familiarity with environmental monitoring, telemetry, industrial control systems, or similar operational environments.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CEH (Certified Ethical Hacker)
- GICSP (Global Industrial Cyber Security Professional)
- Other relevant cybersecurity certifications