Overview
The OT Security Engineer will play a crucial role in conducting hands-on technical assessments for operational technology (OT) security within industrial environments. They will collaborate with OT security architects, engineering teams, and technology vendors to gather and document evidence that supports architecture decisions and improve security posture in complex, multi-vendor environments.
Responsibilities
- Gather and document evidence for OT security capabilities and controls.
- Conduct hands-on configuration, security, and capability reviews across plant and shared IT/OT environments.
- Validate the technical and operational viability of OT security capabilities, including OEM, regulatory, and connectivity considerations.
- Provide technical verification to support reuse, extend, and new architecture decisions.
- Identify security gaps and constraints where evidence or technical requirements cannot be fully validated.
- Maintain clear evidence, findings, gap analysis, and constraint documentation.
- Translate technical findings into actionable outcomes in collaboration with stakeholders.
Requirements
- Hands-on OT/ICS security engineering experience in industrial or critical infrastructure environments.
- Strong practical knowledge of NIST SP 800-82, the Purdue Model, and IEC 62443.
- Experience conducting OT security assessments, configuration reviews, and capability gap analysis.
- Familiarity with OEM security tooling and constraints affecting OT security deployments.
- Strong technical documentation and evidence-gathering skills.
- Comfortable working independently within complex, multi-vendor OT environments.
- Experience in manufacturing, pharmaceutical, or life sciences OT environments is desirable.
- Certification in ISA/IEC 62443 or equivalent is also desirable.