OT Senior Security Engineer (IT & OT Vulnerability Assessment)
Technology
Job Description
Role - OT Senior Security Engineer (IT & OT Vulnerability Assessment)
\n
Location - San Diego - Onsite Role
\n
Architecture, asset inventory and existing controls:
\n
\n
- \n
- Review the OT/IT architecture, network diagrams and data flows across the treatment plant, pump/lift stations, reservoirs and remote telemetry sites.
- Identify vulnerabilities, misconfigurations and security gaps across PLCs, SCADA systems, HMIs, servers, workstations, network devices and field assets.
- Review device hardening: default credentials, open services, insecure protocols, firmware versions and controller key-switch or mode settings.
\n
\n
\n
\n
\n
Network segmentation and boundary security
\n
\n
- \n
- Evaluate network segmentation, switches, routers and firewall rules against the Purdue model and IEC 62443 zones and conduits.
- Assess OT/IT boundary security, the DMZ design and any direct paths between the business network and control systems.
- Review inter-site communications (radio, cellular, fiber, MPLS/VPN links to remote stations) for encryption, segmentation and exposure.
\n
\n
\n
\n
\n
Remote, vendor and wireless access
\n
\n
- \n
- Review remote access, authentication and access management controls, including VPNs, jump hosts, MFA and privileged accounts.
- Assess vendor and integrator access: onboarding/offboarding, shared accounts, session monitoring and time-bound access.
- Identify wireless connectivity risks, rogue access points, cellular modems and unmanaged remote access tools.
\n
\n
\n
\n
\n
Lifecycle and patch management
\n
\n
- \n
- Identify unsupported and end-of-life assets (operating systems, PLC firmware, HMI software, network gear).
- Evaluate patch management practices and gaps, and recommend compensating controls where patching is not feasible.
\n
\n
\n
\n
Governance and operational practices
\n
\n
- \n
- Evaluate change management, configuration management and backup/recovery practices for control system logic and configs.
- Review access control practices, including role-based access, account reviews and separation of duties.
\n
\n
\n
\n
Reporting and roadmap
\n
\n
- \n
- Rate findings by risk, weighing likelihood against impact on public health, water quality and plant operations.
- Deliver a prioritized remediation roadmap with actionable recommendations, split into quick wins, medium-term and strategic items.
- Present results to plant operations, IT and utility leadership in both technical and executive formats.
\n
\n
\n
\n
\n
Required qualifications
\n
\n
- \n
- Bachelor's degree in Cybersecurity, Computer/Electrical Engineering, Information Technology or a related field, or equivalent experience.
- 6+ years in cybersecurity, including at least 3 years hands-on with OT/ICS environments.
- Has run at least two OT security assessments end to end, from scoping through the final report.
- Hands-on knowledge of PLCs, RTUs, HMIs and SCADA platforms common in U.S. water utilities (for example Rockwell/Allen-Bradley, Schneider Electric, Siemens, GE, Inductive Automation Ignition, AVEVA/Wonderware).
- Strong networking skills: VLANs, routing, firewall rulebase review (Palo Alto, Fortinet, Cisco), VPNs and industrial switches.
- Familiar with IEC 62443, NIST SP 800-82 and the NIST Cybersecurity Framework.
- Strong report writing, with the ability to turn technical findings into a clear roadmap for executives.
\n
\n
\n
\n
\n
\n
\n
\n
\n
Preferred qualifications and certifications
\n
\n
- \n
- Experience in the water/wastewater sector, ideally including AWIA Section 1433 risk and resilience assessments or emergency response plans.
- Familiar with treatment processes (intake, filtration, chemical dosing, disinfection, distribution) and the safety impact of control failures.
- Experience with remote telemetry: licensed radio, cellular gateways and SCADA polling of lift and pump stations.
- Hands-on with OT monitoring platforms and assessment tooling (see Frameworks and tools).
- Certifications (one or more preferred):
- GIAC GICSP, GRID or GCIP
- ISA/IEC 62443 Cybersecurity Expert or Risk Assessment Specialist
\n
\n
\n
\n
\n
\n
\n
\n
