Search

OT Senior Security Engineer (IT & OT Vulnerability Assessment)

PublishedPublished: 6/14/2022
Technology

Job Description

Role - OT Senior Security Engineer (IT & OT Vulnerability Assessment)

\n

Location - San Diego - Onsite Role

\n

Architecture, asset inventory and existing controls:

\n


\n

    \n
  • Review the OT/IT architecture, network diagrams and data flows across the treatment plant, pump/lift stations, reservoirs and remote telemetry sites.
  • \n

  • Identify vulnerabilities, misconfigurations and security gaps across PLCs, SCADA systems, HMIs, servers, workstations, network devices and field assets.
  • \n

  • Review device hardening: default credentials, open services, insecure protocols, firmware versions and controller key-switch or mode settings.
  • \n

\n


\n

Network segmentation and boundary security

\n


\n

    \n
  • Evaluate network segmentation, switches, routers and firewall rules against the Purdue model and IEC 62443 zones and conduits.
  • \n

  • Assess OT/IT boundary security, the DMZ design and any direct paths between the business network and control systems.
  • \n

  • Review inter-site communications (radio, cellular, fiber, MPLS/VPN links to remote stations) for encryption, segmentation and exposure.
  • \n

\n


\n

Remote, vendor and wireless access

\n


\n

    \n
  • Review remote access, authentication and access management controls, including VPNs, jump hosts, MFA and privileged accounts.
  • \n

  • Assess vendor and integrator access: onboarding/offboarding, shared accounts, session monitoring and time-bound access.
  • \n

  • Identify wireless connectivity risks, rogue access points, cellular modems and unmanaged remote access tools.
  • \n

\n


\n

Lifecycle and patch management

\n


\n

    \n
  • Identify unsupported and end-of-life assets (operating systems, PLC firmware, HMI software, network gear).
  • \n

  • Evaluate patch management practices and gaps, and recommend compensating controls where patching is not feasible.
  • \n

\n


\n

Governance and operational practices

\n


\n

    \n
  • Evaluate change management, configuration management and backup/recovery practices for control system logic and configs.
  • \n

  • Review access control practices, including role-based access, account reviews and separation of duties.
  • \n

\n


\n

Reporting and roadmap

\n


\n

    \n
  • Rate findings by risk, weighing likelihood against impact on public health, water quality and plant operations.
  • \n

  • Deliver a prioritized remediation roadmap with actionable recommendations, split into quick wins, medium-term and strategic items.
  • \n

  • Present results to plant operations, IT and utility leadership in both technical and executive formats.
  • \n

\n


\n

Required qualifications

\n


\n

    \n
  • Bachelor's degree in Cybersecurity, Computer/Electrical Engineering, Information Technology or a related field, or equivalent experience.
  • \n

  • 6+ years in cybersecurity, including at least 3 years hands-on with OT/ICS environments.
  • \n

  • Has run at least two OT security assessments end to end, from scoping through the final report.
  • \n

  • Hands-on knowledge of PLCs, RTUs, HMIs and SCADA platforms common in U.S. water utilities (for example Rockwell/Allen-Bradley, Schneider Electric, Siemens, GE, Inductive Automation Ignition, AVEVA/Wonderware).
  • \n

  • Strong networking skills: VLANs, routing, firewall rulebase review (Palo Alto, Fortinet, Cisco), VPNs and industrial switches.
  • \n

  • Familiar with IEC 62443, NIST SP 800-82 and the NIST Cybersecurity Framework.
  • \n

  • Strong report writing, with the ability to turn technical findings into a clear roadmap for executives.
  • \n

\n


\n

Preferred qualifications and certifications

\n


\n

    \n
  • Experience in the water/wastewater sector, ideally including AWIA Section 1433 risk and resilience assessments or emergency response plans.
  • \n

  • Familiar with treatment processes (intake, filtration, chemical dosing, disinfection, distribution) and the safety impact of control failures.
  • \n

  • Experience with remote telemetry: licensed radio, cellular gateways and SCADA polling of lift and pump stations.
  • \n

  • Hands-on with OT monitoring platforms and assessment tooling (see Frameworks and tools).
  • \n

  • Certifications (one or more preferred):
  • \n

  • GIAC GICSP, GRID or GCIP
  • \n

  • ISA/IEC 62443 Cybersecurity Expert or Risk Assessment Specialist
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...