Required Skills: OT Security, ICS Security, OT Cybersecurity, ICS cybersecurity, Industrial automation, OT vulnerability assessments, IT vulnerability assessments, ICS Architecture, OT architecture, Purdue Model, IEC 62443, NIST 800-82, Industrial Control Systems, PLC, SCADA, HMI, Engineering workstations
Job Description
OT Security Engineer (IT & OT Vulnerability Assessment)
Key Responsibilities:
- Perform onsite OT Vulnerability Assessments across industrial environments.
- Conduct vulnerability scanning and risk assessments for both OT and IT assets.
- Utilize OT security tools such as Nozomi, Claroty, Tenable.ot, Microsoft Defender for IoT, etc.
- Perform IT vulnerability assessments using Nessus Professional, Qualys, Rapid7, etc.
- Review industrial networks, PLCs, SCADA, HMIs, engineering workstations, servers, and network devices.
- Prepare assessment reports, risk ratings, remediation recommendations, and executive summaries.
- Present findings and recommendations to client stakeholders and management teams.
- Coordinate with plant operations, automation, and IT teams during assessments.
Required Skills & Experience
- 8+ years of experience in OT/ICS Cybersecurity and Industrial Automation.
- Hands-on experience with PLC, SCADA, HMI Programming and Commissioning.
- Strong understanding of ICS/OT architectures, Purdue Model, IEC 62443, and NIST 800-82.
- Experience performing OT Vulnerability Assessments in manufacturing, utilities, energy, mining, or critical infrastructure environments.
- Hands-on experience with:
- Nozomi Networks
- Claroty
- Tenable.ot
- Experience conducting IT Vulnerability Assessments using:
- Nessus Professional
- Qualys
- Rapid7
- Knowledge of industrial protocols such as Modbus, DNP3, OPC-UA, Ethernet/IP, and Profinet.
- Strong report writing, presentation, and client-facing communication skills.
Preferred Certifications