OT Security Resident Engineer
Indexed description
OT Security Resident Engineer
Core Responsibilities
Design and Strategic Planning
- Define and evolve the enterprise OT security architecture, reference models, security zones, conduits, and trust boundaries (e.g., Purdue Model / ISA-95) for new and existing plants and sites.
- Set architecture standards for firewalls, segmentation, remote access, and secure protocols; lead architecture reviews and risk assessments for OT projects.
- Own and evolve the OT security roadmap and target-state architecture.
Technical Security Implementation
- Translate architecture into low-level designs (LLDs) and implementation guides; engineer firewalls, IDS/IPS, NAC, endpoint protection, secure remote access, and OT monitoring tools (e.g., Claroty, Nozomi, Dragos).
- Define secure configuration/hardening baselines for PLCs, RTUs, HMIs, engineering workstations, and historians; design logging, SIEM integration, and asset visibility solutions.
- Lead vulnerability assessments and patch management strategy; design backup, recovery, and restoration architecture, including secure air-gapped backups and removable media/USB controls.
Network Infrastructure Planning
- Design segmented, resilient OT networks (Purdue Levels 0-5), including VLAN structures, routing, and redundancy/failover mechanisms.
- Architect secure IT/OT interconnection (industrial DMZ, data diodes, one-way gateways) and secure wireless, remote, and third-party/vendor connectivity.
- Validate designs through diagrams, data flow mapping, and threat modelling; define time synchronization, redundancy protocols (PRP/HSR, RSTP), and real-time traffic requirements.
Governance and Regulatory Alignment
- Lead OT cybersecurity risk assessments, identify gaps, and define remediation strategies.
- Ensure architecture and deployments align with regulatory, industry, and corporate compliance requirements; support audits and certifications.
- Define security levels (SL-T) and zone/conduit requirements per IEC 62443, and track control gaps to closure.
System Integration and Interoperability
- Define integration architecture across firewalls, switches, SIEM/SOC, NMS, PAM, and other cybersecurity infrastructure.
- Ensure interoperability and data flow standards between OT security tools and enterprise/IT security platforms.
- Conduct post-incident architecture reviews, feeding lessons learned into architecture standards and control design.
Documentation
- Own and maintain architecture blueprints, design standards, reference diagrams, and configuration baselines.
- Establish templates for HLD/LLD, network diagrams, port matrices, and as-built documentation.
Stakeholder & Vendor Management
- Act as senior technical authority for OT cybersecurity architecture across OT operations, IT, SOC, engineering, and OEM/vendor teams.
- Lead architecture and design review boards; present and defend design decisions to stakeholders and leadership.
- Manage OEM/vendor relationships and embed security requirements into RFPs, contracts, and integrator scopes of work.
Knowledge Transfer
- Provide technical mentorship to site teams on architecture and design best practices.
- Develop training material and lead knowledge-transfer sessions to build OT security capability.
- Foster a security-aware culture across OT operations and engineering staff through awareness and training.
Skills & Experience
- 6+ years in cybersecurity, with strong OT/ICS security architecture and industrial network security experience
- Skilled in network security: firewalls, routing/switching, VLANs, segmentation, IDS/IPS, VPN, secure remote access
- Experience with SIEM/SOC solutions, including logging, monitoring, alerting, and OT use cases
- Experience with OT security monitoring/asset visibility tools (Nozomi Networks preferred; Claroty, Dragos also acceptable)
Certifications (Preferred)
- GICSP, IEC 62443, or CISSP
- CCNA/CCNP Security or equivalent
- Nozomi Networks (NNCE) or equivalent OT platform training
- Fortinet, Cisco, or equivalent firewall/network security certification
- Splunk, Microsoft Sentinel (SC-200), QRadar, or equivalent SIEM certification
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search