Operational Technology Control Assessor

ECS Federal LLC

DC

JOB DETAILS
SKILLS
Accounting, Analysis Skills, Automation Systems, Best Practices, Business Operations, Change Control, Computer Security, Configuration Management, Continuous Improvement, Control Systems, Corrective Action, Cyber-Physical, Data Recovery, Design Evaluation, Distributed Control Systems (DCS), Documentation Review, Home Automation, ISO (International Organization for Standardization), Incident Response, International Electro-Technical Commission (IEC), Internet Security, Leadership, Network Architecture/Engineering, Operational Audit, Operational Control, Operations Processes, Operations Security (OPSEC), Problem Solving Skills, Process Improvement, Regulatory Requirements, Remote Access, Requirements Management, Risk, Risk Analysis, Risk Management, Safety Compliance, Sales Management, Security Analysis, Software Patches, Supervisory Control and Data Acquisition (SCADA), System Lifecycle, System Operations, Test Requirements, Testing, U.S. National Institute of Standards and Technology (NIST)
LOCATION
DC
POSTED
30+ days ago

Everforth ECS is seeking an OT Control Assessor to work in our Portland,OR office. Please Note: This position is contingent upon contract award.

The Operational Technology (OT) Control Assessor supports the execution of security and risk control assessments across industrial control systems, OT networks, cyber-physical systems, and mission or facility environments. This role evaluates the design, implementation, and operating effectiveness of technical, administrative, and operational controls while accounting for safety, reliability, availability, and operational continuity requirements.

The ideal candidate has hands-on cybersecurity, control assessment, or OT/ICS experience; understands how security controls apply in operational environments; and can conduct evidence-based testing while collaborating with engineers, operators, system owners, and cybersecurity stakeholders.

Key Responsibilities

OT Control Assessment & Testing

  • Perform assessments of security and risk controls across OT systems, industrial control systems, supervisory control and data acquisition environments, distributed control systems, building automation systems, and related support infrastructure.
  • Evaluate control implementation, design effectiveness, and operating effectiveness using approved assessment methodologies and procedures.
  • Execute control testing through interviews, documentation reviews, configuration or architecture reviews, evidence analysis, and validation of operational procedures.
  • Collect, review, and validate assessment evidence while minimizing disruption to production, safety, mission, or facility operations.

OT/ICS Environment Analysis

  • Review OT architecture, network segmentation, data flows, asset inventories, trust boundaries, remote access paths, vendor access, logging coverage, and interfaces between enterprise IT and OT environments.
  • Assess operational practices related to change control, patching, vulnerability management, backup and recovery, incident response, account management, physical access, and configuration management in OT environments.
  • Identify control gaps, compensating controls, operational constraints, and risk tradeoffs that affect OT security, resilience, and mission continuity.

Framework & Standards Alignment

  • Assess OT controls against applicable frameworks, standards, and organizational baselines such as NIST, NIST SP 800-82, IEC 62443, NERC CIP, CIS Controls, ISO 27001/27002, and program-specific requirements.
  • Map OT control implementation and supporting evidence to applicable assessment objectives, regulatory requirements, contractual requirements, and risk management expectations.
  • Distinguish between enterprise IT control expectations and OT-specific constraints, compensating controls, safety requirements, and availability requirements.

Analysis & Documentation

  • Document assessment activities, evidence reviewed, testing approach, assumptions, limitations, and results clearly and accurately.
  • Develop or contribute to OT-focused findings, risk statements, evidence summaries, and remediation recommendations.
  • Support corrective action planning by recommending practical, risk-informed improvements that account for operational feasibility and system lifecycle constraints.
  • Maintain assessment workpapers and artifacts in accordance with program quality, audit-readiness, and evidence-handling expectations.

Stakeholder Collaboration

  • Work with OT engineers, control system operators, system owners, cybersecurity teams, facility personnel, vendors, and business stakeholders to understand control implementation and operational context.
  • Clarify assessment requirements, evidence needs, site coordination requirements, and testing expectations with technical and operational personnel.
  • Support presentations, status updates, and briefings of OT assessment results as requested by assessment leads or program leadership.

Risk, Safety & Compliance Support

  • Apply approved methodologies consistently to ensure assessment results are accurate, repeatable, defensible, and sensitive to safety and operational priorities.
  • Escalate significant control gaps, evidence limitations, safety concerns, availability impacts, or cyber-physical risk issues to assessment leadership.
  • Support audit readiness, compliance reporting, risk register updates, remediation tracking, and follow-up assessment activities for OT environments.

Continuous Improvement

  • Assist with improving OT assessment methodologies, checklists, templates, tools, evidence requests, and reporting processes.
  • Participate in lessons-learned activities, reassessments, and process improvement initiatives.
  • Stay current with evolving OT cybersecurity threats, control frameworks, regulatory requirements, assessment practices, and industry best practices.

About the Company

E

ECS Federal LLC

ECS was founded in 2001 by experienced IT professionals with a commitment to quality processes, people and performance. Led by our Chairman, Roy Kapani, and an experienced executive leadership team, ECS provides our customers with solutions and services that support their critical needs and further mission objectives. This commitment has paved the way for expansive growth, year over year.

ECS gained market share in 2011 in the Department of Defense and Federal spaces through both organic and acquisition growth. In May, ECS completed its first strategic acquisition with the purchase of OAK Management, Inc., a leading provider of marine environmental services, ship systems engineering, maritime consulting and platform acquisition management. The OAK acquisition kicked off ECS’ intention to add tactical acquisitions as a part of its long term strategy to supplement and expand upon organic growth and to build enterprise value. ECS closed out 2011 with the acquisition of Paradigm Technologies, Inc. The Paradigm transaction added approximately 200 employees to ECS’ existing 900+ employees. Paradigm also added new Defense clients for ECS, including the Missile Defense Agency, the Navy’s Program Executive Officer for Integrated Warfare Systems, the United States Marine Corps, and the U.S. Marshals Service.

In 2012, ECS completed the acquisition of iLuMinA Solutions, Inc. iLuMinA brings large-scale Enterprise Resource Planning (ERP) software implementation and infrastructure design and development to ECS’ expanding capabilities.

ECS will continue to invest in corporate infrastructure and quality processes as we grow and enhance our ability to offer professional excellence to both our customers and our employees.

COMPANY SIZE
50 to 99 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2000
WEBSITE
http://www.ecs-federal.com/

Similar Job Searches