Job Description
Indent :SF_OP_203802-1-4
Role : OT/ICS Security LeadLocation : Boston, MA (Hybrid)
Rate : $80/hr – $85/hrAbout the position- Lead and execute OT/ICS cybersecurity activities across multiple industrial sites ( customer sites)
- Focus on industrial security assessment, segmentation, and risk reduction
- Ensure OT environments are:
- Secure
- Stable
- Aligned to IEC 62443 and NIST standards
- Work closely with plant operations, engineering teams, and IT security teams
- Deliver practical, implementable solutions without impacting production
What you'll doKey Responsibilities1. OT/ICS Security Assessment- Site visit and Conduct end-to-end OT security assessments across plants / operational sites ( apprx.10 sites)
- Perform:
- Asset discovery (PLCs, SCADA, HMI, network devices)
- Network architecture reviews
- Vulnerability identification
- Identify:
- Control gaps
- Exposures and attack surfaces
- Legacy system risks
- Perform gap analysis aligned to IEC 62443 / NIST SP 800-82 frameworks
- Deliver:
- OT baseline reports
- Risk findings and recommendations
2. OT Network Architecture & Segmentation- Design OT network segmentation using Purdue Model (zones & conduits)
- Define:
- IT–OT DMZ architecture
- Secure communication pathways
- Trust boundaries between systems
- Recommend:
- Firewall placement
- Network isolation strategies
- Ensure:
- Industrial safety is not impacted
- uptime and operational continuity are maintained
3. Industrial Cyber Risk Management- Identify risks across:
- PLCs
- SCADA systems
- Industrial protocols
- Vendor remote access
- Analyze:
- Operational impact
- Safety risks
- Business criticality
- Maintain and update:
- OT risk register
- Risk prioritization matrix
- Provide:
- Risk mitigation strategies
- Residual risk recommendations
4. Security Controls & Hardening- Define and recommend OT-specific security controls, including:
- Network segmentation
- Access control (RBAC, vendor access)
- Monitoring & logging
- Design compensating controls for:
- Legacy PLC/SCADA systems
- Systems that cannot support endpoint agents
- Ensure controls are:
- Practical
- Deployable with minimal disruption
5. OT Monitoring & Threat Detection- Deploy and tune OT monitoring tools:
- Perform:
- Network traffic analysis
- Protocol-level inspection
- Detect:
- Anomalies
- Lateral movement risks
- Unauthorized access
- Integrate OT monitoring insights with IT security systems where feasible
6. Remediation & Technical Debt Reduction- Develop OT remediation roadmap based on findings
- Define:
- Short-term mitigations
- Long-term improvements
- Track:
- Remediation actions
- Owners and timelines
- Support:
- Technical debt reduction
- Migration to secure baseline architecture
7. Site-Level Engagement & Coordination- Work closely with:
- Plant managers
- OT engineers
- Maintenance and automation teams
- Align security solutions with:
- Operational processes
- Maintenance windows
- Safety requirements
- Conduct:
- Workshops
- Site walkthroughs
- Stakeholder discussions
8. Industrial Security Standards & Compliance- Ensure alignment with:
- Support:
- Compliance assessments
- Audit readiness
- Map controls to:
- Industry standards
- Organizational security baselines
Key Deliverables - OT asset discovery and baseline report
- Industrial risk assessment and mitigation plan
- Purdue-based segmentation design
- Security control recommendations
- Remediation roadmap and tracking
- Reduced OT cybersecurity risk across sites
What you'll bringCore OT Security Skills- Hands-on experience with:
- PLC, SCADA, DCS, ICS systems
- Strong knowledge of:
- Industrial network protocols
- OT attack vectors and threats
Technical Expertise- Frameworks:
- IEC 62443
- NIST CSF / SP 800-82
- Architecture:
- Purdue Model
- Zone–conduit segmentation
- Tools:
- Armis / Claroty / Nozomi / Dragos
- OT monitoring & network visibility tools
Industrial Domain Knowledge- Experience in:
- Healthcare / pharma /
- Manufacturing / process plants
- Understanding of:
- Safety systems
- Production-critical operations
Soft & Functional Skills- Strong problem-solving and analytical thinking
- Ability to work with cross-functional OT + IT teams
- Strong communication skills for:
- Technical and non-technical stakeholders
Preferred Certifications- GICSP (Global Industrial Cyber Security Professional)
- ISA/IEC 62443 Certification
- CISSP / CISM (optional but beneficial)
Numbers & Facts
| Location | Alexandria, VA |
| Salary | $80–$85 Per Hour |
Skills
Access Controlunmatched
Analysis Skillsunmatched
Automationunmatched
Biotech and Pharmaceuticalunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Communication Skillsunmatched
Computer Securityunmatched
Cross-Functionalunmatched
DMZunmatched
Distributed Control Systems (DCS)unmatched
Firewallsunmatched
Gap Analysisunmatched
Healthcareunmatched
Human Machine Interface (HMI)unmatched
ISA Standardsunmatched
Industrial Managementunmatched
Industry Standardsunmatched
Information Technology & Information Systemsunmatched
International Electro-Technical Commission (IEC)unmatched
Internet Securityunmatched
Manufacturing/Industrial Processesunmatched
Network Architecture/Engineeringunmatched
Network Designunmatched
Network Monitoringunmatched
Network Protocolsunmatched
Network Traffic Analysisunmatched
Operations Processesunmatched
Plant Managementunmatched
Problem Solving Skillsunmatched
Programmable Logic Controller (PLC)unmatched
Remote Accessunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Safety Systemsunmatched
Safety Trainingunmatched
Security Analysisunmatched
Supervisory Control and Data Acquisition (SCADA)unmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Level up your application
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder