About this role
The OT Security Engineer will develop and execute OT security strategy across ICS, SCADA, DCS, PLC, RTU, and HMI environments. They will drive risk assessments, network segmentation (including DMZ), secure remote access, and OT incident response while aligning with IEC 62443, NERC CIP, and NIST SP 800-82.
Key Responsibilities
- Develop and execute OT security strategy covering ICS, SCADA, DCS, PLC, RTU, and HMI environments
- Conduct OT-specific risk assessments, asset inventories, and vulnerability management
- Design and implement OT network segmentation, demilitarized zones (DMZ), and secure remote access solutions
- Lead OT incident response activities including detection, containment, forensics, and recovery
- Monitor OT/ICS networks using specialized tools (Claroty, Dragos, Nozomi, Fortinet OT, etc.)
Technical Overview
This role focuses on OT/ICS cybersecurity including protocol-level knowledge (Modbus, DNP3, PROFINET, OPC-UA, EtherNet/IP, BACnet), monitoring via Claroty/Dragos/Nozomi/Fortinet OT, and incident response workflows. The engineer will design OT network segmentation using Purdue model architectures and ensure secure IT/OT integration while performing threat modeling and red/blue team exercises.
Ideal Candidate
The ideal candidate is an OT/ICS cybersecurity professional with 4–5+ years of hands-on experience securing industrial control systems and critical infrastructure. They can design OT network segmentation and DMZ architectures, lead OT incident response from detection through recovery, and demonstrate deep protocol knowledge across Modbus, DNP3, PROFINET, OPC-UA, EtherNet/IP, and BACnet.
Must-Have Skills
Operational Technology (OT) Security EngineerMinimum 4–5 years of dedicated experience in OT/ICS cybersecurity.Comprehensive understanding of OT protocols: ModbusDNP3PROFINETOPC-UAEtherNet/IPBACnet.Hands-on experience with ICS/SCADA platforms (SiemensHoneywellABBRockwellSchneider ElectricGE).Strong knowledge of OT security frameworks: IEC 62443NIST SP 800-82NERC CIP.Experience designing OT network segmentationpurdue model architecturesand secure IT/OT integration.Familiarity with OT-specific security monitoring and asset discovery tools.Solid understanding of both IT security concepts and OT operational constraints.
Nice-to-Have Skills
Certified GIAC Global Industrial Cyber Security Professional (GICSP)ISA/IEC 62443 Cybersecurity Certificatecritical infrastructure sectors: energyutilitiesoil & gasmanufacturingor watercloud-connected OT environments and IIoT securityregulatory environments (NERC CIPTSA PipelineNRCetc.)OT penetration testing or red team assessments
Tools & Platforms
ClarotyDragosNozomiFortinet OTIEC 62443NERC CIPNIST SP 800-82ModbusDNP3PROFINETOPC-UAEtherNet/IPBACnetSiemensHoneywellABBRockwellSchneider ElectricGE
Required Skills
Operational Technology (OT) SecurityIndustrial control systems (ICS)SCADADCSPLCRTUHMIModbusDNP3PROFINETOPC-UAEtherNet/IPBACnetOT network segmentationdemilitarized zones (DMZ)secure remote accessOT incident responseClarotyDragosNozomiFortinet OTIEC 62443NERC CIPNIST SP 800-82threat modellingred/blue team exercisesasset discoveryasset inventoriesvulnerability management
Hard Skills
Operational Technology (OT) SecurityIndustrial control systems (ICS)SCADADCSPLCRTUHMIOT security strategyrisk assessmentsasset inventoriesvulnerability managementOT network segmentationdemilitarized zones (DMZ)secure remote accessOT incident responsedetectioncontainmentforensicsrecoveryOT/ICS network monitoringClarotyDragosNozomiFortinet OTIEC 62443NERC CIPNIST SP 800-82threat modellingred/blue team exercisesModbusDNP3PROFINETOPC-UAEtherNet/IPBACnetICS/SCADA platformsSiemensHoneywellABBRockwellSchneider ElectricGEpurdue model architecturessecure IT/OT integrationasset discoveryOT-specific security monitoringOT security policiesOT change management processsecurity awareness programs
Soft Skills
bridge IT and OT environmentspartner with engineeringpartner with operationspartner with IT teamslead incident response activitiesthreat modeling collaborationdevelop security policies and procedurestrain operational staffcommunicate security strategy and architecturelead technical exercises
Certifications
Preferred
GIAC Global Industrial Cyber Security Professional (GICSP)ISA/IEC 62443 Cybersecurity Certificate
Keywords for Your Resume
OT Security EngineerOperational Technology (OT) Security EngineerOT/ICS cybersecurityIndustrial control systems (ICS)SCADADCSPLCRTUHMIIEC 62443NERC CIPNIST SP 800-82ModbusDNP3PROFINETOPC-UAEtherNet/IPBACnetOT network segmentationdemilitarized zones (DMZ)secure remote accessOT incident responseClarotyDragosNozomiFortinet OTpurdue model architectures
Deal Breakers
Must have 4–5 years of dedicated experience in OT/ICS cybersecurity, Must have comprehensive understanding of OT protocols (Modbus, DNP3, PROFINET, OPC-UA, EtherNet/IP, BACnet), Must have hands-on experience with ICS/SCADA platforms (Siemens, Honeywell, ABB, Rockwell, Schneider Electric, GE)
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile