OT Security Consultant - Cyber Risk - Level 4
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Krollâs Cyber Risk practice is seeking a contractor-level Operational Technology (OT) Security Architect at the Senior Manager level to support delivery of large-scale OT Security programs across North America, with primary project focus out of the San Francisco, CA area. This role serves as the technical lead for OT Security implementation engagements, with core responsibility for deploying and operationalizing OT monitoring solutions, designing secure OT network architectures, supporting network segmentation initiatives, and enabling continuous monitoring capabilities within critical infrastructure environments., The ideal candidate brings hands-on Nozomi Networks Guardian experience, deep fluency in IEC 62443 and NIST SP 800-82, and a delivery-oriented track record working directly alongside engineering, operations, networking, and cybersecurity teams in industrial environments. Experience in the rail transportation sector is strongly preferred.
Key ResponsibilitiesOT Monitoring Deployment and Operationalization
¡ Lead deployment, configuration, and operationalization of Nozomi Networks Guardian within industrial and critical infrastructure environments.
¡ Configure and tune OT monitoring policies, asset classification, alerting, dashboards, and reporting within Nozomi.
¡ Perform OT asset discovery validation and communication mapping using passive monitoring techniques.
¡ Develop monitoring use cases, operational playbooks, and deployment standards for scalable OT monitoring programs.
¡ Support integration of Nozomi with enterprise Security Information and Event Management (SIEM), Security Operations Center (SOC), Managed Detection and Response (MDR), and ticketing platforms.
OT Network Architecture and Segmentation
¡ Design and document OT network architectures, including security zones, conduits, industrial Demilitarized Zones (DMZs), remote access, and secure IT/OT connectivity.
¡ Review OT network topology and communication flows to support network segmentation and modernization initiatives.
¡ Apply strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.
¡ Align architecture design with IEC 62443 zones-and-conduits model and NIST SP 800-82 guidance.
Documentation and Reporting
¡ Produce architecture diagrams, implementation documentation, technical reports, and executive-ready summaries.
¡ Develop and maintain deployment standards, runbooks, and delivery accelerators for repeatable program execution.
¡ Communicate technical findings and recommendations to both engineering-level and executive stakeholders.
Stakeholder Engagement and Program Delivery
¡ Work closely with engineering, operations, networking, and cybersecurity stakeholders throughout all implementation activities.
¡ Balance cybersecurity requirements with operational and engineering realities in industrial environments.
¡ Travel to client sites as required to support on-site delivery phases.
Mentorship and Practice Development
¡ Mentor junior consultants on OT implementation methodologies and technical practices.
¡ Contribute to Krollâs OT delivery templates, standards, and practice accelerators.
Requirements
Education: Bachelorâs degree in Cybersecurity, Information Technology, Instrumentation, Engineering, or a related field. Four or more additional years of relevant hands-on experience accepted in lieu of degree.
Experience: Minimum 8 years of cybersecurity experience, including 5 or more years focused on Operational Technology (OT) security.
Required Qualifications
¡ Hands-on experience with Nozomi Networks Guardian deployment and configuration; Nozomi Networks Certified Engineer (NNCE) certification is a plus.
¡ Demonstrated experience delivering OT Security implementation projects within industrial or critical infrastructure environments.
¡ Experience implementing OT monitoring solutions using passive network monitoring techniques.
¡ Strong understanding of IEC 62443 and NIST SP 800-82.
¡ Experience supporting OT network segmentation and secure OT architecture design.
¡ Strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.
¡ Strong analytical and problem-solving skills in industrial network environments.
¡ Excellent written and verbal communication skills, including ability to present to executive stakeholders.
¡ Ability to work independently and collaboratively with cross-functional engineering and operational teams.
¡ Willingness to travel to client sites as required.
Desired Skills
¡ Experience in the rail transportation or transit sector.
¡ Experience integrating OT monitoring platforms with enterprise SIEM, SOC, or MDR environments.
¡ Familiarity with ISA/IEC 62443 Security Level assessments and zone/conduit documentation.
¡ Experience with industrial DMZ architecture and IT/OT network separation design.
¡ Prior consulting delivery experience in a professional services or advisory context.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Best Companies to work for in London: Top 25 Companies in 2023
Best Paying Jobs in Technology