OT Security Consultant - Cyber Risk - Level 4

Kroll Inc
San Francisco, CA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$200,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Monitoring of Systems Network Topologies Network Architecture Network Monitoring Routing Network Segmentation Remote Access Technology Security Information and Event Management Virtual Local Area Networks Information Technology Operational Systems

Job description

Kroll’s Cyber Risk practice is seeking a contractor-level Operational Technology (OT) Security Architect at the Senior Manager level to support delivery of large-scale OT Security programs across North America, with primary project focus out of the San Francisco, CA area. This role serves as the technical lead for OT Security implementation engagements, with core responsibility for deploying and operationalizing OT monitoring solutions, designing secure OT network architectures, supporting network segmentation initiatives, and enabling continuous monitoring capabilities within critical infrastructure environments., The ideal candidate brings hands-on Nozomi Networks Guardian experience, deep fluency in IEC 62443 and NIST SP 800-82, and a delivery-oriented track record working directly alongside engineering, operations, networking, and cybersecurity teams in industrial environments. Experience in the rail transportation sector is strongly preferred.

Key ResponsibilitiesOT Monitoring Deployment and Operationalization

¡ Lead deployment, configuration, and operationalization of Nozomi Networks Guardian within industrial and critical infrastructure environments.

¡ Configure and tune OT monitoring policies, asset classification, alerting, dashboards, and reporting within Nozomi.

¡ Perform OT asset discovery validation and communication mapping using passive monitoring techniques.

¡ Develop monitoring use cases, operational playbooks, and deployment standards for scalable OT monitoring programs.

¡ Support integration of Nozomi with enterprise Security Information and Event Management (SIEM), Security Operations Center (SOC), Managed Detection and Response (MDR), and ticketing platforms.

OT Network Architecture and Segmentation

¡ Design and document OT network architectures, including security zones, conduits, industrial Demilitarized Zones (DMZs), remote access, and secure IT/OT connectivity.

¡ Review OT network topology and communication flows to support network segmentation and modernization initiatives.

¡ Apply strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.

¡ Align architecture design with IEC 62443 zones-and-conduits model and NIST SP 800-82 guidance.

Documentation and Reporting

¡ Produce architecture diagrams, implementation documentation, technical reports, and executive-ready summaries.

¡ Develop and maintain deployment standards, runbooks, and delivery accelerators for repeatable program execution.

¡ Communicate technical findings and recommendations to both engineering-level and executive stakeholders.

Stakeholder Engagement and Program Delivery

¡ Work closely with engineering, operations, networking, and cybersecurity stakeholders throughout all implementation activities.

¡ Balance cybersecurity requirements with operational and engineering realities in industrial environments.

¡ Travel to client sites as required to support on-site delivery phases.

Mentorship and Practice Development

¡ Mentor junior consultants on OT implementation methodologies and technical practices.

· Contribute to Kroll’s OT delivery templates, standards, and practice accelerators.

Requirements

Education: Bachelor’s degree in Cybersecurity, Information Technology, Instrumentation, Engineering, or a related field. Four or more additional years of relevant hands-on experience accepted in lieu of degree.

Experience: Minimum 8 years of cybersecurity experience, including 5 or more years focused on Operational Technology (OT) security.

Required Qualifications

¡ Hands-on experience with Nozomi Networks Guardian deployment and configuration; Nozomi Networks Certified Engineer (NNCE) certification is a plus.

¡ Demonstrated experience delivering OT Security implementation projects within industrial or critical infrastructure environments.

¡ Experience implementing OT monitoring solutions using passive network monitoring techniques.

¡ Strong understanding of IEC 62443 and NIST SP 800-82.

¡ Experience supporting OT network segmentation and secure OT architecture design.

¡ Strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.

¡ Strong analytical and problem-solving skills in industrial network environments.

¡ Excellent written and verbal communication skills, including ability to present to executive stakeholders.

¡ Ability to work independently and collaboratively with cross-functional engineering and operational teams.

¡ Willingness to travel to client sites as required.

Desired Skills

¡ Experience in the rail transportation or transit sector.

¡ Experience integrating OT monitoring platforms with enterprise SIEM, SOC, or MDR environments.

¡ Familiarity with ISA/IEC 62443 Security Level assessments and zone/conduit documentation.

¡ Experience with industrial DMZ architecture and IT/OT network separation design.

¡ Prior consulting delivery experience in a professional services or advisory context.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

3:01 min

Comparing structured distributed hash tables with unstructured network topologies

Ishan Tiwari ¡ World Congress 2021

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

1:51 min

Overview of the three Google Maps routing applications

Germån Álvarez ¡ LIVE

2:26 min

The convergence of IT and OT attacks

Kurt Eder ¡ LIVE

Videos

See all

Related articles

See all