> Markdown version of [/jobs/ext/1647314-onsite-cybersecurity-custodian-job-details-black](https://www.wearedevelopers.com/jobs/ext/1647314-onsite-cybersecurity-custodian-job-details-black). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # OnSite Cybersecurity Custodian Job Details | Black... - **Company:** Black & Veatch Holding Company - **Location:** Gaithersburg, MD, United States - **Experience:** Experienced - **Salary:** $112,524.0 - $187,932.0 - **Contract:** Permanent contract - **Skills:** Antivirus Softwares, Backup Devices, CompTIA Security+, Cyber Security, Hard Disk Drives, Firmware, IP Addressing, Network Intrusion Detection Systems, Role-Based Access Control, Remote Access Technology, Security Information and Event Management, Software Asset Management, Virtual Local Area Networks, Data Logging, Change Tracking, Splunk, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://www.juju.com/job/00000000gdb2ii ## About the Role + 3+ years supporting industrial/power generation control systems or OT environments. + Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP). + Practical knowledge of OT networking fundamentalssuch as: IP addressing, VLANs,firewallconcepts, routingbasics. + Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design. + Ability to work on-site in BeechIsland ,SC for 12+ months (typical 5x8 with occasional off-hours during cutovers). + Willingness to travel to vendor facilities for CFAT support. Occasionaltravel forplanning/working sessions may be requested.Eligible to meet badging/background/site access requirements. + Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling. + Experience supporting FAT/commissioning on large capital projects (power generation or similar). + Strong documentation discipline-ability to produce clear procedures, logs, checklists, and evidence packages. + Experience working with vendors and multi-discipline teams in construction/commissioning environments Minimum Qualifications Bachelor's Degree or relevant work experience. 4+ years experience in a business/consulting environment. All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations. Certifications Certifications related to area of expertise, where applicable preferred., Action oriented Interpersonal savvy Customer focus ## Description The role begins no later than November 2026 to support readiness activities ahead of Distributed Control System (DCS)Factory Acceptance Testing (FAT)in March 2027, includes travel to vendor FAT/CyberFAT(CFAT)locations, andremainson-site through installation, commissioning, and turnover. After completion of the BeechIslandproject, the role is expected to continue as a full-timeICS Cybersecurity Consultantposition supporting B&V's Infrastructure Advisory (IA)IndustrialCybersecurity team acrossadditionalOT/ICS projects.Thepost-projectrole can be based at the BV office in Columbia,SCor any other BV office location. Reporting & Teaming + Report operationally to the project leadershipteam,while working closely with B&V cybersecuritystakeholders. + Work closely with theIA ICSCybersecurityteamwhoprovides back-office support including:Project planning and cybersecurity execution roadmap,Standards, templates, and evidence packages,Requirements interpretation and technical guidanceandAction-item tracking support and cadence facilitation + Execute the on-site work, coordinate vendors, and ensure evidence is captured and organized. Key Responsibilities Cybersecurity Program Execution & Evidence Ownership + Supported and lead by BV Senior Cybersecurity Consultantsfrom Home Office, manageday-to-day execution of the on-site OT cybersecurityprogram, including tracking requirements, planned actions, and completion statusand report status of activities to BV Senior Cybersecurity Consultantsfor review and approvals + Build andmaintainan organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable. + Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, andsign-offsasrequired. CFAT / CyberSiteAcceptanceTesting (CSAT)Support + Support pre-CFAT readiness andparticipatein vendor CFAT activities asrequired(travelrequired). + Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations. + Track and close cyber-related FAT punch items; ensure retests andfinal evidenceare captured and filed. Identity, Credential, and Access Control + Verify and document required access controls including MFA for remote access, least privilege, and role-based access models. + Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes. Asset Inventory, Configuration Baselines & Change Tracking + Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references). + Track configuration baselines, redlines, and as-built updates throughout construction and commissioning. + Coordinatechangedocumentation andevidence, including post-change backup capture and validation. Removable Media & Transient Cyber Assets (TCA) Controls + Enforce and document removable media and transient device controls in line with Owner policies and site procedures. + Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention. + Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met). Monitoring, Logging, and Detection Enablement + Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, andforwardingarchitecture. + Support readiness for NIDS/span port configuration and eventforwardingrequirements. + Validate and document that logging is enabled, time-synchronized, and functioning withoutimpactingsystem performance. Additional Key Responsibilities Backup, Recovery, and Resilience + Verify backup procedures are in place for OTassetsand that backups are created after major changes (patching, configuration updates). + Support restorationtesting whererequired; ensure offline backup handling meets custody and storage requirements. + Track encrypted portable hard drives / backup media custody and handover documentation where applicable. Incident Reporting & Response Support + Maintain cyber escalation contacts and on-site reporting procedures. + Support documentation of cybersecurityevents, policy violations, corrective actions, and evidence of remediation steps. + Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records. Training, Workforce Security & Compliance Documentation + Track andmaintainevidence for required cybersecurityawareness training completion. + Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations). + Conduct periodic verification that access authorizationsremaincurrent and justified. A successful CybersecurityCustodian will: + Maintain a complete, well-organized cyber evidence repository that maps activities to requirements and stands up to Owner and compliance scrutiny. + Enable smooth FAT/CFAT/commissioning progress byidentifyingcybersecuritygaps early and driving closure without schedule disruption. + Demonstrate strong coordination across vendors, EPC, site teams, and theback-officecyberteam. + Establish consistent cyber processes on-site that improve repeatability and reduce risk. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)