> Markdown version of [/jobs/ext/2299285-security-sr-consultant-operational-technology](https://www.wearedevelopers.com/jobs/ext/2299285-security-sr-consultant-operational-technology). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Sr. Consultant - Operational Technology - **Company:** World Wide Technology - **Location:** United States - **Experience:** Expert - **Salary:** $117,200.0 - $146,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Computer Networks, Software Design Patterns, Ethernet, Data Flow Control, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Information Systems Security Architecture Professional, Machine Learning, Modbus, Network Architecture, Network Planning and Design, Routing, Profibus, Remote Access Technology, Transmission Control Protocol (TCP), Traffic Analysis, Virtual Local Area Networks, Network Routers, Data Processing, Firewalls (Computer Science), Bacnet, Process Control Systems - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9128061/security-sr-consultant-operational-technology ## About the Role * 4-8 years of overall cybersecurity, industrial automation, or control systems experience with a clear focus on OT/ICS security, including a security consulting or equivalent client-facing delivery role with a portfolio of example deliverables. * Demonstrated experience authoring client-facing OT security strategy and assessment documents (reports, architecture designs, executive presentations). * Working command of OT protocols and their security characteristics: Modbus TCP/RTU, DNP3, EtherNet/IP and CIP, PROFINET/PROFIBUS, OPC-DA/UA, IEC 61850, IEC 60870-5-104, BACnet, or HART. * Working knowledge of the Purdue Enterprise Reference Architecture and IDMZ design patterns, and of segmentation, conduit enforcement, and unidirectional gateway or data diode use in OT environments. * Practical experience with OT asset visibility and monitoring platforms, including sensor placement, span and tap strategy, and the safety rationale for passive over active discovery. * Working knowledge of OT standards and regulatory drivers: ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and one or more of NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or FDA premarket cybersecurity guidance. * Strong data networking background, including hands-on roles supporting switches, routers, and firewalls, and a working command of VLANs, routing, ACLs, and industrial network design. * Demonstrated understanding of the operational constraints that govern OT remediation: availability and safety precedence, management of change, outage and turnaround windows, vendor warranty and support boundaries, unsupported and legacy operating systems, and the practical limits of patching in a validated or safety-rated environment. * Preferred: direct time working in an operating industrial environment (controls engineering, plant IT, maintenance, or operations); familiarity with safety instrumented systems and IEC 61511; exposure to OT incident response and tabletop facilitation; familiarity with ICS threat intelligence and the OT-specific threat landscape (TRITON, INDUSTROYER, PIPEDREAM); PLC or SCADA programming experience. * Certifications desired: ISA/IEC 62443 Cybersecurity Specialist, GICSP, GRID, GCIP, CISSP, CISSP-ISSAP, or CISM. Specialized Knowledge, Skills & Abilities Working knowledge and consulting experience in at least three of the following areas: * Operational Technologies and Environments (ICS, SCADA, DCS, BAS, IIoT, IoMT) * Industrial Network Architecture and Segmentation (Purdue model, IDMZ, zones and conduits) * OT Asset Visibility, Monitoring, and Detection * Risk Management and Assessments, including consequence-driven methods * Policy, Governance, and Compliance (ISA/IEC 62443, NERC CIP, TSA, NIST) * Secure Remote Access and Third-Party/Vendor Access Governance * Incident Response and Recovery in OT environments * Threat and Vulnerability Management in constrained environments * Network and Systems Security * Identity and Access Management, * Professional writing is required: strong, demonstrable ability to produce technical and business-related artifacts at a client-deliverable standard. * Able to perform concurrent tasks in complex environments under shifting priorities and timelines. * Able to communicate and modify approach, language, and style across a wide range of audiences, from controls engineers and plant operators to VP/CxO-level stakeholders, and to establish credibility with operations personnel who may be skeptical of security initiatives. * Collaborative, with the ability to manage conflicting interests across security, operations, and safety, and to operate effectively amid ambiguity and incomplete documentation. * Self-directed and proactive, with strong problem-solving instincts and intellectual curiosity about evolving technology. * Willing and able to travel to client facilities on an occasional basis, and to work within plant safety, PPE, escort, and permit requirements. ## Description World Wide Technology (WWT) is seeking a Security Sr. Consultant to own the technical execution of operational technology and industrial control system security engagements across critical infrastructure and manufacturing clients. This is a consulting role: you lead defined workstreams from discovery through analysis and design, and you author the deliverable content that defines the client's OT security posture and remediation plan. You are the consultant the client's representatives work with day to day, operating under the direction of a Lead Consultant or Principal Consultant who holds overall engagement accountability and final deliverable quality. OT engagements are governed by constraints that do not apply in enterprise IT: availability and safety outrank confidentiality, change is bound to management-of-change processes and outage windows, and a meaningful share of the installed base runs unsupported operating systems on vendor-warranted equipment that cannot be patched or actively scanned. Engagements follow a consequence-driven, standards-anchored methodology: you baseline the environment through passive discovery and structured site walkdowns, model zones and conduits against the Purdue reference architecture and IEC 62443-3-2, assess controls against ISA/IEC 62443, NIST SP 800-82, and the client's applicable regulatory obligations, and sequence remediation against operational consequence and the constraints of the outage calendar. Recommendations must be executable by the personnel responsible for operating the facility. This is a full-time position with a defined growth path toward the Lead Consultant level. Previous security consulting experience and a portfolio of client-facing deliverables are strongly preferred, as is direct time spent working in operating industrial environments., * Own technical execution of assigned OT security workstreams, driving day-to-day progress, quality, and pace against the agreed schedule and scope, escalating scope and commercial matters to the engagement lead. * Plan and conduct OT discovery: asset inventory and network baselining, control system architecture documentation, protocol and traffic analysis, remote access path enumeration, patch and lifecycle posture, backup and recovery review, and third-party and vendor access review. * Conduct site walkdowns and structured interviews with controls engineers, plant IT, operations, maintenance, safety, and vendor personnel; document the environment as operated and reconcile it against drawings and asset records, which are frequently outdated. * Operate safely on client sites: complete required site safety training and work within client PPE, escort, permit, and lockout/tagout requirements without exception. * Model zones and conduits against the Purdue Enterprise Reference Architecture and IEC 62443-3-2, documenting current-state trust boundaries, IDMZ posture, and the cross-level flows that deviate from the model. * Assess controls against applicable standards and regulations, including ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and the client's obligations under NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or sector equivalents, documenting the evidence behind every finding. * Assess and rationalize OT security technology already deployed, including passive monitoring and asset visibility platforms, secure remote access, firewalls and unidirectional gateways at the IDMZ, endpoint controls where supported, and backup infrastructure; recommend the approach per gap for engagement-lead review, and justify net-new capability rather than assuming it. * Account for AI systems in scope by identifying machine learning and analytics components in the OT environment, including ML-based anomaly detection within monitoring platforms, vendor-hosted predictive maintenance and remote diagnostics, and any pathway by which process data leaves the facility or automated action is returned to it; document the resulting conduits and trust boundaries. * Account for operational and safety interlocks: understand how safety instrumented systems, management-of-change processes, validated environments, and turnaround windows constrain remediation, and shape recommendations consistent with the facility's actual change calendar. * Author deliverable content: clear, well-structured, client-ready documents and presentations covering current-state architecture, gap and risk analysis, zone-and-conduit design, and a phased roadmap, for Lead Consultant or Principal Consultant review. * Run pre-readout reviews with client SMEs, including the controls and operations personnel whose endorsement determines whether the plan is implemented; present findings to project sponsors and working-group leadership, and support the engagement lead on the executive readout to client leadership. * Support deliverable review cycles, incorporating feedback across review iterations and driving documents toward acceptance, partnering with the WWT Program Manager on cadence and the engagement lead on quality. * Identify and communicate risks through the project's RAID process and weekly status, escalating issues that affect scope, schedule, safety, or quality. * Contribute to practice IP: refine OT assessment methodologies, walkdown and discovery templates, zone-and-conduit patterns, and reusable artifacts that improve delivery consistency across engagements. Typical Deliverables The defining output of this role is authoring the engagement's OT security deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, target-state architecture, and a phased remediation roadmap the client can fund and execute within its outage calendar. You are a primary author, and the quality of these documents is a primary performance criterion for the role. You are a primary author of the deliverable set below, working under the review of the Lead Consultant or Principal Consultant, who holds final quality accountability: * Current-State OT Discovery & Asset Baseline: consolidated asset inventory, network architecture and dataflow documentation, protocol and communication baseline, remote access path inventory, and lifecycle and patch posture across in-scope sites. * OT Cybersecurity Gap & Risk Assessment: control gap analysis against ISA/IEC 62443 and NIST SP 800-82, with findings prioritized by operational consequence rather than CVSS alone, and regulatory exposure mapped where NERC CIP, TSA, or sector obligations apply. * Zone & Conduit Architecture and Segmentation Design: Purdue-aligned target-state zone model, conduit definitions and enforcement points, IDMZ design, and the broker, jump-host, or data-diode pattern selected per flow. * OT Secure Remote Access & Monitoring Design: vendor and employee remote access architecture, passive monitoring and asset visibility sensor placement and span/tap strategy, and the integration path into enterprise SOC or OT-specific monitoring operations. * Executive Findings & Recommendations: executive-level presentation consolidating key findings, consequence-based risk framing, strategic recommendations, and a phased roadmap sequenced against outage windows and capital cycles. Growth & Development * Build depth across the major control system platform families and their engineering toolchains, toward the breadth required to establish situational understanding quickly in an unfamiliar facility. * Maintain working currency in AI security as the field develops, including the evolution of AI risk frameworks, the security implications of agentic and tool-calling systems, and the controls available to govern them; AI competence is expected of every consultant in the practice, independent of specialization. * Expand sector range beyond your primary vertical; the regulatory drivers and risk profile differ significantly across electric utility, oil and gas, water and wastewater, discrete and process manufacturing, and pharmaceutical environments. * Develop the executive communication capability required to own the client readout rather than support it: translating consequence-based OT risk for the VP, CxO, and board audiences responsible for funding remediation. * Grow pursuit capability through exposure to scoping, ROM estimation, and SOW development alongside the Lead Consultant or Principal Consultant. * Begin mentoring Consultants and Analysts on discovery method, walkdown discipline, site safety practice, and WWT delivery standards. * Grow toward owning an engagement end to end, which is the threshold for the Lead Consultant level., Beyond technical delivery, this role is expected to demonstrate the following in front of clients and within the WWT team: * Safety first: treat client site safety rules as non-negotiable, and never allow a security objective to override an operational or safety constraint. A recommendation that introduces risk of a process upset is not acceptable, regardless of its security merit. * Ownership and accountability: take responsibility for the outcomes of your workstreams and the quality of every deliverable you author, and follow through on commitments without being chased. * Trusted advisor: build credibility quickly with both security and operations audiences, give candid and well-reasoned recommendations, and represent WWT as a partner the client relies on rather than an order-taker. * Clear communication: translate technical complexity into plain language for the audience at hand, listen actively, and keep stakeholders informed without surprises. * Integrity: give honest assessments even when the message is hard, and protect the client's interests and WWT's reputation in every recommendation., We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for all! If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process. ## Related Videos - [Optimizing Land-Based Fish Feeding with Node-RED](https://www.wearedevelopers.com/videos/2032-optimizing-land-based-fish-feeding-with-node-red) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)