Cyber - Operational Technology - Senior - Consulting
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
As an OT Cybersecurity Senior or Senior Consultant in Technology Consulting, you will deliver and lead defined workstreams across OT security assessments, architecture, strategy and implementation initiatives. You will work directly with clients, prepare high-quality technical and executive deliverables, and help improve the security and resilience of industrial environments., * Conduct OT cybersecurity maturity assessments, risk assessments, gap analyses, security audits, architecture reviews and vulnerability assessments.
- Assess industrial environments that may include ICS, SCADA, DCS, PLC, RTU, HMI, SIS and IIoT technologies, industrial networks and supporting infrastructure.
- Review OT network architectures, segmentation approaches, zones and conduits, firewall rules, secure remote access, system hardening, asset visibility and monitoring capabilities.
- Support the development of OT cybersecurity strategies, roadmaps, policies, standards, procedures, reference architectures and implementation plans.
- Design and support implementation of OT security solutions while considering safety, availability, reliability and operational constraints.
- Apply frameworks and standards such as ISA/IEC 62443, NIST SP 800-82 and NIST CSF. Apply sector-specific guidance when relevant.
- Participate in and facilitate client interviews, workshops and technical discussions with engineering, operations, maintenance, IT and cybersecurity stakeholders.
- Prepare clear client deliverables, technical documentation, architecture diagrams, executive presentations and prioritized recommendations.
- Lead defined workstreams and support project planning, status reporting, risk and issue tracking, resource planning and budget monitoring.
- Collaborate with engagement leadership and multidisciplinary teams. Guide and mentor junior team members where appropriate.
- Contribute to proposals, client presentations, reusable assets, thought leadership and identification of additional client needs.
- Stay current on OT threats, vulnerabilities, industrial attack techniques, technologies and regulatory developments.
Requirements
- Strong understanding of OT and ICS cybersecurity principles, industrial control environments and the operational impact of security decisions.
- Working knowledge of industrial network architectures, common protocols and controls such as segmentation, firewalls, IDS or IPS, allowlisting, monitoring and secure remote access.
- Ability to analyze technical information and develop practical recommendations for technical and nontechnical audiences.
- Strong written and verbal communication, stakeholder management, analytical and problem-solving skills.
- Ability to manage competing priorities and deliver high-quality work in a collaborative consulting environment.
- Ability to work with cross-functional teams spanning engineering, operations, IT and cybersecurity.
To qualify for the role, you must have
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Industrial Automation or a related field, or equivalent relevant experience.
- Approximately 3 or more years of relevant cybersecurity, OT security, industrial automation or related experience. HR should calibrate the final threshold to the approved U.S. rank and compensation structure.
- Experience performing or supporting OT cybersecurity assessments, architecture reviews, risk analysis, security design or implementation activities.
- Knowledge of OT and ICS environments and systems such as SCADA, DCS, PLC, RTU or HMI.
- Familiarity with ISA/IEC 62443, NIST SP 800-82, NIST CSF or comparable cybersecurity guidance.
- Experience producing professional reports, presentations, technical documentation or architecture artifacts.
- Ability and willingness to travel based on client and project needs.
Ideally, you’ll also have
- Hands-on experience with OT monitoring, asset visibility or threat detection platforms such as Nozomi Networks, Claroty, Dragos, Armis, Microsoft Defender for IoT, Cisco Cyber Vision or comparable technologies.
- Experience in power and utilities, oil and gas, manufacturing, chemicals, mining, transportation, water or other critical infrastructure sectors.
- Experience with industrial protocols such as Modbus, DNP3, OPC, OPC UA, EtherNet/IP, CIP, PROFINET or IEC 61850.
- Experience with OT incident response, vulnerability management, security testing, threat modeling or transition-to-operations activities.
- Relevant certifications such as GICSP, ISA/IEC 62443, GRID, CISSP, CISM, CISA, Security+, CCNA or comparable credentials.
What we look for
We are looking for professionals who combine OT and ICS technical credibility with practical consulting judgment. Successful candidates communicate clearly, collaborate across engineering, operations and cybersecurity teams, and deliver high-quality outcomes in complex industrial environments.
Benefits & conditions
- New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices - $125,800 to $209,700
- Bay Area California offices - $131,100 to $218,500
- All other offices locations in the US, including Sacramento - $104,800 to $192,200
- Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
About the company
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity
Industrial and critical infrastructure organizations are strengthening cybersecurity as Operational Technology environments become more connected and exposed to changing threats. They need professionals who can understand industrial systems, work across engineering and cybersecurity teams, and turn technical analysis into practical improvements., * At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.
| EY | Building a better working world |
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Best Paying Jobs in Technology
Top-Paying Tech Jobs (with Salaries)
The Most Popular IT Jobs on the Market