Cybersecurity, OT-IT Security Consultant

Brown and Caldwell
Denver, CO, United States
1 day ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$129,000.0 - $177,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Systems Ethernet Supervisory Control and Data Acquisition (SCADA) Identity and Access Management Intrusion Detection and Prevention Virtual Private Networks (VPN)
+22 more
Network Security Modbus Network Architecture Network Monitoring Network Segmentation Remote Access Technology OPC Unified Architecture Security Information and Event Management Data Streaming Systems Architecture Software Vulnerability Management Digital Twin Multi-Agent Systems Firewalls (Computer Science) Information Technology Process Control Systems Operational Systems CIS Benchmarks Industrial Software Devsecops Key Vault Vulnerability Analysis

Job description

As a Cybersecurity Engineer at Brown and Caldwell, you will play a pivotal role in securing the operational technology (OT) and information technology (IT) environments that keep water and environmental infrastructure running safely and reliably. We are using modern technology to transform the way that water is managed across the country. Your work will directly impact our clients’ ability to protect critical infrastructure, maintain regulatory compliance, and build resilient digital solutions that ensure a future of clean water, thriving communities, and environmental protection., * Lead strategic cyber engineering consultation projects.

  • Make critical business development recommendations to balance risk and opportunity related to security solutions in accordance with the company’s strategy and operations.
  • Perform contract reviews.
  • Perform complex security assessments for engineering designs and client systems to identify areas of risk and compliance gaps.
  • Compare engineering designs with security frameworks, such as AWWA and NIST CSF, to identify potential gaps.
  • Lead the delivery of the security-related service offerings for our clients.
  • Validate security solution architecture, design, and implementation.
  • Support business development from a cybersecurity standpoint.
  • Ensure compliance with company policies and external regulations related to digital security.
  • Flexibility to adapt and execute various additional assignments based on evolving needs.

Preferred Requirements

  • Collaborate with interdisciplinary teams of environmental engineers, SCADA/controls engineers, data engineers, and software developers to assess, design, and implement cybersecurity solutions for client OT and IT environments.
  • Lead cybersecurity risk and vulnerability assessments of industrial control systems (ICS), SCADA networks, and enterprise IT environments for water, wastewater, and environmental clients, aligned to NIST SP 800-82, NIST CSF, and IEC 62443.
  • Design secure network architectures for converged IT/OT environments, including network segmentation, zone and conduit models, secure remote access, OT aware security gateways, and SOC integration strategies.
  • Support clients in meeting regulatory and compliance requirements, including America’s Water Infrastructure Act (AWIA) risk and resilience assessments, EPA cybersecurity guidance, and state level critical infrastructure requirements.
  • Develop cybersecurity governance deliverables, including policies, incident response plans, system security plans, and roadmaps that balance operational reliability with security posture improvement.
  • Evaluate and specify security technologies for OT environments (asset discovery and monitoring platforms, intrusion detection, firewalls, unidirectional gateways) with an understanding of the availability and safety constraints unique to industrial systems.
  • Advise on secure design and deployment of emerging digital solutions - including cloud connected SCADA, IoT/edge sensing, digital twins, and AI/agentic systems - addressing risks such as API credential handling, data flow security, and prompt injection exposure.
  • Support business development through proposal contributions, scopes of work, client presentations, and thought leadership on OT/IT convergence and critical infrastructure security.
  • Stay up to date with emerging threats, technologies, and best practices in ICS/OT security, cloud security, and AI system security to drive continuous improvement.

Mentorship

  • Provide mentorship, guidance, support, and knowledge-sharing to help less experienced team members develop their skills and grow within their roles.

Requirements

  • Advanced understanding of cyber security risks and mitigation solutions.
  • Demonstrated competency in security solution architecture, design, and implementation.
  • Advanced knowledge in contract review and security reviews.
  • Proven ability to conduct complex and insightful security assessments.
  • Strong knowledge in network infrastructure security (physical and virtual) solutions and tactics.
  • Strong Informational Technology (IT), Operational Technology (OT), and Industrial Control Systems (ICS) knowledge.
  • Highly adept in policy adherence and compliance in the context of cyber security.
  • Excellent skills in business development support and strategic decision-making.

Experience

  • Typically, a minimum of 8 years of relevant cyber security consultant experience is required.
  • Relevant cyber security certifications (Security+, CISSP, GICSP, etc).
  • Experience with on-premise and cloud-based system architecture is required.
  • Previous experience in NIST or related security frameworks is required.

Preferred Experience

Technical Proficiency:

  • OT/ICS Security: Deep working knowledge of SCADA, PLC/RTU, HMI, and historian architectures; familiarity with industrial protocols (Modbus, DNP3, OPC UA, EtherNet/IP) and their security limitations.
  • Frameworks & Standards: Demonstrated experience applying NIST SP 800-82, NIST CSF, IEC 62443, and CIS Controls; familiarity with NIST AI RMF is a plus.
  • Network Security: Strong understanding of network architecture and segmentation (Purdue Model), firewalls, VPNs, secure remote access, and OT network monitoring platforms (e.g., Claroty, Dragos, Nozomi).
  • IT Security: Solid grounding in enterprise security domains, including identity and access management, endpoint protection, vulnerability management, and security operations/SIEM.

Cloud & Platform Experience:

  • Experience securing Azure environments, including Azure security services (Defender, Sentinel, Key Vault, Entra ID), DevSecOps practices, and secure CI/CD pipelines.
  • Understanding of cloud-to-OT connectivity patterns and the security implications of hybrid architectures, edge compute, and IoT data pipelines.
  • Domain Specifics:
  • Water Sector: Experience with water/wastewater utility environments, AWIA compliance, and EPA/WaterISAC guidance is a strong plus.
  • Assessments & Advisory: Experience delivering client facing cybersecurity assessments, gap analyses, and roadmaps in a consulting or professional services context.

Soft Skills:

  • Strong problem solving skills and the ability to work in a collaborative, cross functional environment spanning engineering, operations, and IT stakeholders.
  • Excellent communication skills to interact with technical and non-technical audiences, with the ability to translate cyber risk into terms that resonate with utility leadership and operations staff.
  • A passion for staying updated with the latest trends, threats, and technologies in OT/IT security and critical infrastructure protection., * A relevant degree or equivalent experience is required., * Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Computer/Electrical Engineering, Information Systems, or a related field.
  • 8+ years of experience in cybersecurity, with at least 3 years focused on OT/ICS environments or critical infrastructure sectors (water/wastewater, energy, manufacturing, or similar).
  • Relevant certifications strongly preferred: GICSP, ISA/IEC 62443 Cybersecurity Expert, CISSP, GRID, or equivalent.

About the company

Headquartered in Walnut Creek, California, Brown and Caldwell is a full-service environmental engineering and construction services firm with 50 offices and over 2,100 professionals across North America and the Pacific. For more than 75 years, we have created leading-edge environmental solutions for municipalities, private industry, and government agencies. We strive to be the company of choice-to our clients, who benefit from our passion for delivering exceptional quality, and to our employees, present and future, who share our commitment to client service, collaboration, and innovation. Join us, and you will find a home where you can do your best work, reach new levels of expertise, and enjoy exceptional development opportunities. For more information, visit www.brownandcaldwell.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:23 min

Raspberry Pi and Modbus for feeder control

Øivind Heggland Øivind Heggland · Europe 2026 Virtual

4:52 min

Connecting namespaces with local virtual ethernet pairs

Oliver Seitz Oliver Seitz · World Congress 2025

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:12 min

Abstracting physical machine boundaries using industrial edge gateways

Freya Menzel Freya Menzel +1 · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all