OT Security Consultant - Cyber Risk - Level 4
Role details
Job location
Tech stack
Job description
Kroll's Cyber Risk practice is seeking a contractor-level Operational Technology (OT) Security Architect at the Senior Manager level to support delivery of large-scale OT Security programs across North America, with primary project focus out of the San Francisco, CA area. This role serves as the technical lead for OT Security implementation engagements, with core responsibility for deploying and operationalizing OT monitoring solutions, designing secure OT network architectures, supporting network segmentation initiatives, and enabling continuous monitoring capabilities within critical infrastructure environments., The ideal candidate brings hands-on Nozomi Networks Guardian experience, deep fluency in IEC 62443 and NIST SP 800-82, and a delivery-oriented track record working directly alongside engineering, operations, networking, and cybersecurity teams in industrial environments. Experience in the rail transportation sector is strongly preferred.
Key ResponsibilitiesOT Monitoring Deployment and Operationalization
· Lead deployment, configuration, and operationalization of Nozomi Networks Guardian within industrial and critical infrastructure environments.
· Configure and tune OT monitoring policies, asset classification, alerting, dashboards, and reporting within Nozomi.
· Perform OT asset discovery validation and communication mapping using passive monitoring techniques.
· Develop monitoring use cases, operational playbooks, and deployment standards for scalable OT monitoring programs.
· Support integration of Nozomi with enterprise Security Information and Event Management (SIEM), Security Operations Center (SOC), Managed Detection and Response (MDR), and ticketing platforms.
OT Network Architecture and Segmentation
· Design and document OT network architectures, including security zones, conduits, industrial Demilitarized Zones (DMZs), remote access, and secure IT/OT connectivity.
· Review OT network topology and communication flows to support network segmentation and modernization initiatives.
· Apply strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.
· Align architecture design with IEC 62443 zones-and-conduits model and NIST SP 800-82 guidance.
Documentation and Reporting
· Produce architecture diagrams, implementation documentation, technical reports, and executive-ready summaries.
· Develop and maintain deployment standards, runbooks, and delivery accelerators for repeatable program execution.
· Communicate technical findings and recommendations to both engineering-level and executive stakeholders.
Stakeholder Engagement and Program Delivery
· Work closely with engineering, operations, networking, and cybersecurity stakeholders throughout all implementation activities.
· Balance cybersecurity requirements with operational and engineering realities in industrial environments.
· Travel to client sites as required to support on-site delivery phases.
Mentorship and Practice Development
· Mentor junior consultants on OT implementation methodologies and technical practices.
· Contribute to Kroll's OT delivery templates, standards, and practice accelerators.
Requirements
Education: Bachelor's degree in Cybersecurity, Information Technology, Instrumentation, Engineering, or a related field. Four or more additional years of relevant hands-on experience accepted in lieu of degree.
Experience: Minimum 8 years of cybersecurity experience, including 5 or more years focused on Operational Technology (OT) security.
Required Qualifications
· Hands-on experience with Nozomi Networks Guardian deployment and configuration; Nozomi Networks Certified Engineer (NNCE) certification is a plus.
· Demonstrated experience delivering OT Security implementation projects within industrial or critical infrastructure environments.
· Experience implementing OT monitoring solutions using passive network monitoring techniques.
· Strong understanding of IEC 62443 and NIST SP 800-82.
· Experience supporting OT network segmentation and secure OT architecture design.
· Strong understanding of industrial networking concepts, including SPAN/TAP architectures, VLANs, routing, industrial firewalls, and secure remote access.
· Strong analytical and problem-solving skills in industrial network environments.
· Excellent written and verbal communication skills, including ability to present to executive stakeholders.
· Ability to work independently and collaboratively with cross-functional engineering and operational teams.
· Willingness to travel to client sites as required.
Desired Skills
· Experience in the rail transportation or transit sector.
· Experience integrating OT monitoring platforms with enterprise SIEM, SOC, or MDR environments.
· Familiarity with ISA/IEC 62443 Security Level assessments and zone/conduit documentation.
· Experience with industrial DMZ architecture and IT/OT network separation design.
· Prior consulting delivery experience in a professional services or advisory context.