United States
3 months ago

Job Overview

Job Type
Regular Full Time
Pay
Not disclosed

Job description

Location:
United States
Work arrangement:
On-site

Role Summary

The Operational Technology (OT) Cybersecurity Consultant assesses the security posture and maturity of OT environments for clients across manufacturing, energy, utilities, and other critical infrastructure sectors. This role involves conducting stakeholder interviews, reviewing OT documentation, evaluating security practices against industry frameworks, and developing maturity assessment reports with remediation recommendations. The Consultant presents findings and strategic guidance to clients while working with Project Managers, Directors, and Delivery teams to manage project scope and timelines.

Responsibilities

  • Maintain current knowledge of OT security standards, regulatory developments, and industry trends through ongoing professional development and relevant certifications
  • Support and guide OT risk and security discussions with technical teams, operations staff, and executive stakeholders
  • Conduct stakeholder interviews and review OT-related policies, procedures, architecture documentation, and compliance records to understand organizational OT environments and priorities
  • Assess client environments against OT security practices and compliance posture against IEC 62443, NIST SP 800-82, NIST CSF, NERC CIP, NIS2 Directive, EU Cyber Resilience Act, C2M2, and other relevant OT standards and frameworks
  • Develop maturity assessment and benchmarking reports identifying OT security gaps, current state findings, and prioritized remediation recommendations
  • Develop sequenced remediation roadmaps with prioritized activities, timelines, and implementation guidance to address identified OT security gaps
  • Advise clients on OT security program structure, governance frameworks, organizational roles and responsibilities, and recommended policies and procedures
  • Present assessment findings, risk analysis, and strategic recommendations to clients and their leadership through executive briefings and detailed reports
  • Support other Cyber Risk Advisory consulting engagements when necessary to maintain team capacity

Requirements

  • At least 4 years of working experience in operational technology security, OT risk assessment, or related infrastructure security roles
  • Bachelor's degree in Engineering, Computer Science, Information Systems, or related field, or equivalent combination of education and experience demonstrating OT security expertise
  • Direct experience in OT environments such as manufacturing, energy, utilities, or other critical infrastructure sectors
  • Hands-on experience with Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems
  • Knowledge of control system technologies, industrial automation architectures, and OT-specific networking environments
  • Expertise in OT security assessment frameworks including IEC 62443, NIST SP 800-82, and industry-specific requirements such as NERC CIP
  • Understanding of emerging OT regulatory requirements including NIS2 Directive, EU Cyber Resilience Act, and other sector-specific directives
  • Strong analytical and critical thinking abilities
  • Strong oral and written communication skills when presenting technical findings to both technical and non-technical audiences

Bonus Points

  • GICSP (Global Industrial Cyber Security Professional) certification
  • CISM certification
  • CISSP certification
  • GRID (GIAC Response and Industrial Defense) certification
  • GCIH (GIAC Certified Incident Handler) certification
  • C2M2 (Cybersecurity Capability Maturity Model) assessment experience
  • NIST Cybersecurity Framework (CSF) assessment and implementation experience
  • Incident response experience in OT or critical infrastructure environments
  • Business continuity or disaster recovery experience in OT environments
  • Experience with safety-critical systems and understanding of functional safety standards (IEC 61508, ISO 10218)
  • Technical writing experience for policy and procedure development
  • Cloud platform experience relevant to OT environments or industrial IoT implementations

Why You’ll Want to Join Us

At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.

Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com .

About the Company

Under FedRAMP, compliance is no longer a document—it’s a set of Key Security Indicators (KSIs): measurable security outcomes validated through automation, continuously. Coalfire organizes its delivery engineering into capability-focused teams, each owning a set of KSI domains such as identity and access management, monitoring and logging, change management, or incident recovery. We’re looking for a Cloud Engineer to go deep on a team’s domains—building the standard implementation once, making it deployable anywhere, and landing it in client environment after client environment, getting better every time. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place.

Role:
Operational Technology Security Consultant
Job Type:
Regular Full Time

Company profile

Coalfire

coalfire.com

Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses on FedRAMP, cloud migration and AI risk. It runs coordinated assessments across 85+ frameworks, attempts to hack client systems to find weaknesses, and helps clients reduce risk and simplify compliance. Coalfire is an Amazon Web Services Advanced Consulting Partner with 50+ AWS certified professionals, and it lists its address in Greenwood Village, Colorado. The company was co-founded in 2001 by Rick Dakin, Kennet Westby and Alan Ferguson.

Founded
2001
Founders
Rick Dakin, Kennet Westby, Alan Ferguson

More jobs at Coalfire

Similar Security Engineer jobs at other companies