Operational Technology Controls and Automation Engineer

Gordon Food Service

$90K — $110K *
Energy & Utilities
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field, or equivalent experience required.
  • Preferred certifications include GICSP, CISSP, ISA/IEC 62443 Cybersecurity Expert, or Palo Alto PCNSA/PCNSE.
  • Expertise in Industrial Control Systems, PLCs (Rockwell/Allen-Bradley, Siemens), and HMIs.
  • Advanced knowledge of industrial networking protocols (Profinet, EtherNet/IP, Modbus TCP).
  • Hands-on proficiency with Layer 7 Next-Gen Firewalls and Zero Trust Access like Prisma Access.
  • Strong troubleshooting skills related to network flow data and incident response.
  • Excellent communication skills for writing procedures and technical reports.

Responsibilities

  • Design and enforce Zero Trust network segmentation for OT environments.
  • Lead technical migration to modern Zero Trust Network Access solutions for vendor access.
  • Manage OT visibility and NDR platforms for real-time threat detection.
  • Operationalize automated incident containment procedures during cyber threats.
  • Develop network security standards for implementing Zero Trust and cloud migration.
  • Integrate identity services into dynamic access policies across various infrastructures.
  • Own disaster recovery protocols for PLC logic and local execution databases.

Benefits

  • Health, dental, and vision insurance plans.
  • Retirement savings plan with company matching contributions.
  • Paid time off and employee wellness programs.
  • Opportunities for professional development and certifications.
  • Flexible working hours and a supportive work environment.
Full Job Description
Position Summary:

The Operational Technology Controls and Automation Engineer serves as the key technical lead bridging physical warehouse automation, industrial cybersecurity, and operational execution across the distribution network.

This role is responsible for driving the continuous improvement, stability, and security posture of all on-site Operational Technology (OT) - including Material Handling Equipment (MHE/conveyors/sorters/ASRS), Cold Chain/Refrigeration controls, Building Management Systems (BMS), and facility safety infrastructure.

Functioning as a technical owner and influencer, this role collaborates directly with Divisional DC Maintenance, Enterprise IT/GTS, Security Operations, and external OEM vendors to enforce OT network segmentation, optimize real-time WCS/WES execution logic, and guarantee high availability without compromising floor throughput or physical safety.

What you will do:

OT Security Posture & Network Governance
  • Zero-Trust Floor Architecture & Segmentation: Partners with Enterprise Security to design, deploy, and enforce Layer 7 network segmentation (e.g., Palo Alto / Prisma Access) between OT subnets and enterprise VLANs, protecting OT/ICS environments from enterprise threats without impacting operational continuity.
  • Secure Vendor Remote Access (SASE/ZTNA): Leads the leads the deployment and execution of technical migration from legacy VPNs to modern Zero Trust Network Access (ZTNA) and SASE jump-box portals, establishing strict access governance for third-party automation and refrigeration providers.
  • OT Visibility, Telemetry & NDR: Manages Network Detection and Response and OT visibility platforms (e.g., Armis, Cisco CyberVision, Vectra), maintaining real-time asset inventories and threat detection across cloud and floor environments.
  • Automated Incident Containment ("Red Button"): Operationalizes and executes pre-approved "break-glass" containment playbooks with SecOps to isolate compromised warehouse segments or malicious vendor tunnels at machine speed during cyber threats without causing self-inflicted plant outages.

Network Security Architecture & Enterprise Governance
  • Zero Trust Reference Architectures: Partners with GTS teams to develop and maintain network security design patterns, engineering standards, and implementation roadmaps supporting Zero Trust, SASE, cloud migration, and business objectives.
  • Unified Segmentation Strategy: Partners with other GTS and Security teams and oversees a global segmentation model utilizing Next-Gen Firewalls (NGFWs), micro-segmentation, and cloud-native security controls across cloud, data center, partner networks, and site locations.
  • Cross-Functional Infrastructure Alignment: Partners with Cloud, On-Prem Network, and IAM teams to integrate identity attributes, device posture, and directory services into dynamic access policies across SD-WAN and enterprise transit layers.
  • Infrastructure as Code (IaC) & Policy Automation: Implements IaC and policy-as-code solutions to automatically deploy, validate, and audit network security controls across hybrid environments.

System Health, Resiliency & Disaster Recovery
  • High Availability & Virtual Patching: Establishes edge firewall virtual patching and threat prevention profiles (IPS/App-ID) to mitigate vulnerabilities on legacy PLCs and controllers that cannot accept direct firmware patches.
  • Local HA/DR Verification: Owns point-in-time backup integrity and disaster recovery protocols for PLC ladder logic, SCADA configurations, and local execution databases to satisfy corporate Recovery Point (RPO) and Recovery Time (RTO) objectives.
  • Complex Root-Cause Triage: Serves as senior technical escalation support during complex automation stoppages and cybersecurity incidents, troubleshooting fieldbus communications (Profinet, EtherNet/IP) and network-based threat activity.

Continuous Improvement & Operational Leadership
  • Informal Technical Leadership & Mentorship: Serves as a trusted advisor to Divisional DC Maintenance, Site Leadership, and GTS teams, mentoring technicians and driving network-wide adoption of OT best practices, SOPs, and engineering standards.
  • WCS/WES & Control Logic Optimization: Oversees the integration and real-time execution performance of Warehouse Control Systems (WCS) and Warehouse Execution Systems (WES), ensuring wave-balancing algorithms and routing logic maintain peak case-per-hour throughput.
  • Operational Change Gatekeeper: Controls PLC firmware updates, SCADA updates, and control logic patches, ensuring all updates undergo offline validation in pre-production environments prior to scheduled maintenance windows.

Strategic Technology Modernization
  • Architecture Advisory & Committee Participation: Participates in the Cross-Functional Architecture Group to influence the secure design of enterprise technology initiatives, cloud transit, and data-in-transit encryption standards.
  • Metrics & Roadmap Evaluation: Evaluates emerging network security technologies and defines key security engineering metrics related to network visibility, policy compliance, and Zero Trust maturity.
  • Performs other duties as assigned.
  • Control Platform Standards: Develops and maintains Control Platform Standards that are maintained in the GFS Standards used for existing and new implementations
  • Infrastructure Support: Provides and specifies server OT needs for IT to provide the appropriate solution for the OT application or Control System. This includes supporting provisioning of support contractors and required roles to support GFS systems.
  • Device Approvals and Certification: Collaborate with Enterprise security in review of devices that will exist on GFS networks. This includes hardware devices, software used to control devices, and other OT specific applications and devices.


When you will work:

  • Monday to Friday, 8am to 5pm


What you'll bring to the table:

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field or equivalent combination of education and experience required.
  • GICSP (Global Industrial Cyber Security Professional), CISSP, ISA/IEC 62443 Cybersecurity Expert, or Palo Alto PCNSA/PCNSE certifications preferred.
  • Deep expertise in Industrial Control Systems (ICS), Programmable Logic Controllers (PLCs - Rockwell/Allen-Bradley, Siemens), HMIs, variable frequency drives (VFDs), and fixed barcode scan tunnels.
  • Advanced knowledge of industrial networking protocols (Profinet, EtherNet/IP, Modbus TCP) and industrial network security frameworks (ISA/IEC 62443, NIST SP 800-82, Purdue Model).
  • Hands-on proficiency with Layer 7 Next-Gen Firewalls (Palo Alto Networks, App-ID, Threat Prevention) and SASE/Zero-Trust Access (Prisma Access).
  • Knowledge of Automated Material Handling Systems (AMHS), AS/RS stacker cranes, robotics, and their operational relationships to cold chain refrigeration and facility utilities.
  • Strong ability to influence without direct authority, build trust with floor maintenance teams, and translate complex technical requirements into actionable site guidance.
  • Strong troubleshooting and analytical skills related to interpreting trend logs, packet captures, and network flow data.
  • Excellent written and verbal communication skills; ability to author procedures, business proposals, and technical incident reports for executive leadership.
  • Strong Electrical / Controls background
  • Strong Industrial control system trouble shooting experience with ability to assist in system trouble events both remotely and on site dispatched if needed.

Similar Jobs

More Jobs at Gordon Food Service

More Energy & Utilities Jobs

Find similar Operational Technology Controls and Automation Engineer jobs: