Operational Technology (OT) Security Analyst / ICS Penetration Tester - TS/SCI Clearance Required - JBSA Lackland - San Antonio, TXJob Description We are seeking a highly skilled Operational Technology (OT) Security Analyst to evaluate, attack, and strengthen the security posture of our critical industrial control systems (ICS). Unlike standard IT penetration testing, this role requires a deep understanding of physical safety constraints, legacy industrial protocols, and the unique challenges of testing live production environments without causing downtime.
Job Responsibilities - The candidate will be responsible for conducting hands-on safety-first security assessments, documenting vulnerabilities, and collaborating with plant engineers to mitigate physical and digital risks.
- Vulnerability Testing: Conduct active and passive security assessments on OT environments, including SCADA, PLCs, RTUs, and HMI systems.
- Protocol Analysis: Analyze and test proprietary and open industrial protocols (e.g., Modbus, DNP3, Ethernet/IP, PROFINET, BACnet).
- Architectural Review: Evaluate network segmentation designs (Purdue Model) and identify unauthorized IT-to-OT bridging.
- Risk Mitigation: Deliver clear, actionable remediation reports to both highly technical engineering teams and non-technical plant managers.
- Safety First Execution: Design customized, non-disruptive testing methodologies specifically tailored to avoid triggering physical system failures or emergency shutdowns .
Basic QualificationsSecurity Clearance: Active TS/SCI
Education: Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or related discipline. Equivalent experience may be substituted.
Certification: Candidate must meet applicable IAT II certification requirements (ex: Security+).
Experience: - Minimum of 3-5 years of dedicated experience in cybersecurity testing, with at least 2 years focused specifically on OT/ICS environments.
- Industrial Protocols: Solid working knowledge of industrial network architecture and the Purdue Model.
- Safety Awareness: Proven track record of performing vulnerability assessments in operational environments where physical safety is the highest priority.
Preferred QualificationsCertifications:- Global Industrial Cyber Security Professional (GICSP)
- GIAC Response and Industrial Defense (GRID)
- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP/OSCP+) (as evidence of core ethical hacking capabilities)
BenefitsMedical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid Legal Plan and Identity Protection Plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.