Appcast

OT Cybersecurity Consultant

Appcast$74K — $137K *
Energy & Utilities
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, or related field
  • 3+ years of experience in cybersecurity or related fields
  • Foundational knowledge of cybersecurity & risk management
  • Familiarity with cybersecurity frameworks like NIST CSF and ISO 27001
  • Basic understanding of OT systems and industrial protocols
  • Strong writing and presentation skills for client deliverables
  • Proficiency in Microsoft Office Suite (Excel, Word, PowerPoint, Visio)

Responsibilities

  • Support cybersecurity advisory and risk engagements across critical infrastructure
  • Conduct cybersecurity maturity assessments and gap analyses in IT and OT environments
  • Evaluate cybersecurity programs in areas like governance, incident response, and OT security practices
  • Assess OT environments, including ICS/SCADA and connected assets
  • Identify cybersecurity risks and contribute to remediation planning
  • Review OT network segmentation and secure access patterns
  • Document cybersecurity architectures, processes, and controls

Benefits

  • Health, vision, and dental insurance
  • Employer paid provincial care premiums
  • Defined Contribution Pension Plan (DCPP)
  • Tax-Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP)
  • Life insurance and paid time off
  • Sick leave and recognized holidays off
  • Discounts on gym memberships
Full Job Description
Job Description:

Parsons is seeking an OT Cybersecurity Consultant to support cybersecurity advisory and technology risk engagements across rail and transit systems, water and wastewater infrastructure, and other industrial/critical infrastructure environments.

This is a consulting-focused role involving assessments, gap analyses, control reviews, client workshops, documentation, and remediation planning across both IT and Operational Technology (OT) environments. You will help clients strengthen cybersecurity programs while respecting OT priorities such as safety, reliability, availability, and operational continuity.

Engagements may align to frameworks and guidance such as NIST CSF 2.0, NIST SP 800-82 Rev. 3, ISA/IEC 62443, ISO/IEC 27001, CIS Controls, and Canadian public-sector control expectations such as ITSG-33, where applicable.

What You'll Be Doing:
  • Support delivery of cybersecurity advisory, technology risk, and OT cybersecurity consulting engagements for clients across multiple industries (critical infrastructure focus).
  • Assist in cybersecurity maturity assessments, gap analyses, and control reviews across both IT and OT environments (current-state vs target-state).
  • Help evaluate cybersecurity programs across domains including:
    • governance & risk management
    • IAM / privileged access
    • data protection
    • vulnerability management
    • incident response & recovery
    • third-party risk & supplier connectivity
    • security operations / monitoring
    • OT security engineering practices
  • Support OT environment assessments including ICS/SCADA, plant networks, connected assets, and operational processes (with attention to performance/reliability/safety constraints).
  • Assist in identifying cybersecurity risks, control gaps, and potential operational impacts; contribute to practical, risk-based recommendations and remediation planning.
  • Support reviews of OT network segmentation, secure remote access patterns, asset inventories, system hardening, patching approaches, backup/recovery expectations, and monitoring/logging capabilities.
  • Assist in mapping/testing controls against frameworks/standards such as NIST CSF 2.0 and ISA/IEC 62443 (e.g., organizing findings into control matrices and prioritized remediation roadmaps).
  • Participate in client interviews, workshops, walkthroughs, and site discussions; document architectures, processes, and control design/operation.
  • Help document cybersecurity operating models, governance processes, and policy/standard/procedure needs for both enterprise and industrial environments.
  • Support development of cybersecurity deliverables: reports, slide decks, issue logs, control matrices, and remediation roadmaps.
  • Support project management activities: workstream coordination, status reporting, RAID tracking, and remediation follow-up.
  • Conduct research on emerging threats and OT vulnerabilities; incorporate relevant guidance into deliverables and client recommendations.
  • Contribute to proposal development (scoping, methodology, workplans, and supporting content).


What Required Skills You'll Bring:
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, Engineering, or related field.
  • 3+ years of relevant experience in cybersecurity, technology risk, IT audit, OT/industrial cybersecurity, compliance, engineering technology environments, or consulting.
  • Foundational understanding of cybersecurity and risk management across enterprise IT and OT environments.
  • Familiarity with one or more of: NIST CSF, ISO 27001, CIS Controls, ISA/IEC 62443, NIST SP 800-82.
  • Basic understanding of OT/industrial concepts: ICS/SCADA components, plant networks, industrial protocols, connected devices, and operational constraints.
  • Strong writing and presentation skills (able to produce client-ready deliverables).
  • Strong analytical/problem-solving skills with attention to detail.
  • Proficiency in Microsoft Excel, Word, PowerPoint, and Visio.
  • Willingness to travel to client sites and operational facilities.


What Desired Skills You'll Bring:
  • Exposure to rail & transit OT environments (operations centers, communications networks, SCADA interfaces, etc.).
  • Exposure to water/wastewater OT environments (treatment plants, pump stations, telemetry/SCADA operations).
  • Familiarity with Canadian public-sector security control expectations such as ITSG-33 (helpful for work involving government-aligned control catalogues and risk management approaches).
  • Experience supporting any of: segmentation/DMZ designs, secure remote access, OT asset discovery, vulnerability management in OT, or OT security monitoring.
  • Relevant certifications (asset): Security+, CISSP, GICSP, ISA/IEC 62443 Fundamentals, CCNA, CISA/CRISC, ISO 27001 Foundation (or similar).


This position is part of our Critical Infrastructure team.

Salary Range: $74,000 - $137,500

This job posting is for a current addition or replacement opportunity within Parsons.

We value our employees and want our employees to take care of their overall wellbeing, which is why we offer best-in-class benefits such as health, vision, dental, employer paid provincial care premiums, Defined Contribution Pension Plan (DCPP), Tax-Free Savings Account (TFSA), Registered Retirement Savings Plan (RRSP), life insurance, paid time off, sick leave, all province observed holidays off, and gym membership discounts to fit your busy lifestyle!

About Appcast

Appcast is a global leader in programmatic recruitment advertising technology. More than just a job board, Appcast?s programmatic recruitment advertising exchange connects employers and job seekers through real-time bidding and automatic job ad optimization. Appcast?s proprietary technology and advanced data analysis tools enable employers to source and hire top talent quickly, efficiently, and cost-effectively. Appcast is headquartered in Lebanon, New Hampshire, with offices in Boston, New York City, San Francisco, London, Manchester, and Budapest.
Learn more about Appcast
Size
200 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Appcast

More Energy & Utilities Jobs

Find similar OT Cybersecurity Consultant jobs: