World Wide Technology

Security Sr. Consultant - Operational Technology

World Wide Technology$117K — $146K *
US-AnywhereRemote in United States
Technical Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-8 years of cybersecurity, industrial automation, or control systems experience with a focus on OT/ICS security.
  • Proficiency in writing client-facing OT security strategy and assessment documents.
  • Strong understanding of OT protocols: Modbus, DNP3, EtherNet/IP, and more.
  • Knowledge of Purdue Enterprise Reference Architecture and security design patterns in OT environments.
  • Experience with OT asset visibility and monitoring platforms.
  • Familiarity with OT standards and regulatory guidelines: ISA/IEC 62443, NIST SP 800-82, etc.
  • Strong data networking background with knowledge of switches, routers, and firewalls.

Responsibilities

  • Lead technical execution of OT security workstreams, ensuring progress and quality.
  • Plan and execute OT discovery processes including asset inventory and network baselining.
  • Conduct site assessments and interviews with engineering and operations staff.
  • Adhere to client safety protocols and regulations during site visits.
  • Model zones and conduits against established security architectures, documenting trust boundaries.
  • Evaluate controls against applicable security standards and regulatory requirements.
  • Assess and recommend improvements for existing OT security technology.

Benefits

  • Health (Medical & Prescription), Dental, and Vision Care.
  • Competitive Pay and Profit Sharing.
  • 401k Plan with Company Matching and Tuition Reimbursement.
  • Generous Paid Time Off, including Parental and Medical Leave.
  • Additional perks like Family Planning Benefits and Pet Insurance.
Full Job Description
Qualifications

Experience
  • 4-8 years of overall cybersecurity, industrial automation, or control systems experience with a clear focus on OT/ICS security, including a security consulting or equivalent client-facing delivery role with a portfolio of example deliverables.
  • Demonstrated experience authoring client-facing OT security strategy and assessment documents (reports, architecture designs, executive presentations).
  • Working command of OT protocols and their security characteristics: Modbus TCP/RTU, DNP3, EtherNet/IP and CIP, PROFINET/PROFIBUS, OPC-DA/UA, IEC 61850, IEC 60870-5-104, BACnet, or HART.
  • Working knowledge of the Purdue Enterprise Reference Architecture and IDMZ design patterns, and of segmentation, conduit enforcement, and unidirectional gateway or data diode use in OT environments.
  • Practical experience with OT asset visibility and monitoring platforms, including sensor placement, span and tap strategy, and the safety rationale for passive over active discovery.
  • Working knowledge of OT standards and regulatory drivers: ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and one or more of NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or FDA premarket cybersecurity guidance.
  • Strong data networking background, including hands-on roles supporting switches, routers, and firewalls, and a working command of VLANs, routing, ACLs, and industrial network design.
  • Demonstrated understanding of the operational constraints that govern OT remediation: availability and safety precedence, management of change, outage and turnaround windows, vendor warranty and support boundaries, unsupported and legacy operating systems, and the practical limits of patching in a validated or safety-rated environment.
  • Preferred: direct time working in an operating industrial environment (controls engineering, plant IT, maintenance, or operations); familiarity with safety instrumented systems and IEC 61511; exposure to OT incident response and tabletop facilitation; familiarity with ICS threat intelligence and the OT-specific threat landscape (TRITON, INDUSTROYER, PIPEDREAM); PLC or SCADA programming experience.
  • Certifications desired: ISA/IEC 62443 Cybersecurity Specialist, GICSP, GRID, GCIP, CISSP, CISSP-ISSAP, or CISM.

Specialized Knowledge, Skills & Abilities

Working knowledge and consulting experience in at least three of the following areas:
  • Operational Technologies and Environments (ICS, SCADA, DCS, BAS, IIoT, IoMT)
  • Industrial Network Architecture and Segmentation (Purdue model, IDMZ, zones and conduits)
  • OT Asset Visibility, Monitoring, and Detection
  • Risk Management and Assessments, including consequence-driven methods
  • Policy, Governance, and Compliance (ISA/IEC 62443, NERC CIP, TSA, NIST)
  • Secure Remote Access and Third-Party/Vendor Access Governance
  • Incident Response and Recovery in OT environments
  • Threat and Vulnerability Management in constrained environments
  • Network and Systems Security
  • Identity and Access Management

Professional Attributes
  • Professional writing is required: strong, demonstrable ability to produce technical and business-related artifacts at a client-deliverable standard.
  • Able to perform concurrent tasks in complex environments under shifting priorities and timelines.
  • Able to communicate and modify approach, language, and style across a wide range of audiences, from controls engineers and plant operators to VP/CxO-level stakeholders, and to establish credibility with operations personnel who may be skeptical of security initiatives.
  • Collaborative, with the ability to manage conflicting interests across security, operations, and safety, and to operate effectively amid ambiguity and incomplete documentation.
  • Self-directed and proactive, with strong problem-solving instincts and intellectual curiosity about evolving technology.
  • Willing and able to travel to client facilities on an occasional basis, and to work within plant safety, PPE, escort, and permit requirements.

Professional Behaviors

Beyond technical delivery, this role is expected to demonstrate the following in front of clients and within the WWT team:
  • Safety first: treat client site safety rules as non-negotiable, and never allow a security objective to override an operational or safety constraint. A recommendation that introduces risk of a process upset is not acceptable, regardless of its security merit.
  • Ownership and accountability: take responsibility for the outcomes of your workstreams and the quality of every deliverable you author, and follow through on commitments without being chased.
  • Trusted advisor: build credibility quickly with both security and operations audiences, give candid and well-reasoned recommendations, and represent WWT as a partner the client relies on rather than an order-taker.
  • Clear communication: translate technical complexity into plain language for the audience at hand, listen actively, and keep stakeholders informed without surprises.
  • Integrity: give honest assessments even when the message is hard, and protect the client's interests and WWT's reputation in every recommendation.

Want to learn more about Consulting & Security Services? Check us out on our platform:

https://www.wwt.com/consulting-services

https://www.wwt.com/category/security-transformation

Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $117,200 to $146,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.

The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
  • Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
  • Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
  • Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
  • Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program

Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US benefits website at wwt.com/us-benefits.

If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process.

#LI-TB1

Position Overview:

World Wide Technology (WWT) is seeking a Security Sr. Consultant to own the technical execution of operational technology and industrial control system security engagements across critical infrastructure and manufacturing clients. This is a consulting role: you lead defined workstreams from discovery through analysis and design, and you author the deliverable content that defines the client's OT security posture and remediation plan. You are the consultant the client's representatives work with day to day, operating under the direction of a Lead Consultant or Principal Consultant who holds overall engagement accountability and final deliverable quality.

OT engagements are governed by constraints that do not apply in enterprise IT: availability and safety outrank confidentiality, change is bound to management-of-change processes and outage windows, and a meaningful share of the installed base runs unsupported operating systems on vendor-warranted equipment that cannot be patched or actively scanned. Engagements follow a consequence-driven, standards-anchored methodology: you baseline the environment through passive discovery and structured site walkdowns, model zones and conduits against the Purdue reference architecture and IEC 62443-3-2, assess controls against ISA/IEC 62443, NIST SP 800-82, and the client's applicable regulatory obligations, and sequence remediation against operational consequence and the constraints of the outage calendar.

Recommendations must be executable by the personnel responsible for operating the facility. This is a full-time position with a defined growth path toward the Lead Consultant level. Previous security consulting experience and a portfolio of client-facing deliverables are strongly preferred, as is direct time spent working in operating industrial environments.

Key Responsibilities
  1. Own technical execution of assigned OT security workstreams, driving day-to-day progress, quality, and pace against the agreed schedule and scope, escalating scope and commercial matters to the engagement lead.
  2. Plan and conduct OT discovery: asset inventory and network baselining, control system architecture documentation, protocol and traffic analysis, remote access path enumeration, patch and lifecycle posture, backup and recovery review, and third-party and vendor access review.
  3. Conduct site walkdowns and structured interviews with controls engineers, plant IT, operations, maintenance, safety, and vendor personnel; document the environment as operated and reconcile it against drawings and asset records, which are frequently outdated.
  4. Operate safely on client sites: complete required site safety training and work within client PPE, escort, permit, and lockout/tagout requirements without exception.
  5. Model zones and conduits against the Purdue Enterprise Reference Architecture and IEC 62443-3-2, documenting current-state trust boundaries, IDMZ posture, and the cross-level flows that deviate from the model.
  6. Assess controls against applicable standards and regulations, including ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and the client's obligations under NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or sector equivalents, documenting the evidence behind every finding.
  7. Assess and rationalize OT security technology already deployed, including passive monitoring and asset visibility platforms, secure remote access, firewalls and unidirectional gateways at the IDMZ, endpoint controls where supported, and backup infrastructure; recommend the approach per gap for engagement-lead review, and justify net-new capability rather than assuming it.
  8. Account for AI systems in scope by identifying machine learning and analytics components in the OT environment, including ML-based anomaly detection within monitoring platforms, vendor-hosted predictive maintenance and remote diagnostics, and any pathway by which process data leaves the facility or automated action is returned to it; document the resulting conduits and trust boundaries.
  9. Account for operational and safety interlocks: understand how safety instrumented systems, management-of-change processes, validated environments, and turnaround windows constrain remediation, and shape recommendations consistent with the facility's actual change calendar.
  10. Author deliverable content: clear, well-str

About World Wide Technology

World Wide Technology (WWT) is a technology solution provider that offers a wide range of services to businesses and organizations. The company was founded in 1990 and is headquartered in Maryland Heights, Missouri. WWT provides a variety of services, including consulting, design, integration, and managed services. The company has a strong focus on innovation and has been recognized for its efforts in this area. WWT has partnerships with many leading technology companies, including Cisco, Dell, and Microsoft. The company has a global presence, with offices in the United States, Europe, and Asia.
Learn more about World Wide Technology
Size
7,000 employees
Industry
Founded
1990

Similar Jobs

More Jobs at World Wide Technology

More Technical Services Jobs

Find similar Security Sr. Consultant - Operational Technology jobs: