Senior Security Consultant, Operational Technologies (OT)

IOActive

$100K — $175K *
US-AnywhereRemote in United States
Energy & Utilities
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in offensive security, with 2-3 years in OT, ICS or critical infrastructure
  • Hands-on experience in OT domains like pen testing, threat modeling, and ICS assessments
  • Familiarity with industrial protocols and relevant security standards
  • Experience in plant operations with a focus on safety and process integrity
  • Bachelor's degree in Engineering or Computer Science, with relevant certifications preferred

Responsibilities

  • Serve as the senior technical voice in client discussions and engagements
  • Lead delivery on OT projects, owning the technical approach and findings
  • Perform hands-on assessment using non-disruptive OT methodologies
  • Conduct network reviews to identify security and safety risks
  • Lead tailored threat modeling exercises for OT environments
  • Translate technical findings into risk language for diverse audience
  • Mentor junior consultants and contribute to OT methodologies

Benefits

  • Work with an industry leader in cyber security
  • Access to world-class technical teams and research
  • High-energy, collaborative team environment
  • Flexibility to work remotely or on-site
  • Opportunities for travel
  • Performance-based incentives
Full Job Description
About the Role

The Senior Consultant, OT is a technical practitioner in IOActive's Operational Technology practice. The Senior Consultant leads complex and sensitive OT engagements across industrial control systems, critical infrastructure, embedded industrial devices, and OT/IT convergence environments - turning IOActive's deep research credibility into engagements that genuinely change how clients protect their most sensitive operational environments.

The Senior Consultant is expected to be a force multiplier for the OT practice through informal mentorship of junior consultants, contribution to research and methodology, and visible technical leadership on engagements as well as in the broader OT security community.

What You'll Do

Client Engagement

  • Serve as the senior technical voice in client discussions, technical deep-dives, and interviews with industrial systems engineers, control system vendors, and OT security teams
  • Lead delivery on OT engagements as the senior consultant on project teams - owning technical approach, methodology, hands-on testing, and findings
  • Protect the integrity, safety, and availability of clients' critical assets by leveraging your experience in non-disruptive and non-destructive OT assessment methodologies[AM1]
  • Perform hands-on technical work spanning industrial protocols and embedded industrial device analysis
  • Conduct network architecture reviews using the Purdue model and industrial segmentation principles; identify safety, availability, and security risks
  • Lead threat modeling exercises tailored to OT environments - incorporating safety, availability, and process integrity considerations alongside traditional security risks
  • Translate technical findings into business and operational risk language for client engineering, plant operations, and security leadership
  • Author and quality-review engagement deliverables to IOActive's standard
  • Build trusted technical relationships with client Security Architects, OT Security Leads, Heads of Industrial Cybersecurity, and engineering directors
  • Support pre-sales conversations with technical credibility - scoping calls, capability discussions, proposal input

Practice Contribution and Mentorship

Mentor junior and mid-level consultants in OT methodology, tools, and client engagement - even without direct reporting authority

  • Contribute to IOActive's OT methodologies, testing playbooks, report templates, and intellectual property
  • Identify opportunities to extend IOActive's OT capability - new service offerings, tooling, or research directions
  • Collaborate with the Hardware and Silicon practice on embedded industrial device work and component-level analysis where engagements span boundaries

Research and Market Presence

  • Contribute to IOActive's OT research - vulnerability discovery, protocol analysis, attack technique development, and published findings
  • Build personal profile in the OT security community through attending events, conference talks, published research, working group participation, etc.
  • Represent IOActive in OT security industry conversations, standards bodies, and customer advisory engagements as opportunities arise


What You'll Bring

Experience and Background

  • 5+ years in offensive security services, with at least 2-3 years focused on OT, ICS, or other critical infrastructure work
  • Hands-on engagement delivery experience across multiple OT domains - pen testing, threat modeling, ICS assessments, embedded industrial device security, or red-team / purple-team work in OT environments
  • Working knowledge across the breadth of the OT landscape and industrial protocols
  • Familiarity with relevant standards and frameworks[AM2]
  • Experience working in or alongside plant operations, with appreciation for safety, availability, and process integrity considerations that differentiate OT from IT security work

Capabilities

  • Strong technical credibility and the comfort to operate as the senior voice on engagements
  • Excellent written communication - you produce reports that clients act on rather than file
  • Strong verbal communication, including in technical workshops with engineering audiences and in business conversations with client leadership
  • Comfort with the physical and operational realities of OT engagements - plant visits, equipment rooms, control rooms, occasional non-standard hours during testing windows
  • Collaborative mindset - OT engagements typically involve close coordination with delivery teams across services lines
  • Genuine curiosity about how systems work - OT consultants who succeed at IOActive are the ones who find the problems interesting

Credentials

  • Bachelor's degree in Engineering (Computer, Electrical, Industrial, Mechanical), Computer Science, or equivalent experience
  • Relevant industry certifications strongly preferred
  • Willingness to travel approximately 30%, including on-site work at industrial facilities, sometimes in non-traditional environments, plants, substations, refineries, field locations)
  • Ability to obtain relevant security clearances if engagements require it (US: clearance preferred, not required; EMEA: equivalent clearances where applicable)

What We Offer

A chance to work with an industry leader in cyber security

Access to world-class technical teams and research

A high-energy, collaborative team that values innovation

Flexibility-work remotely or from the office as needed

Opportunities for travel

Competitive compensation and performance-based incentives

  • Salary range is broadly targeted between $100,000 - $175,000, depending on location, background and experience level


If this sounds like your kind of challenge, we'd love to hear from you. Let's talk!

Similar Jobs

More Jobs at IOActive

More Energy & Utilities Jobs

Find similar Senior Security Consultant, Operational Technologies (OT) jobs: