Operational Technology; OT Cybersecurity Engineer
Listed on 2026-04-23
-
Engineering
Cybersecurity, Systems Engineer -
IT/Tech
Cybersecurity, Systems Engineer
Location: New York
Overview
This Opportunity:
This is an exciting opportunity to join WSP’s Critical & Emerging Technology team within the national Transit & Rail practice. This role focuses on delivering OT cybersecurity engineering, assessments, supplier/OEM compliance reviews, and architecture support for transit and rail systems including CBTC, SCADA, PTC, traction power, fleet charging, and safety-critical infrastructure. This may include safeguarding systems such as signaling, SCADA, traction power, and fleet charging infrastructure, while championing the adoption and strategies to future proof our clients to test and validate emerging technologies that enhance safety, reliability, and performance.
While it is critical for the candidate to thoroughly understand and contribute to the latest cyber standards (NIST, ISO, IEC, and FTA), the role requires the individual to lead engaging conversations with our clients about what the future of transit may hold and how best to prepare. The role will work closely with our established WSP US Properties & Buildings Cybersecurity team as well as the global WSP Cybersecurity community.
Deep cybersecurity expertise within the Transportation sector can be found in our global team.
This position may be based out of any mutually agreed upon East Coast Office with New York, NY as a preferred location
.
Core Technical Responsibilities
Conduct OT cybersecurity risk assessments, threat modeling, and vulnerability evaluations aligned with IEC 62443, TS 50701, NIST 800‑82/53, and relevant transit/rail standards.
Review supplier/OEM cybersecurity documentation such as SSPs, IRAs, DCRAs, zoning/conduit models, SBOM/HBOM, and patch management plans.
Support secure OT system and network architecture development including segmentation, DMZ design, boundary protection, and access control strategies.
Assist with OT asset inventory, system baselining, and network visibility activities to improve cybersecurity situational awareness.
Develop and recommend mitigation strategies, corrective actions, and cybersecurity controls for identified risks and vulnerabilities.
Support cybersecurity testing, commissioning, and configuration validation for OT systems, including controllers, network devices, and field hardware.
Contribute to cybersecurity procurement documentation including scopes, requirements, and acceptance criteria.
Support development of cybersecurity master plans, monitoring strategies, and operational security documentation.
Participate in OT tabletop exercises and incident response activities in coordination with client teams.
Work collaboratively with engineering, systems integration, operations, and safety teams across project life cycles.
Provide clear technical documentation and contribute to stakeholder communication as required.
Required Qualifications
Bachelor’s degree in engineering, cybersecurity, computer science, or a related field.
7- 10+ years of OT cybersecurity experience, including 3+ years in transit, rail, or critical infrastructure environments.
Hands‑on experience with rail/transit OT systems (CBTC, SCADA, PLCs, traction power, tunnel ventilation, fire/life safety, fleet charging, V2I/V2X, and related systems).
Deep knowledge of relevant cybersecurity standards including IEC 62443, TS50701, IEC 63452, NIST 800‑82/53, ISO frameworks, UNECE, TS, and APTA guidelines.
Demonstrated expertise in threat modeling, penetration testing, and OT network security; experience securing OTA, remote diagnostics, and air‑gapped environments.
Familiarity with OT security tools and monitoring technologies (e.g., Nozomi, Claroty, Dragos, protocol analysis tools).
Professional certifications such as CISSP, GICSP, ISA/IEC, and/or CompTIA Security+.
Strong communication, stakeholder engagement, and technical writing skills for client-facing environments.
Experience supporting cybersecurity-related compliance for U.S. transit regulatory bodies (FTA, FRA, TSA).
Ability to work independently and collaboratively across disciplines, delivering cybersecurity solutions in complex operational environments.
Understanding of OT…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).