Senior Security Consultant, Operational Technologies; OT
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Systems Engineer
About the Role
The Senior Consultant, OT is a technical practitioner in IOActive’s Operational Technology practice. The Senior Consultant leads complex and sensitive OT engagements across industrial control systems, critical infrastructure, embedded industrial devices, and OT/IT convergence environments — turning IOActive’s deep research credibility into engagements that genuinely change how clients protect their most sensitive operational environments.
The Senior Consultant is expected to be a force multiplier for the OT practice through informal mentorship of junior consultants, contribution to research and methodology, and visible technical leadership on engagements as well as in the broader OT security community.
What You’ll Do Client Engagement- Serve as the senior technical voice in client discussions, technical deep-dives, and interviews with industrial systems engineers, control system vendors, and OT security teams
- Lead delivery on OT engagements as the senior consultant on project teams — owning technical approach, methodology, hands-on testing, and findings
- Protect the integrity, safety, and availability of clients’ critical assets by leveraging your experience in non-disruptive and non-destructive OT assessment methodologies [AM1]
- Perform hands-on technical work spanning industrial protocols and embedded industrial device analysis
- Conduct network architecture reviews using the Purdue model and industrial segmentation principles; identify safety, availability, and security risks
- Lead threat modeling exercises tailored to OT environments — incorporating safety, availability, and process integrity considerations alongside traditional security risks
- Translate technical findings into business and operational risk language for client engineering, plant operations, and security leadership
- Author and quality-review engagement deliverables to IOActive’s standard
- Build trusted technical relationships with client Security Architects, OT Security Leads, Heads of Industrial Cybersecurity, and engineering directors
- Support pre-sales conversations with technical credibility — scoping calls, capability discussions, proposal input
Mentor junior and mid-level consultants in OT methodology, tools, and client engagement — even without direct reporting authority
- Contribute to IOActive’s OT methodologies, testing playbooks, report templates, and intellectual property
- Identify opportunities to extend IOActive’s OT capability — new service offerings, tooling, or research directions
- Collaborate with the Hardware and Silicon practice on embedded industrial device work and component-level analysis where engagements span boundaries
- Contribute to IOActive’s OT research — vulnerability discovery, protocol analysis, attack technique development, and published findings
- Build personal profile in the OT security community through attending events, conference talks, published research, working group participation, etc.
- Represent IOActive in OT security industry conversations, standards bodies, and customer advisory engagements as opportunities arise
- 5+ years in offensive security services, with at least 2–3 years focused on OT, IC6 or other critical infrastructure work
- Hands‑on engagement delivery experience across multiple OT domains — pen testing, threat modeling, ICs assessments, embedded industrial device security, or red-team / purple-team work in OT environments
- Working knowledge across the breadth of the OT landscape and industrial protocols
- Familiarity with relevant standards and frameworks [AM2]
- Experience working in or alongside plant operations, with appreciation for safety, availability, and process integrity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).