OT Security & Architecture Manager
About the role
This role leads and matures the organization's OT cybersecurity program across industrial control systems (ICS), operational technology (OT), marine, offshore, manufacturing, robotics, and critical infrastructure environments. It provides strategic leadership and operational oversight for OT cybersecurity governance, risk management, security architecture, vulnerability management, monitoring, and compliance activities. The position offers a hybrid work environment, combining virtual work with in-office presence in Houston as required.
Responsibilities
- Partner with OT engineering teams, site management, business units, IT cybersecurity, compliance, and operations leadership to ensure cybersecurity controls are implemented while maintaining operational safety, reliability, and availability.
- Establish and maintain an enterprise-wide OT cybersecurity program aligned with industry standards, including NIST Cybersecurity Framework, NIST 800-82, Purdue Model, Title 33 CFR maritime cybersecurity requirements, customer obligations, and internal cybersecurity policies.
OT Cybersecurity Program Leadership
- Lead the enterprise OT Cybersecurity Program across all business units and operational environments.
- Develop and execute OT cybersecurity strategy, roadmap, standards, and maturity improvement initiatives.
- Establish governance processes to ensure consistent implementation of OT cybersecurity controls globally.
- Serve as the primary cybersecurity advisor to OT operations, engineering, manufacturing, and offshore stakeholders.
- Provide executive reporting on OT cyber risks, vulnerabilities, remediation efforts, and security posture.
OT Threat & Vulnerability Management
- Own the OT vulnerability management program, including identification, prioritization, risk assessment, remediation planning, and reporting.
- Lead enterprise OT patch management activities while balancing operational availability, safety, and cyber risk.
- Establish risk-based remediation processes focused on exploitability, operational impact, and criticality.
- Coordinate vulnerability assessments across OT environments, including ICS, SCADA, DCS, PLC, HMI, and IIoT systems.
- Develop and report KPIs related to remediation effectiveness, patch compliance, and exposure reduction.
OT Security Architecture & Risk Assessments
- Lead OT cybersecurity architecture governance and provide security oversight for operational technology environments.
- Review and approve OT security architecture designs, network segmentation strategies, remote access solutions, and major technology initiatives.
- Oversee cybersecurity risk assessments for new and existing OT systems and infrastructure.
- Ensure security controls are incorporated into all OT projects from design through deployment.
- Partner with the OT Security Architect to maintain secure reference architectures and technology standards.
- Drive IT/OT convergence initiatives while maintaining appropriate security boundaries.
OT Change Management
- Establish cybersecurity governance within OT Management of Change (MoC) processes.
- Ensure cyber risk review and approval requirements are incorporated into OT engineering and operational changes.
- Validate cybersecurity impacts of system modifications, upgrades, integrations, and technology refresh activities.
- Ensure asset inventories, baseline configurations, and security documentation remain current following approved changes.
OT Monitoring, Logging & Incident Readiness
- Lead OT security monitoring strategy, including collection, analysis, and retention of OT security logs.
- Partner with the Security Operations Center to integrate OT asset telemetry and detection capabilities.
- Develop OT-specific use cases, detection rules, playbooks, and incident response procedures.
- Lead tabletop exercises, cyber drills, and response preparedness activities for OT environments.
- Monitor emerging OT cyber threats and communicate actionable intelligence to stakeholders.
OT Red Teaming & Security Validation
- Establish and manage OT cyber assessment and adversary simulation programs.
- Coordinate OT-focused penetration testing, red team activities, architecture reviews, and control validation exercises.
- Ensure testing activities are safely coordinated and approved to avoid disruption of operational environments.
- Track remediation of findings and drive continuous control improvements.
Firewall & Network Security Governance
- Oversee OT firewall governance and industrial network security architecture.
- Review firewall rulesets, network segmentation controls, remote access pathways, and external connectivity risks.
- Ensure OT networks align with established cybersecurity architecture standards and best practices.
- Validate compliance with approved secure network designs and zone/conduit architectures.
Policy, Standards & Compliance
- Develop, maintain, and govern OT cybersecurity policies, standards, baselines, and procedures.
- Ensure alignment with:
- NIST Cybersecurity Framework
- NIST SP 800-82
- IEC 62443
- ISA/IEC industrial security practices
- Title 33 CFR maritime cybersecurity requirements
- U.S. Coast Guard cybersecurity requirements
- Customer-specific cybersecurity obligations
- Lead cybersecurity compliance assessments, control reviews, audits, and remediation activities.
- Support regulatory and customer assurance initiatives across global operations.
Leadership & Team Development
- Lead, mentor, and develop a high-performing OT cybersecurity team.
- Provide strategic directions to the OT Security Architect and OT Security Project Manager.
- Establish operational objectives, performance metrics, and development plans.
- Foster strong partnerships between cybersecurity, engineering, OT operations, and business leadership.
- Promote a culture of continuous improvement, cybersecurity awareness, and operational excellence.
Requirements
- Bachelor's degree in Cybersecurity, Engineering, Computer Science, Information Systems, or related field.
- Minimum 10 years of cybersecurity experience.
- Minimum 5 years supporting Operational Technology (OT), Industrial Control Systems (ICS), or critical infrastructure environments.
- Minimum 5 years leading cybersecurity programs, projects, or teams.
- Minimum 5 years’ experience with:
- OT patch management
- Vulnerability management
- ICS/SCADA environments
- Industrial networking
- Firewall technologies
- Security architecture
- Risk assessments
- Incident response
- Regulatory compliance
- Experience partnering with engineering, manufacturing, offshore, marine, robotics, or industrial operations teams.
- CISSP or CISM Certification.
Desired Qualifications
- GICSP
- GRID
- GSTR
- ISA/IEC 62443 Cybersecurity Expert
- CCSP
- PMP
About Us
Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.
About The Team
Our regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high-quality support that ensures our operations run efficiently and safely. Having these teams based locally allows us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.