Security Sr. Consultant – Operational Technology
About the Role
World Wide Technology (WWT) is seeking a Security Sr. Consultant to own the technical execution of operational technology and industrial control system security engagements across critical infrastructure and manufacturing clients. This is a consulting role: you lead defined workstreams from discovery through analysis and design, and you author the deliverable content that defines the client's OT security posture and remediation plan. You are the consultant the client's representatives work with day to day, operating under the direction of a Lead Consultant or Principal Consultant who holds overall engagement accountability and final deliverable quality.
OT engagements are governed by constraints that do not apply in enterprise IT: availability and safety outrank confidentiality, change is bound to management-of-change processes and outage windows, and a meaningful share of the installed base runs unsupported operating systems on vendor-warranted equipment that cannot be patched or actively scanned. Engagements follow a consequence-driven, standards-anchored methodology: you baseline the environment through passive discovery and structured site walkdowns, model zones and conduits against the Purdue reference architecture and IEC 62443-3-2, assess controls against ISA/IEC 62443, NIST SP 800-82, and the client's applicable regulatory obligations, and sequence remediation against operational consequence and the constraints of the outage calendar. Recommendations must be executable by the personnel responsible for operating the facility.
This is a full-time position with a defined growth path toward the Lead Consultant level. Previous security consulting experience and a portfolio of client-facing deliverables are strongly preferred, as is direct time spent working in operating industrial environments.
Key Responsibilities
- Own technical execution of assigned OT security workstreams, driving day-to-day progress, quality, and pace against the agreed schedule and scope, escalating scope and commercial matters to the engagement lead.
- Plan and conduct OT discovery: asset inventory and network baselining, control system architecture documentation, protocol and traffic analysis, remote access path enumeration, patch and lifecycle posture, backup and recovery review, and third-party and vendor access review.
- Conduct site walkdowns and structured interviews with controls engineers, plant IT, operations, maintenance, safety, and vendor personnel; document the environment as operated and reconcile it against drawings and asset records, which are frequently outdated.
- Operate safely on client sites: complete required site safety training and work within client PPE, escort, permit, and lockout/tagout requirements without exception.
- Model zones and conduits against the Purdue Enterprise Reference Architecture and IEC 62443-3-2, documenting current-state trust boundaries, IDMZ posture, and the cross-level flows that deviate from the model.
- Assess controls against applicable standards and regulations, including ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and the client's obligations under NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or sector equivalents, documenting the evidence behind every finding.
- Assess and rationalize OT security technology already deployed, including passive monitoring and asset visibility platforms, secure remote access, firewalls and unidirectional gateways at the IDMZ, endpoint controls where supported, and backup infrastructure; recommend the approach per gap for engagement-lead review, and justify net-new capability rather than assuming it.
- Account for AI systems in scope by identifying machine learning and analytics components in the OT environment, including ML-based anomaly detection within monitoring platforms, vendor-hosted predictive maintenance and remote diagnostics, and any pathway by which process data leaves the facility or automated action is returned to it; document the resulting conduits and trust boundaries.
- Account for operational and safety interlocks: understand how safety instrumented systems, management-of-change processes, validated environments, and turnaround windows constrain remediation, and shape recommendations consistent with the facility's actual change calendar.
- Author deliverable content: clear, well-structured, client-ready documents and presentations covering current-state architecture, gap and risk analysis, zone-and-conduit design, and a phased roadmap, for Lead Consultant or Principal Consultant review.
- Run pre-readout reviews with client SMEs, including the controls and operations personnel whose endorsement determines whether the plan is implemented; present findings to project sponsors and working-group leadership, and support the engagement lead on the executive readout to client leadership.
- Support deliverable review cycles, incorporating feedback across review iterations and driving documents toward acceptance, partnering with the WWT Program Manager on cadence and the engagement lead on quality.
- Identify and communicate risks through the project's RAID process and weekly status, escalating issues that affect scope, schedule, safety, or quality.
- Contribute to practice IP: refine OT assessment methodologies, walkdown and discovery templates, zone-and-conduit patterns, and reusable artifacts that improve delivery consistency across engagements.
Typical Deliverables
The defining output of this role is authoring the engagement's OT security deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, target-state architecture, and a phased remediation roadmap the client can fund and execute within its outage calendar. You are a primary author, and the quality of these documents is a primary performance criterion for the role. You are a primary author of the deliverable set below, working under the review of the Lead Consultant or Principal Consultant, who holds final quality accountability:
- Current-State OT Discovery & Asset Baseline: consolidated asset inventory, network architecture and dataflow documentation, protocol and communication baseline, remote access path inventory, and lifecycle and patch posture across in-scope sites.
- OT Cybersecurity Gap & Risk Assessment: control gap analysis against ISA/IEC 62443 and NIST SP 800-82, with findings prioritized by operational consequence rather than CVSS alone, and regulatory exposure mapped where NERC CIP, TSA, or sector obligations apply.
- Zone & Conduit Architecture and Segmentation Design: Purdue-aligned target-state zone model, conduit definitions and enforcement points, IDMZ design, and the broker, jump-host, or data-diode pattern selected per flow.
- OT Secure Remote Access & Monitoring Design: vendor and employee remote access architecture, passive monitoring and asset visibility sensor placement and span/tap strategy, and the integration path into enterprise SOC or OT-specific monitoring operations.
- Executive Findings & Recommendations: executive-level presentation consolidating key findings, consequence-based risk framing, strategic recommendations, and a phased roadmap sequenced against outage windows and capital cycles.
Growth & Development
- Build depth across the major control system platform families and their engineering toolchains, toward the breadth required to establish situational understanding quickly in an unfamiliar facility.
- Maintain working currency in AI security as the field develops, including the evolution of AI risk frameworks, the security implications of agentic and tool-calling systems, and the controls available to govern them; AI competence is expected of every consultant in the practice, independent of specialization.
- Expand sector range beyond your primary vertical; the regulatory drivers and risk profile differ significantly across electric utility, oil and gas, water and wastewater, discrete and process manufacturing, and pharmaceutical environments.
- Develop the executive communication capability required to own the client readout rather than support it: translating consequence-based OT risk for the VP, CxO, and board audiences responsible for funding remediation.
- Grow pursuit capability through exposure to scoping, ROM estimation, and SOW development alongside the Lead Consultant or Principal Consultant.
- Begin mentoring Consultants and Analysts on discovery method, walkdown discipline, site safety practice, and WWT delivery standards.
- Grow toward owning an engagement end to end, which is the threshold for the Lead Consultant level.
Qualifications
Experience
- 4-8 years of overall cybersecurity, industrial automation, or control systems experience with a clear focus on OT/ICS security, including a security consulting or equivalent client-facing delivery role with a portfolio of example deliverables.
- Demonstrated experience authoring client-facing OT security strategy and assessment documents (reports, architecture designs, executive presentations).
- Working command of OT protocols and their security characteristics: Modbus TCP/RTU, DNP3, EtherNet/IP and CIP, PROFINET/PROFIBUS, OPC-DA/UA, IEC 61850, IEC 60870-5-104, BACnet, or HART.
- Working knowledge of the Purdue Enterprise Reference Architecture and IDMZ design patterns, and of segmentation, conduit enforcement, and unidirectional gateway or data diode use in OT environments.
- Practical experience with OT asset visibility and monitoring platforms, including sensor placement, span and tap strategy, and the safety rationale for passive over active discovery.
- Working knowledge of OT standards and regulatory drivers: ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and one or more of NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or FDA premarket cybersecurity guidance.
- Strong data networking background, including hands-on roles supporting switches, routers, and firewalls, and a working command of VLANs, routing, ACLs, and industrial network design.
- Demonstrated understanding of the operational constraints that govern OT environments, including safety instrumented systems, management-of-change processes, validated environments, and outage windows.