GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. They are seeking a Principal OT Security Engineer to lead OT security engineering engagements and advance their OT service delivery methodology while cultivating client relationships and contributing to business development.
Responsibilities:
- Lead and oversee OT security engineering engagements, including deployment and optimization of OT security tools, health-checks of existing OT security programs, driving configuration and architecture decisions in collaboration with clients and vendors, and leading OT security architecture assessments
- Define and advance GuidePoint's OT service delivery methodology, setting technical standards and quality benchmarks for the broader OT practice
- Author and review comprehensive services deliverables that are proficiently tailored to both technical and executive audiences, fully detailing technical execution, core deficiencies, business impact, and strategic remediation roadmaps
- Serve as a subject matter expert (SME) and final technical escalation point for complex OT engagements across the practice
- Perpetually strengthen and disseminate relevant skills, knowledge, and capabilities to keep GuidePoint and its clients at the forefront of the OT security industry
- Cultivate and expand senior client relationships, acting as a trusted advisor to client leadership and representing GuidePoint at the highest levels
- Drive cross-functional collaboration to mature and differentiate GuidePoint's OT service offerings in alignment with the SANS Five ICS Critical Controls and other leading frameworks
- Contribute to business development through thought leadership, conference presentations, whitepaper authorship, and active participation in pre-sales and proposal activities
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Requirements:
- Deep expertise in OT, ICS, SCADA, IIoT, network architecture, industrial cybersecurity design, and program strategy is required
- Lead and oversee OT security engineering engagements, including deployment and optimization of OT security tools, health-checks of existing OT security programs, driving configuration and architecture decisions in collaboration with clients and vendors, and leading OT security architecture assessments
- Define and advance GuidePoint's OT service delivery methodology, setting technical standards and quality benchmarks for the broader OT practice
- Author and review comprehensive services deliverables that are proficiently tailored to both technical and executive audiences, fully detailing technical execution, core deficiencies, business impact, and strategic remediation roadmaps
- Serve as a subject matter expert (SME) and final technical escalation point for complex OT engagements across the practice
- Perpetually strengthen and disseminate relevant skills, knowledge, and capabilities to keep GuidePoint and its clients at the forefront of the OT security industry
- Cultivate and expand senior client relationships, acting as a trusted advisor to client leadership and representing GuidePoint at the highest levels
- Drive cross-functional collaboration to mature and differentiate GuidePoint's OT service offerings in alignment with the SANS Five ICS Critical Controls and other leading frameworks
- Contribute to business development through thought leadership, conference presentations, whitepaper authorship, and active participation in pre-sales and proposal activities
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- Deep knowledge of the Purdue Model Framework and PERA architecture
- Minimum of ten (10) years of experience performing security services related to OT
- Minimum of seven (7) years of hands-on experience architecting, designing, deploying, and operationalizing OT security tools such as Claroty, Dragos, Forescout, Nozomi, Tenable OT, or equivalent
- Ten or more (10+) combined years of OT network architecture and security design experience required
- Demonstrated Operational Technology Penetration Testing (OTPT) experience required
- SANS GICSP, GRID, or equivalent advanced OT/ICS security certification required
- Expert-level knowledge of ISA/IEC 62443, NIST CSF/SP 800-82, SANS ICS Critical Controls, TSA Directives, NERC CIP, and other OT best practice security frameworks required
- Vendor certifications strongly preferred
- Multiple certifications strongly preferred