Summary
Job Title: OT Security SpecialistDuration: 3 Months
Location: Richmond, VA 23219
Work Module: Hybrid
Position Summary
The OT Security Specialist will provide industrial control system and operational technology expertise throughout the assessment. This role will guide safe testing of the selected TOC, field cabinet, field-connected assets, communications paths, and any approved controlled device scenario.
The specialist will determine whether proposed testing techniques are suitable for the operational environment and will help protect system availability, traffic operations, and public safety.
Key Responsibilities
Review the architecture of the OT environment, including the Central Office, selected TOC, field network, Azure DMZ, LTE connectivity, and field cabinet.
Interpret the OT environment using the Purdue Model and identify relevant security zones and conduits.
Review approved OT network diagrams, device configurations, field connectivity, industrial protocols, and operational dependencies.
Identify testing methods that are safe for the selected operational systems and connected field devices.
Establish asset-specific safety constraints, stop conditions, emergency procedures, and prohibited actions for inclusion in the ROE.
Support testing of the selected TOC and approved field-connected assets.
Evaluate the security of field communications paths and field-adjacent access opportunities.
Support approved physical access and controlled device scenarios.
Evaluate whether field access could provide unauthorized connectivity to internal OT resources.
Assess OT host hardening, default services, management interfaces, insecure protocols, trust relationships, and segmentation controls.
Advise the testing team when active validation could affect operational availability or device stability.
Prevent unauthorized PLC logic changes, firmware updates, configuration changes, persistence, denial-of-service activity, or other unsafe actions.
Coordinate testing with OIS, TOC personnel, field operations staff, and escorts.
Evaluate technical findings in the context of operational impact, public safety, recoverability, and compensating controls.
Map applicable findings to MITRE ATT&CK for ICS and NIST SP 800-82.
Develop practical remediation recommendations that account for OT availability, maintenance windows, equipment lifecycle, and operational constraints.
Prepare technical content for the field, physical, controlled device, TOC, and consolidated assessment reports.
Support final debriefing and retesting of remediated OT findings.
Required Skills
OT and ICS cybersecurity
SCADA environments and industrial architecture
Purdue Model segmentation
Industrial network protocols
Field device and cabinet security
OT network discovery and asset identification
Safe assessment of operational systems
OT vulnerability analysis
Field communications and remote-access security
OT logging, monitoring, and detection
Physical and field-access risk analysis
Operational safety and availability protection
MITRE ATT&CK for ICS
NIST SP 800-82
Technical report writing and risk communication
Required Experience
Minimum five years of OT, ICS, SCADA, or industrial cybersecurity experience
Experience assessing operational networks and field-connected devices
Experience conducting or supporting penetration testing in operationally sensitive environments
Experience applying safety restrictions and stop-work procedures during technical testing
Experience evaluating OT segmentation, remote access, and field connectivity
Experience documenting technical findings in terms of both cybersecurity risk and operational impact
Experience working with network engineers, penetration testers, SOC teams, and operations personnel
Desired Experience
Experience with transportation systems, traffic operations centers, roadside technology, cameras, dynamic message signs, sensors, or similar field devices
Experience with LTE-connected industrial or field networks
Experience assessing cloud-connected OT boundary environments
Experience supporting public-sector or critical infrastructure organizations
Familiarity with NIST SP 800-53, CIS Controls, SEC530, SEC520, and SEC502
Desired Certifications
Global Industrial Cyber Security Professional, GICSP
GIAC Response and Industrial Defense, GRID
Certified Information Systems Security Professional, CISSP
Job Description
Job Title: OT Security SpecialistDuration: 3 Months
Location: Richmond, VA 23219
Work Module: Hybrid
Position Summary
The OT Security Specialist will provide industrial control system and operational technology expertise throughout the assessment. This role will guide safe testing of the selected TOC, field cabinet, field-connected assets, communications paths, and any approved controlled device scenario.
The specialist will determine whether proposed testing techniques are suitable for the operational environment and will help protect system availability, traffic operations, and public safety.
Key Responsibilities
Review the architecture of the OT environment, including the Central Office, selected TOC, field network, Azure DMZ, LTE connectivity, and field cabinet.
Interpret the OT environment using the Purdue Model and identify relevant security zones and conduits.
Review approved OT network diagrams, device configurations, field connectivity, industrial protocols, and operational dependencies.
Identify testing methods that are safe for the selected operational systems and connected field devices.
Establish asset-specific safety constraints, stop conditions, emergency procedures, and prohibited actions for inclusion in the ROE.
Support testing of the selected TOC and approved field-connected assets.
Evaluate the security of field communications paths and field-adjacent access opportunities.
Support approved physical access and controlled device scenarios.
Evaluate whether field access could provide unauthorized connectivity to internal OT resources.
Assess OT host hardening, default services, management interfaces, insecure protocols, trust relationships, and segmentation controls.
Advise the testing team when active validation could affect operational availability or device stability.
Prevent unauthorized PLC logic changes, firmware updates, configuration changes, persistence, denial-of-service activity, or other unsafe actions.
Coordinate testing with OIS, TOC personnel, field operations staff, and escorts.
Evaluate technical findings in the context of operational impact, public safety, recoverability, and compensating controls.
Map applicable findings to MITRE ATT&CK for ICS and NIST SP 800-82.
Develop practical remediation recommendations that account for OT availability, maintenance windows, equipment lifecycle, and operational constraints.
Prepare technical content for the field, physical, controlled device, TOC, and consolidated assessment reports.
Support final debriefing and retesting of remediated OT findings.
Required Skills
OT and ICS cybersecurity
SCADA environments and industrial architecture
Purdue Model segmentation
Industrial network protocols
Field device and cabinet security
OT network discovery and asset identification
Safe assessment of operational systems
OT vulnerability analysis
Field communications and remote-access security
OT logging, monitoring, and detection
Physical and field-access risk analysis
Operational safety and availability protection
MITRE ATT&CK for ICS
NIST SP 800-82
Technical report writing and risk communication
Required Experience
Minimum five years of OT, ICS, SCADA, or industrial cybersecurity experience
Experience assessing operational networks and field-connected devices
Experience conducting or supporting penetration testing in operationally sensitive environments
Experience applying safety restrictions and stop-work procedures during technical testing
Experience evaluating OT segmentation, remote access, and field connectivity
Experience documenting technical findings in terms of both cybersecurity risk and operational impact
Experience working with network engineers, penetration testers, SOC teams, and operations personnel
Desired Experience
Experience with transportation systems, traffic operations centers, roadside technology, cameras, dynamic message signs, sensors, or similar field devices
Experience with LTE-connected industrial or field networks
Experience assessing cloud-connected OT boundary environments
Experience supporting public-sector or critical infrastructure organizations
Familiarity with NIST SP 800-53, CIS Controls, SEC530, SEC520, and SEC502
Desired Certifications
Global Industrial Cyber Security Professional, GICSP
GIAC Response and Industrial Defense, GRID
Certified Information Systems Security Professional, CISSP
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Deputy Director of Community Development
- Charlottesville, Virginia
- ALBEMARLE COUNTY, VA
- Sep 13, 2026
-
Temporary Help - Fire Rescue
- Charlottesville, Virginia
- ALBEMARLE COUNTY, VA
- Sep 13, 2026
-
Certified Sheriff's Office Deputy or Sheriff's Office Recruit
- Charlottesville, Virginia
- ALBEMARLE COUNTY, VA
- Aug 20, 2026
-
Sheriff's Office Deputy Part-Time
- Charlottesville, Virginia
- ALBEMARLE COUNTY, VA
- Aug 20, 2026
-
Director of the Office of Housing
- Charlottesville, Virginia
- ALBEMARLE COUNTY, VA
- Sep 23, 2026
-
$80,000–$90,000 - 90,000 Annually
Senior Accountant - City of Williamsburg, VA
- Williamsburg, Virginia
- City of Williamsburg, VA
- Sep 18, 2026