~37m ago
New

Operational Technology (OT) Secure by Design SME

United StatesUnited StatesNormalmid
OtherTechnology
1 views0 saves0 applied

Quick Summary

Overview

Everforth ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to join our team in Arlington, VA (Hybrid).

Technical Tools
OtherTechnology

Everforth ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to join our team in Arlington, VA (Hybrid).

 

ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to support the Cybersecurity and Infrastructure Security Agency’s Technical Engineering and Support Services program.

The OT Secure by Design SME will provide deep technical expertise supporting CISA initiatives focused on improving the security of operational technology, industrial control systems, and critical infrastructure products. This role will work with OT manufacturers, industrial control system integrators, technology vendors, device suppliers, and critical infrastructure stakeholders to evaluate product security, assess vendor maturity, identify cybersecurity risks, and advance Secure by Design practices across the OT ecosystem.

The ideal candidate brings hands-on experience with OT/ICS technologies, industrial product security, vulnerability assessment, embedded systems, firmware or device analysis, and secure product development practices. This role will be a hybrid role.

Responsibilities

~1 min read
  • Support the development and implementation of Secure by Design strategies for OT, ICS, and industrial technology environments.
  • Provide technical guidance to OT manufacturers, PLC vendors, ICS integrators, device suppliers, and critical infrastructure stakeholders.
  • Translate Secure by Design principles into practical technical recommendations for industrial products and systems.
  • Advise stakeholders on integrating security throughout the product and system development lifecycle.
  • Support development of technical guidance, recommendations, and industry-facing materials that promote secure product development.
  • Assess OT and ICS devices across energy, water, manufacturing, and other critical infrastructure sectors.
  • Evaluate device architectures, embedded software, firmware, communications, security controls, and system interfaces.
  • Identify vulnerabilities, insecure configurations, architectural weaknesses, and systemic product-security risks.
  • Conduct or support firmware analysis, reverse engineering, and device-level security evaluation as appropriate.
  • Evaluate product security risks while accounting for operational availability, reliability, and safety requirements.
  • Assess cybersecurity maturity across OT manufacturers and technology providers.
  • Evaluate secure development lifecycle practices, vulnerability disclosure processes, patching strategies, product-support models, and supply-chain security practices.
  • Identify gaps between current vendor practices and Secure by Design principles.
  • Provide technical recommendations to manufacturers and technology providers to strengthen product security.
  • Develop repeatable approaches for assessing vendor and product-security maturity.
  • Develop repeatable and scalable testing methodologies for OT and ICS products and devices.
  • Design technical assessment approaches that evaluate hardware, firmware, software, communications, and supply-chain risks.
  • Support vulnerability identification, validation, classification, and prioritization.
  • Evaluate the effectiveness of compensating controls and mitigation strategies.
  • Document technical findings and translate assessment results into actionable recommendations for both technical and executive audiences.
  • Engage with OT manufacturers, ICS integrators, asset owners, technology vendors, and critical infrastructure organizations.
  • Support technical workshops, industry engagements, assessments, and working sessions.
  • Provide technical guidance on improving OT products and system security.
  • Identify recurring industry-wide security gaps and opportunities for broader guidance or scalable solutions.
  • Communicate complex technical findings clearly to engineering teams, leadership, government stakeholders, and external partners.

Salary Range: $200,000 - $250,000

General Description of Benefits 

  • 8+ years of cybersecurity experience, with significant experience supporting operational technology, industrial control systems, SCADA, embedded systems, or industrial product security.
  • Deep understanding of OT/ICS architectures, industrial automation, control systems, and industrial networks.
  • Demonstrated experience assessing the security of OT/ICS products, devices, embedded systems, or industrial environments.
  • Strong knowledge of NIST SP 800-82, CISA OT cybersecurity guidance, and relevant industrial cybersecurity practices and frameworks.
  • Experience with vulnerability assessment, vulnerability research, device security testing, firmware analysis, reverse engineering, or similar technical security activities.
  • Understanding of secure software and product development lifecycle practices.
  • Experience evaluating vendor or manufacturer cybersecurity maturity.
  • Knowledge of vulnerability disclosure, patch management, product security, and cybersecurity supply-chain risk.
  • Familiarity with industrial protocols such as Modbus, DNP3, OPC/OPC UA, BACnet, EtherNet/IP, or similar technologies.
  • Experience developing or applying repeatable technical assessments and testing methodologies.
  • Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders.
  • Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, Electrical Engineering, Information Technology, or a related field.
  • U.S. citizenship and ability to obtain and maintain required Public Trust suitability.

Location & Eligibility

Where is the job
United States
On-site within the country
Who can apply
US

Listing Details

First seen
October 5, 2026
Last seen
October 5, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
57%
Scored at
October 5, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Operational Technology (OT) Secure by Design SME