Operational Technology Security Consultant

    United States
    Full-Time
    Mid (3-6 yrs)
    Legal & Compliance
    Posted on June 26, 2026
    Position Summary:

    The Operational Technology (OT) Cybersecurity Consultant assesses the security posture and maturity of OT environments for clients across manufacturing, energy, utilities, and other critical infrastructure sectors. This role involves conducting stakeholder interviews, reviewing OT documentation, evaluating security practices against industry frameworks, and developing maturity assessment reports with remediation recommendations. The Consultant presents findings and strategic guidance to clients while working with Project Managers, Directors, and Delivery teams to manage project scope and timelines.

    What You'll Do
  1. Maintain current knowledge of OT security standards, regulatory developments, and industry trends through ongoing professional development and relevant certifications
  2. Support and guide OT risk and security discussions with technical teams, operations staff, and executive stakeholders
  3. Conduct stakeholder interviews and review OT-related policies, procedures, architecture documentation, and compliance records to understand organizational OT environments and priorities
  4. Assess client environments against OT security practices and compliance posture against IEC 62443, NIST SP 800-82, NIST CSF, NERC CIP, NIS2 Directive, EU Cyber Resilience Act, C2M2, and other relevant OT standards and frameworks
  5. Develop maturity assessment and benchmarking reports identifying OT security gaps, current state findings, and prioritized remediation recommendations
  6. Develop sequenced remediation roadmaps with prioritized activities, timelines, and implementation guidance to address identified OT security gaps
  7. Advise clients on OT security program structure, governance frameworks, organizational roles and responsibilities, and recommended policies and procedures
  8. Present assessment findings, risk analysis, and strategic recommendations to clients and their leadership through executive briefings and detailed reports
  9. Support other Cyber Risk Advisory consulting engagements when necessary to maintain team capacity
  10. What You'll Bring
  11. At least 4 years of working experience in operational technology security, OT risk assessment, or related infrastructure security roles
  12. Bachelor's degree in Engineering, Computer Science, Information Systems, or related field, or equivalent combination of education and experience demonstrating OT security expertise
  13. Direct experience in OT environments such as manufacturing, energy, utilities, or other critical infrastructure sectors
  14. Hands-on experience with Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems
  15. Knowledge of control system technologies, industrial automation architectures, and OT-specific networking environments
  16. Expertise in OT security assessment frameworks including IEC 62443, NIST SP 800-82, and industry-specific requirements such as NERC CIP
  17. Understanding of emerging OT regulatory requirements including NIS2 Directive, EU Cyber Resilience Act, and other sector-specific directives
  18. Strong analytical and critical thinking abilities
  19. Strong oral and written communication skills when presenting technical findings to both technical and non-technical audiences
  20. Bonus Points
  21. GICSP (Global Industrial Cyber Security Professional) certification
  22. CISM certification
  23. CISSP certification
  24. GRID (GIAC Response and Industrial Defense) certification
  25. GCIH (GIAC Certified Incident Handler) certification
  26. C2M2 (Cybersecurity Capability Maturity Model) assessment experience
  27. NIST Cybersecurity Framework (CSF) assessment and implementation experience
  28. Incident response experience in OT or critical infrastructure environments
  29. Business continuity or disaster recovery experience in OT environments
  30. Experience with safety-critical systems and understanding of functional safety standards (IEC 61508, ISO 10218)
  31. Technical writing experience for policy and procedure development
  32. Cloud platform experience relevant to OT environments or industrial IoT implementations
  33. Why You’ll Want to Join Us

    At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.

    Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

    At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.

    Company:  Coalfire

    Provides cybersecurity and compliance services for tech, healthcare, and finance industries.
    Remote-First Company
    1001-5000 employees
    Cybersecurity
    HQ: United States