Operational Technology (OT) Secure by Design SME

payments$200,000 – $250,000/yrschedule2 days ago
sync_altWork style:Hybrid
schoolEducation:High school
Apply Nowopen_in_new

Job description

Everforth ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to join our team in Arlington, VA (Hybrid).

ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to support the Cybersecurity and Infrastructure Security Agency’s Technical Engineering and Support Services program.

The OT Secure by Design SME will provide deep technical expertise supporting CISA initiatives focused on improving the security of operational technology, industrial control systems, and critical infrastructure products. This role will work with OT manufacturers, industrial control system integrators, technology vendors, device suppliers, and critical infrastructure stakeholders to evaluate product security, assess vendor maturity, identify cybersecurity risks, and advance Secure by Design practices across the OT ecosystem.

The ideal candidate brings hands-on experience with OT/ICS technologies, industrial product security, vulnerability assessment, embedded systems, firmware or device analysis, and secure product development practices. This role will be a hybrid role.

Key Responsibilities

OT/ICS Secure by Design Strategy

  • Support the development and implementation of Secure by Design strategies for OT, ICS, and industrial technology environments.
  • Provide technical guidance to OT manufacturers, PLC vendors, ICS integrators, device suppliers, and critical infrastructure stakeholders.
  • Translate Secure by Design principles into practical technical recommendations for industrial products and systems.
  • Advise stakeholders on integrating security throughout the product and system development lifecycle.
  • Support development of technical guidance, recommendations, and industry-facing materials that promote secure product development.

OT Product and Device Security Assessment

  • Assess OT and ICS devices across energy, water, manufacturing, and other critical infrastructure sectors.
  • Evaluate device architectures, embedded software, firmware, communications, security controls, and system interfaces.
  • Identify vulnerabilities, insecure configurations, architectural weaknesses, and systemic product-security risks.
  • Conduct or support firmware analysis, reverse engineering, and device-level security evaluation as appropriate.
  • Evaluate product security risks while accounting for operational availability, reliability, and safety requirements.

Vendor Security and Maturity Assessment

  • Assess cybersecurity maturity across OT manufacturers and technology providers.
  • Evaluate secure development lifecycle practices, vulnerability disclosure processes, patching strategies, product-support models, and supply-chain security practices.
  • Identify gaps between current vendor practices and Secure by Design principles.
  • Provide technical recommendations to manufacturers and technology providers to strengthen product security.
  • Develop repeatable approaches for assessing vendor and product-security maturity.

Security Testing and Technical Evaluation

  • Develop repeatable and scalable testing methodologies for OT and ICS products and devices.
  • Design technical assessment approaches that evaluate hardware, firmware, software, communications, and supply-chain risks.
  • Support vulnerability identification, validation, classification, and prioritization.
  • Evaluate the effectiveness of compensating controls and mitigation strategies.
  • Document technical findings and translate assessment results into actionable recommendations for both technical and executive audiences.

Critical Infrastructure and Industry Engagement

  • Engage with OT manufacturers, ICS integrators, asset owners, technology vendors, and critical infrastructure organizations.
  • Support technical workshops, industry engagements, assessments, and working sessions.
  • Provide technical guidance on improving OT products and system security.
  • Identify recurring industry-wide security gaps and opportunities for broader guidance or scalable solutions.
  • Communicate complex technical findings clearly to engineering teams, leadership, government stakeholders, and external partners.

Salary Range: $200,000 - $250,000

General Description of Benefits

Skills mentioned

Apply for this job

Use the application link supplied with this listing to apply to ECS FEDERAL LLC. Check the destination before entering personal information.

Apply Nowopen_in_new