Industrial OT Cybersecurity Engineer

Job ID: 40355283

Budget: $25 – $50 USD

I need an experienced cybersecurity engineer who knows how to secure manufacturing OT environments from the ground up. Our plant floor runs a mix of SCADA, PLC and DCS systems on VMware / ESXi virtual infrastructure, and I’m kicking off a project that tightens every layer—from the hypervisor to the operator workstation—while staying fully aligned with ISA/IEC 62443 and NIST guidelines.

Scope of work
• Assess the present security posture, map risks to ISA/IEC 62443 zones & conduits, and deliver a concise risk report.
• Recommend and implement security improvements that will not disrupt production or existing integrations.
• Verify every change through functional testing and validation before sign-off.

Core technical tasks
• Deploy and tune an endpoint detection & response (EDR) solution across 50 VMs.
• Upgrade guest operating systems, apply the latest security patches, and document version baselines.
• Configure and optimise an IDS that understands OT protocols.
• Perform OS and service hardening following CIS benchmarks.
• Secure remote access with a VPN architecture built for least privilege.
• Strengthen privileged-access management (PAM) and roll out MFA to operators and maintenance teams.

Acceptance criteria
1. EDR agents report healthy status on all 50 VMs.
2. Patch levels meet or exceed vendor recommendations.
3. IDS generates no false positives during a 48-hour production run.
4. Hardening checks pass an independent audit tool.
5. VPN and PAM workflows demonstrate MFA enforcement without downtime.
6. Final validation report confirms compliance to ISA/IEC 62443 relevant sections.

If you bring solid OT cybersecurity experience, especially in manufacturing, and can speak fluently about SCADA, PLC and DCS nuances, I’d like to hear how you would approach this engagement and the tools you prefer.