Job Requirements
Remote
Top Secret CI Polygraph
Career Level not specified
$117,200 - $146,500
Job Description
Why WWT?
World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe.
Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)-a collaborative ecosystem featuring state-of-the-art hardware and software-WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distributions capabilities.
With more than 14,000 team members and over 60 locations globally, WWT's culture-grounded in core values and leadership philosophies-has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada.
Want to work with highly motivated individuals on high-performance teams? Join WWT today!
What is the Solutions Consulting & Engineering (SC&E) Team and why join?
Solutions Consulting & Engineering is an organization that is Customer Focused and Solutions Led. We deliver end-to-end and emerging solutions to drive customer satisfaction, increase profitability and growth. Our success is enabled by our world-class management consulting, delivery excellence and engineering brilliance. Our goal is to bring together business acumen with full-stack technical know-how to develop innovative solutions for our clients' most complex challenges.
Position Overview:
World Wide Technology (WWT) is seeking a Security Sr. Consultant to own the technical execution of operational technology and industrial control system security engagements across critical infrastructure and manufacturing clients. This is a consulting role: you lead defined workstreams from discovery through analysis and design, and you author the deliverable content that defines the client's OT security posture and remediation plan. You are the consultant the client's representatives work with day to day, operating under the direction of a Lead Consultant or Principal Consultant who holds overall engagement accountability and final deliverable quality.
OT engagements are governed by constraints that do not apply in enterprise IT: availability and safety outrank confidentiality, change is bound to management-of-change processes and outage windows, and a meaningful share of the installed base runs unsupported operating systems on vendor-warranted equipment that cannot be patched or actively scanned. Engagements follow a consequence-driven, standards-anchored methodology: you baseline the environment through passive discovery and structured site walkdowns, model zones and conduits against the Purdue reference architecture and IEC 62443-3-2, assess controls against ISA/IEC 62443, NIST SP 800-82, and the client's applicable regulatory obligations, and sequence remediation against operational consequence and the constraints of the outage calendar.
Recommendations must be executable by the personnel responsible for operating the facility. This is a full-time position with a defined growth path toward the Lead Consultant level. Previous security consulting experience and a portfolio of client-facing deliverables are strongly preferred, as is direct time spent working in operating industrial environments.
Key Responsibilities
Own technical execution of assigned OT security workstreams, driving day-to-day progress, quality, and pace against the agreed schedule and scope, escalating scope and commercial matters to the engagement lead. Plan and conduct OT discovery: asset inventory and network baselining, control system architecture documentation, protocol and traffic analysis, remote access path enumeration, patch and lifecycle posture, backup and recovery review, and third-party and vendor access review. Conduct site walkdowns and structured interviews with controls engineers, plant IT, operations, maintenance, safety, and vendor personnel; document the environment as operated and reconcile it against drawings and asset records, which are frequently outdated. Operate safely on client sites: complete required site safety training and work within client PPE, escort, permit, and lockout/tagout requirements without exception. Model zones and conduits against the Purdue Enterprise Reference Architecture and IEC 62443-3-2, documenting current-state trust boundaries, IDMZ posture, and the cross-level flows that deviate from the model. Assess controls against applicable standards and regulations, including ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and the client's obligations under NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or sector equivalents, documenting the evidence behind every finding. Assess and rationalize OT security technology already deployed, including passive monitoring and asset visibility platforms, secure remote access, firewalls and unidirectional gateways at the IDMZ, endpoint controls where supported, and backup infrastructure; recommend the approach per gap for engagement-lead review, and justify net-new capability rather than assuming it. Account for AI systems in scope by identifying machine learning and analytics components in the OT environment, including ML-based anomaly detection within monitoring platforms, vendor-hosted predictive maintenance and remote diagnostics, and any pathway by which process data leaves the facility or automated action is returned to it; document the resulting conduits and trust boundaries. Account for operational and safety interlocks: understand how safety instrumented systems, management-of-change processes, validated environments, and turnaround windows constrain remediation, and shape recommendations consistent with the facility's actual change calendar. Author deliverable content: clear, well-structured, client-ready documents and presentations covering current-state architecture, gap and risk analysis, zone-and-conduit design, and a phased roadmap, for Lead Consultant or Principal Consultant review. Run pre-readout reviews with client SMEs, including the controls and operations personnel whose endorsement determines whether the plan is implemented; present findings to project sponsors and working-group leadership, and support the engagement lead on the executive readout to client leadership. Support deliverable review cycles, incorporating feedback across review iterations and driving documents toward acceptance, partnering with the WWT Program Manager on cadence and the engagement lead on quality. Identify and communicate risks through the project's RAID process and weekly status, escalating issues that affect scope, schedule, safety, or quality. Contribute to practice IP: refine OT assessment methodologies, walkdown and discovery templates, zone-and-conduit patterns, and reusable artifacts that improve delivery consistency across engagements.
Typical Deliverables
The defining output of this role is authoring the engagement's OT security deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, target-state architecture, and a phased remediation roadmap the client can fund and execute within its outage calendar. You are a primary author, and the quality of these documents is a primary performance criterion for the role.
You are a primary author of the deliverable set below, working under the review of the Lead Consultant or Principal Consultant, who holds final quality accountability:
Current-State OT Discovery & Asset Baseline: consolidated asset inventory, network architecture and dataflow documentation, protocol and communication baseline, remote access path inventory, and lifecycle and patch posture across in-scope sites. OT Cybersecurity Gap & Risk Assessment: control gap analysis against ISA/IEC 62443 and NIST SP 800-82, with findings prioritized by operational consequence rather than CVSS alone, and regulatory exposure mapped where NERC CIP, TSA, or sector obligations apply. Zone & Conduit Architecture and Segmentation Design: Purdue-aligned target-state zone model, conduit definitions and enforcement points, IDMZ design, and the broker, jump-host, or data-diode pattern selected per flow. OT Secure Remote Access & Monitoring Design: vendor and employee remote access architecture, passive monitoring and asset visibility sensor placement and span/tap strategy, and the integration path into enterprise SOC or OT-specific monitoring operations. Executive Findings & Recommendations: executive-level presentation consolidating key findings, consequence-based risk framing, strategic recommendations, and a phased roadmap sequenced against outage windows and capital cycles.
Growth & Development
Build depth across the major control system platform families and their engineering toolchains, toward the breadth required to establish situational understanding quickly in an unfamiliar facility. Maintain working currency in AI security as the field develops, including the evolution of AI risk frameworks, the security implications of agentic and tool-calling systems, and the controls available to govern them; AI competence is expected of every consultant in the practice, independent of specialization. Expand sector range beyond your primary vertical; the regulatory drivers and risk profile differ significantly across electric utility, oil and gas, water and wastewater, discrete and process manufacturing, and pharmaceutical environments. Develop the executive communication capability required to own the client readout rather than support it: translating consequence-based OT risk for the VP, CxO, and board audiences responsible for funding remediation. Grow pursuit capability through exposure to scoping, ROM estimation, and SOW development alongside the Lead Consultant or Principal Consultant. Begin mentoring Consultants and Analysts on discovery method, walkdown discipline, site safety practice, and WWT delivery standards. Grow toward owning an engagement end to end, which is the threshold for the Lead Consultant level.
Qualifications
Experience
Specialized Knowledge, Skills & Abilities
Working knowledge and consulting experience in at least three of the following areas:
Professional Attributes
Professional Behaviors
Beyond technical delivery, this role is expected to demonstrate the following in front of clients and within the WWT team:
Want to learn more about Consulting & Security Services? Check us out on our platform:
https://www.wwt.com/consulting-services
https://www.wwt.com/category/security-transformation
Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $117,200 to $146,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.
The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US benefits website at wwt.com/us-benefits.
We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT
remains a great place to work for all!
If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process.
World Wide Technology is an Equal Opportunity Employer.
If you have any questions or concerns about this posting, please email taposting@wwt.com .
#LI-TB1
World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe.
Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)-a collaborative ecosystem featuring state-of-the-art hardware and software-WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distributions capabilities.
With more than 14,000 team members and over 60 locations globally, WWT's culture-grounded in core values and leadership philosophies-has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada.
Want to work with highly motivated individuals on high-performance teams? Join WWT today!
What is the Solutions Consulting & Engineering (SC&E) Team and why join?
Solutions Consulting & Engineering is an organization that is Customer Focused and Solutions Led. We deliver end-to-end and emerging solutions to drive customer satisfaction, increase profitability and growth. Our success is enabled by our world-class management consulting, delivery excellence and engineering brilliance. Our goal is to bring together business acumen with full-stack technical know-how to develop innovative solutions for our clients' most complex challenges.
Position Overview:
World Wide Technology (WWT) is seeking a Security Sr. Consultant to own the technical execution of operational technology and industrial control system security engagements across critical infrastructure and manufacturing clients. This is a consulting role: you lead defined workstreams from discovery through analysis and design, and you author the deliverable content that defines the client's OT security posture and remediation plan. You are the consultant the client's representatives work with day to day, operating under the direction of a Lead Consultant or Principal Consultant who holds overall engagement accountability and final deliverable quality.
OT engagements are governed by constraints that do not apply in enterprise IT: availability and safety outrank confidentiality, change is bound to management-of-change processes and outage windows, and a meaningful share of the installed base runs unsupported operating systems on vendor-warranted equipment that cannot be patched or actively scanned. Engagements follow a consequence-driven, standards-anchored methodology: you baseline the environment through passive discovery and structured site walkdowns, model zones and conduits against the Purdue reference architecture and IEC 62443-3-2, assess controls against ISA/IEC 62443, NIST SP 800-82, and the client's applicable regulatory obligations, and sequence remediation against operational consequence and the constraints of the outage calendar.
Recommendations must be executable by the personnel responsible for operating the facility. This is a full-time position with a defined growth path toward the Lead Consultant level. Previous security consulting experience and a portfolio of client-facing deliverables are strongly preferred, as is direct time spent working in operating industrial environments.
Key Responsibilities
Typical Deliverables
The defining output of this role is authoring the engagement's OT security deliverables: comprehensive, client-ready documents that consolidate current-state discovery, gap and risk analysis, target-state architecture, and a phased remediation roadmap the client can fund and execute within its outage calendar. You are a primary author, and the quality of these documents is a primary performance criterion for the role.
You are a primary author of the deliverable set below, working under the review of the Lead Consultant or Principal Consultant, who holds final quality accountability:
Growth & Development
Qualifications
Experience
- 4-8 years of overall cybersecurity, industrial automation, or control systems experience with a clear focus on OT/ICS security, including a security consulting or equivalent client-facing delivery role with a portfolio of example deliverables.
- Demonstrated experience authoring client-facing OT security strategy and assessment documents (reports, architecture designs, executive presentations).
- Working command of OT protocols and their security characteristics: Modbus TCP/RTU, DNP3, EtherNet/IP and CIP, PROFINET/PROFIBUS, OPC-DA/UA, IEC 61850, IEC 60870-5-104, BACnet, or HART.
- Working knowledge of the Purdue Enterprise Reference Architecture and IDMZ design patterns, and of segmentation, conduit enforcement, and unidirectional gateway or data diode use in OT environments.
- Practical experience with OT asset visibility and monitoring platforms, including sensor placement, span and tap strategy, and the safety rationale for passive over active discovery.
- Working knowledge of OT standards and regulatory drivers: ISA/IEC 62443, NIST SP 800-82r3, NIST CSF 2.0, and one or more of NERC CIP, TSA Security Directives, AWIA, CISA Cross-Sector Cybersecurity Performance Goals, or FDA premarket cybersecurity guidance.
- Strong data networking background, including hands-on roles supporting switches, routers, and firewalls, and a working command of VLANs, routing, ACLs, and industrial network design.
- Demonstrated understanding of the operational constraints that govern OT remediation: availability and safety precedence, management of change, outage and turnaround windows, vendor warranty and support boundaries, unsupported and legacy operating systems, and the practical limits of patching in a validated or safety-rated environment.
- Preferred: direct time working in an operating industrial environment (controls engineering, plant IT, maintenance, or operations); familiarity with safety instrumented systems and IEC 61511; exposure to OT incident response and tabletop facilitation; familiarity with ICS threat intelligence and the OT-specific threat landscape (TRITON, INDUSTROYER, PIPEDREAM); PLC or SCADA programming experience.
- Certifications desired: ISA/IEC 62443 Cybersecurity Specialist, GICSP, GRID, GCIP, CISSP, CISSP-ISSAP, or CISM.
Specialized Knowledge, Skills & Abilities
Working knowledge and consulting experience in at least three of the following areas:
- Operational Technologies and Environments (ICS, SCADA, DCS, BAS, IIoT, IoMT)
- Industrial Network Architecture and Segmentation (Purdue model, IDMZ, zones and conduits)
- OT Asset Visibility, Monitoring, and Detection
- Risk Management and Assessments, including consequence-driven methods
- Policy, Governance, and Compliance (ISA/IEC 62443, NERC CIP, TSA, NIST)
- Secure Remote Access and Third-Party/Vendor Access Governance
- Incident Response and Recovery in OT environments
- Threat and Vulnerability Management in constrained environments
- Network and Systems Security
- Identity and Access Management
Professional Attributes
- Professional writing is required: strong, demonstrable ability to produce technical and business-related artifacts at a client-deliverable standard.
- Able to perform concurrent tasks in complex environments under shifting priorities and timelines.
- Able to communicate and modify approach, language, and style across a wide range of audiences, from controls engineers and plant operators to VP/CxO-level stakeholders, and to establish credibility with operations personnel who may be skeptical of security initiatives.
- Collaborative, with the ability to manage conflicting interests across security, operations, and safety, and to operate effectively amid ambiguity and incomplete documentation.
- Self-directed and proactive, with strong problem-solving instincts and intellectual curiosity about evolving technology.
- Willing and able to travel to client facilities on an occasional basis, and to work within plant safety, PPE, escort, and permit requirements.
Professional Behaviors
Beyond technical delivery, this role is expected to demonstrate the following in front of clients and within the WWT team:
- Safety first: treat client site safety rules as non-negotiable, and never allow a security objective to override an operational or safety constraint. A recommendation that introduces risk of a process upset is not acceptable, regardless of its security merit.
- Ownership and accountability: take responsibility for the outcomes of your workstreams and the quality of every deliverable you author, and follow through on commitments without being chased.
- Trusted advisor: build credibility quickly with both security and operations audiences, give candid and well-reasoned recommendations, and represent WWT as a partner the client relies on rather than an order-taker.
- Clear communication: translate technical complexity into plain language for the audience at hand, listen actively, and keep stakeholders informed without surprises.
- Integrity: give honest assessments even when the message is hard, and protect the client's interests and WWT's reputation in every recommendation.
Want to learn more about Consulting & Security Services? Check us out on our platform:
https://www.wwt.com/consulting-services
https://www.wwt.com/category/security-transformation
Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $117,200 to $146,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.
The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
- Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
- Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
- Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
- Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program
Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US benefits website at wwt.com/us-benefits.
We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT
remains a great place to work for all!
If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process.
World Wide Technology is an Equal Opportunity Employer.
If you have any questions or concerns about this posting, please email taposting@wwt.com .
#LI-TB1
group id: 10106058