user avatar

Operational Technology (OT) Secure by Design SME

ECS

Posted today

Job Requirements

Arlington, VA
Public Trust CI Polygraph
Career Level not specified
$200,000 - $250,000

Job Description

Job Description
Everforth ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to join our team in Arlington, VA (Hybrid).

ECS is seeking an Operational Technology (OT) Secure by Design Subject Matter Expert (SME) to support the Cybersecurity and Infrastructure Security Agency's Technical Engineering and Support Services program.

The OT Secure by Design SME will provide deep technical expertise supporting CISA initiatives focused on improving the security of operational technology, industrial control systems, and critical infrastructure products. This role will work with OT manufacturers, industrial control system integrators, technology vendors, device suppliers, and critical infrastructure stakeholders to evaluate product security, assess vendor maturity, identify cybersecurity risks, and advance Secure by Design practices across the OT ecosystem.

The ideal candidate brings hands-on experience with OT/ICS technologies, industrial product security, vulnerability assessment, embedded systems, firmware or device analysis, and secure product development practices. This role will be a hybrid role.

Key Responsibilities

OT/ICS Secure by Design Strategy
  • Support the development and implementation of Secure by Design strategies for OT, ICS, and industrial technology environments.
  • Provide technical guidance to OT manufacturers, PLC vendors, ICS integrators, device suppliers, and critical infrastructure stakeholders.
  • Translate Secure by Design principles into practical technical recommendations for industrial products and systems.
  • Advise stakeholders on integrating security throughout the product and system development lifecycle.
  • Support development of technical guidance, recommendations, and industry-facing materials that promote secure product development.

OT Product and Device Security Assessment
  • Assess OT and ICS devices across energy, water, manufacturing, and other critical infrastructure sectors.
  • Evaluate device architectures, embedded software, firmware, communications, security controls, and system interfaces.
  • Identify vulnerabilities, insecure configurations, architectural weaknesses, and systemic product-security risks.
  • Conduct or support firmware analysis, reverse engineering, and device-level security evaluation as appropriate.
  • Evaluate product security risks while accounting for operational availability, reliability, and safety requirements.

Vendor Security and Maturity Assessment
  • Assess cybersecurity maturity across OT manufacturers and technology providers.
  • Evaluate secure development lifecycle practices, vulnerability disclosure processes, patching strategies, product-support models, and supply-chain security practices.
  • Identify gaps between current vendor practices and Secure by Design principles.
  • Provide technical recommendations to manufacturers and technology providers to strengthen product security.
  • Develop repeatable approaches for assessing vendor and product-security maturity.

Security Testing and Technical Evaluation
  • Develop repeatable and scalable testing methodologies for OT and ICS products and devices.
  • Design technical assessment approaches that evaluate hardware, firmware, software, communications, and supply-chain risks.
  • Support vulnerability identification, validation, classification, and prioritization.
  • Evaluate the effectiveness of compensating controls and mitigation strategies.
  • Document technical findings and translate assessment results into actionable recommendations for both technical and executive audiences.

Critical Infrastructure and Industry Engagement
  • Engage with OT manufacturers, ICS integrators, asset owners, technology vendors, and critical infrastructure organizations.
  • Support technical workshops, industry engagements, assessments, and working sessions.
  • Provide technical guidance on improving OT products and system security.
  • Identify recurring industry-wide security gaps and opportunities for broader guidance or scalable solutions.
  • Communicate complex technical findings clearly to engineering teams, leadership, government stakeholders, and external partners.

Salary Range: $200,000 - $250,000

Required Skills
  • 8+ years of cybersecurity experience, with significant experience supporting operational technology, industrial control systems, SCADA, embedded systems, or industrial product security.
  • Deep understanding of OT/ICS architectures, industrial automation, control systems, and industrial networks.
  • Demonstrated experience assessing the security of OT/ICS products, devices, embedded systems, or industrial environments.
  • Strong knowledge of NIST SP 800-82, CISA OT cybersecurity guidance, and relevant industrial cybersecurity practices and frameworks.
  • Experience with vulnerability assessment, vulnerability research, device security testing, firmware analysis, reverse engineering, or similar technical security activities.
  • Understanding of secure software and product development lifecycle practices.
  • Experience evaluating vendor or manufacturer cybersecurity maturity.
  • Knowledge of vulnerability disclosure, patch management, product security, and cybersecurity supply-chain risk.
  • Familiarity with industrial protocols such as Modbus, DNP3, OPC/OPC UA, BACnet, EtherNet/IP, or similar technologies.
  • Experience developing or applying repeatable technical assessments and testing methodologies.
  • Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders.
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Electrical Engineering, Information Technology, or a related field.
  • U.S. citizenship and ability to obtain and maintain required Public Trust suitability.
Desired Skills
  • GICSP, ISA/IEC 62443 Cybersecurity Specialist, CISSP, GRID, GCIP, or comparable OT/product-security certification.
  • Experience working directly with OT manufacturers, industrial technology vendors, or product-development organizations.
  • Experience with embedded systems, hardware security, firmware analysis, or reverse engineering tools.
  • Experience conducting Secure by Design, product-security, or manufacturer maturity assessments.
  • Familiarity with SBOMs, vulnerability disclosure programs, CVE processes, and software supply-chain security.
  • Experience with NERC CIP, DOE cybersecurity requirements, or other critical infrastructure sector requirements.
  • Experience supporting cybersecurity initiatives across energy, water, manufacturing, transportation, or other critical infrastructure sectors.
  • Experience developing technical cybersecurity guidance for government or industry audiences.
  • Experience engaging with senior government officials, industry executives, engineers, and technical practitioners.

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven


Meet the challenge. Make a difference with Everforth ECS!
group id: 10112231A
Find ECS on Social Media
Recruiters
user avatar
About Us
ECS, a key segment of ASGN Incorporated, is a trusted IT systems integrator serving government agencies. ECS provides modern digital solutions that enable fast and efficient decision making and support the effective execution of government agency operations. ECS’ leading-edge AI, cybersecurity, and open data management solutions boost collaboration, innovation, and worker productivity, improve employee and customer experiences, and protect critical agency data and assets.

ECS Jobs


Clearance Level
Public Trust
Employer
ECS