Coalfire logo
Coalfire
Posted 30 days agoVerified live 1d ago

Operational Technology Security Consultant

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
10 H-1B approvalsDept. of Labor
3 green cardsCertified filings
Operational Technology SecurityOT Risk AssessmentIndustrial Control Systems (ICS)Supervisory Control and Data Acquisition (SCADA)Industrial Automation ArchitecturesOT NetworkingIEC 62443NIST SP 800-82NERC CIPNIST Cybersecurity Framework (CSF)OT Security Maturity AssessmentsOral and Written Communication

About the company

Coalfire is the premier Cybersecurity and Compliance Services leader for the tech, healthcare, and finance industries.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
10H-1B approved
100%approval rate
3new H-1B hires
3PERM certified
$129,791median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20232
20244
20254
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
20251
20261
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20241
20252
Top sponsored roles
ConsultantInformation Security AnalystPrincipal Consultant, Application Security
Sponsored employees from
India

Job description

Summary

Coalfire is a cybersecurity company that helps clients address complex cybersecurity challenges across evolving technology environments. The Operational Technology Security Consultant assesses OT security posture and maturity, conducts stakeholder interviews and framework-based evaluations, develops remediation roadmaps and reports, and presents findings and guidance to clients.

Responsibilities

  • Maintain current knowledge of OT security standards, regulatory developments, and industry trends through ongoing professional development and relevant certifications
  • Support and guide OT risk and security discussions with technical teams, operations staff, and executive stakeholders
  • Conduct stakeholder interviews and review OT-related policies, procedures, architecture documentation, and compliance records to understand organizational OT environments and priorities
  • Assess client environments against OT security practices and compliance posture against IEC 62443, NIST SP 800-82, NIST CSF, NERC CIP, NIS2 Directive, EU Cyber Resilience Act, C2M2, and other relevant OT standards and frameworks
  • Develop maturity assessment and benchmarking reports identifying OT security gaps, current state findings, and prioritized remediation recommendations
  • Develop sequenced remediation roadmaps with prioritized activities, timelines, and implementation guidance to address identified OT security gaps
  • Advise clients on OT security program structure, governance frameworks, organizational roles and responsibilities, and recommended policies and procedures
  • Present assessment findings, risk analysis, and strategic recommendations to clients and their leadership through executive briefings and detailed reports
  • Support other Cyber Risk Advisory consulting engagements when necessary to maintain team capacity

Skills

  • - At least 4 years of working experience in operational technology security, OT risk assessment, or related infrastructure security roles
  • - Bachelor's degree in Engineering, Computer Science, Information Systems, or related field, or equivalent combination of education and experience demonstrating OT security expertise
  • - Direct experience in OT environments such as manufacturing, energy, utilities, or other critical infrastructure sectors
  • - Hands-on experience with Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems
  • - Knowledge of control system technologies, industrial automation architectures, and OT-specific networking environments
  • - Expertise in OT security assessment frameworks including IEC 62443, NIST SP 800-82, and industry-specific requirements such as NERC CIP
  • - Understanding of emerging OT regulatory requirements including NIS2 Directive, EU Cyber Resilience Act, and other sector-specific directives
  • - Strong analytical and critical thinking abilities
  • - Strong oral and written communication skills when presenting technical findings to both technical and non-technical audiences
  • - GICSP (Global Industrial Cyber Security Professional) certification
  • - CISM certification
  • - CISSP certification
  • - GRID (GIAC Response and Industrial Defense) certification
  • - GCIH (GIAC Certified Incident Handler) certification
  • - C2M2 (Cybersecurity Capability Maturity Model) assessment experience
  • - NIST Cybersecurity Framework (CSF) assessment and implementation experience
  • - Incident response experience in OT or critical infrastructure environments
  • - Business continuity or disaster recovery experience in OT environments
  • - Experience with safety-critical systems and understanding of functional safety standards (IEC 61508, ISO 10218)
  • - Technical writing experience for policy and procedure development
  • - Cloud platform experience relevant to OT environments or industrial IoT implementations

Qualifications

Must Haves

  • - At least 4 years of working experience in operational technology security, OT risk assessment, or related infrastructure security roles
  • - Bachelor's degree in Engineering, Computer Science, Information Systems, or related field, or equivalent combination of education and experience demonstrating OT security expertise
  • - Direct experience in OT environments such as manufacturing, energy, utilities, or other critical infrastructure sectors
  • - Hands-on experience with Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems
  • - Knowledge of control system technologies, industrial automation architectures, and OT-specific networking environments
  • - Expertise in OT security assessment frameworks including IEC 62443, NIST SP 800-82, and industry-specific requirements such as NERC CIP
  • - Understanding of emerging OT regulatory requirements including NIS2 Directive, EU Cyber Resilience Act, and other sector-specific directives
  • - Strong analytical and critical thinking abilities
  • - Strong oral and written communication skills when presenting technical findings to both technical and non-technical audiences

Nice to Haves

  • - GICSP (Global Industrial Cyber Security Professional) certification
  • - CISM certification
  • - CISSP certification
  • - GRID (GIAC Response and Industrial Defense) certification
  • - GCIH (GIAC Certified Incident Handler) certification
  • - C2M2 (Cybersecurity Capability Maturity Model) assessment experience
  • - NIST Cybersecurity Framework (CSF) assessment and implementation experience
  • - Incident response experience in OT or critical infrastructure environments
  • - Business continuity or disaster recovery experience in OT environments
  • - Experience with safety-critical systems and understanding of functional safety standards (IEC 61508, ISO 10218)
  • - Technical writing experience for policy and procedure development
  • - Cloud platform experience relevant to OT environments or industrial IoT implementations

Benefits

  • Flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
  • Opportunities to join employee resource groups
  • Participation in in-person and virtual events
  • Paid parental leave
  • Flexible time off
  • Certification and training reimbursement
  • Digital mental health and wellbeing support membership
  • Comprehensive insurance options

More jobs like this