Hiring.Camp

Operational Technology (OT) Penetration Tester

Imri

·

Yesterday

Salary
$75 – $90/hr
Location
New York
Workplace
Hybrid, Onsite
Type
Full-time
Department
IT
Education
Bachelor
Source
AcquireTM

Description

COMPANY OVERVIEW

Join our award-winning team at Information Management Resources, Inc. (IMRI), a small business leader in the technology industry known for our commitment to innovation, excellence, and authenticity. Founded in 1992, IMRI has been at the forefront of delivering advanced cybersecurity and IT solutions, safeguarding organizations against evolving threats. We have built a reputation for our expertise in Cybersecurity, Digital Transformation, Strategic Business Consulting, and Staff Augmentation. Guided by our core values of innovation, excellence, and a solution-driven mindset, we have served a diverse portfolio of customers that includes federal agencies, state and local governments, and Fortune 1000 companies.

At IMRI, we recognize the integral part our employees play in our ongoing success. To support this, we offer a comprehensive benefits package, tailored to meet the individual needs of our employees. We are committed to promoting their overall well-being and equipping them with the necessary tools to flourish in their careers. We welcome you to be a part of our ongoing mission as we continue to navigate the digital landscape, committed to empowering organizations with our innovative solutions.

POSITION: Operational Technology (OT) Penetration Tester

SUMMARY: IMRI is seeking an Operational Technology (OT) Penetration Tester to support cybersecurity assessment and penetration testing activities for government client environments that may include operational technology, industrial control systems, SCADA-connected systems, specialized public-safety technologies, segmented infrastructure, isolated networks, air-gapped environments, and other mission-critical operational assets. This role provides technical expertise to safely assess OT and OT-adjacent environments, identify exploitable weaknesses, validate attack paths, and deliver practical remediation guidance while maintaining operational continuity and safety.

LOCATION/SCHEDULE: Hybrid or onsite as required supporting Nassau County, NY. Majority of work will be performed during standard business hours Monday-Friday, 8:00 AM-5:00 PM EST, with occasional nights, weekends, or approved maintenance-window support during OT/ICS discovery, rules-of-engagement coordination, testing execution, validation, reporting, and stakeholder briefings. (Anticipated 400 hours per contract year.) 

KEY RESPONSIBILITIES:

  • Plan and execute OT/ICS, SCADA, and operational-environment assessment activities in accordance with approved rules of engagement, safety constraints, maintenance windows, and stakeholder coordination requirements.
  • Perform passive and active discovery, architecture review, segmentation analysis, firewall and access-control review, vulnerability validation, and controlled exploit testing where explicitly authorized.
  • Assess OT-adjacent systems such as radio communications, CAD-related infrastructure, evidence management systems, building or facilities systems, public-safety support networks, isolated enclaves, and other specialized operational technologies.
  • Evaluate network segmentation, trust relationships, remote access paths, authentication mechanisms, jump hosts, management interfaces, insecure services, default credentials, unsupported systems, and operational exposure risks.
  • Coordinate closely with government client IT, legal or investigative stakeholders, public-safety representatives, authorized liaisons, system owners, and operational stakeholders to minimize disruption and protect mission-critical operations.
  • Use OT-safe testing methods that emphasize passive validation, configuration review, protocol-aware assessment, and controlled testing rather than disruptive scanning or exploitation.
  • Analyze findings using risk-based methods aligned to NIST CSF, NIST SP 800-53, NIST SP 800-82, NIST SP 800-115, CIS Controls, CVE/CVSS, and applicable CJIS considerations.
  • Develop detailed technical findings, evidence, attack-path narratives, operational impact analysis, prioritized remediation recommendations, and executive-ready summaries.
  • Support annual penetration testing, operational security validation, wireless assessment, firewall review, infrastructure hardening review, and modernization roadmap activities involving OT or OT-adjacent environments.
  • Participate in client briefings, remediation planning, retesting, lessons learned, and knowledge transfer activities to support long-term operational resilience.

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, Industrial Control Systems, or related field, or equivalent professional experience.
  • 5+ years of cybersecurity assessment, penetration testing, vulnerability assessment, network security, security engineering, or operational technology security experience.
  • Hands-on experience assessing OT/ICS, SCADA, industrial networks, critical infrastructure, public-safety systems, segmented environments, or mission-critical operational networks.
  • Strong understanding of OT network architecture, industrial protocols, segmentation models, engineering workstations, HMIs, PLCs, RTUs, historian systems, remote access controls, and operational safety considerations.
  • Experience with penetration testing methodologies, vulnerability validation, attack-path analysis, firewall and network-device review, wireless assessment, and secure reporting practices.
  • Ability to conduct testing in production or sensitive environments using disciplined coordination, change control, safety planning, and non-disruptive assessment techniques.
  • Strong written communication, technical reporting, stakeholder coordination, and executive briefing skills.

PREFERRED QUALIFICATIONS:

  • Experience supporting cybersecurity assessments for utilities, transportation agencies, defense organizations, law enforcement, emergency services, municipal environments, or other critical infrastructure operators.
  • Familiarity with NIST SP 800-82, NERC CIP concepts, CJIS security requirements, IEC 62443 principles, MITRE ATT&CK for ICS, OWASP, PTES, and OSSTMM-aligned testing practices.
  • Experience with tools such as Tenable/Nessus, Nmap, Wireshark, Burp Suite, Metasploit, Kali Linux, OT protocol analyzers, firewall review tools, and safe discovery or configuration-review utilities.
  • Relevant certifications such as GICSP, GRID, GCIP, GPEN, CISSP, CISM, CRISC, CEH, PenTest+, Security+, Network+, CCNA, or equivalent OT/cybersecurity credentials.
  • Experience preparing executive and technical reports that include operational impacts, compensating controls, remediation sequencing, and retesting criteria.

 

IMRI offers top-tier benefits that include: medical coverage through nationally recognized carriers, ancillary coverages, paid vacation and sick leave in compliance with all state and local laws, 401(k) with company match, company paid life insurance and LTD, and several additional voluntary coverages.

 

Pay will be commensurate with the experience, skills, and qualifications that the candidate brings to the position.

 

Equal Employment Opportunity Statement

IMRI is an Equal Employment Opportunity employer. IMRI prohibits unlawful discrimination and harassment and provides equal employment opportunity to all applicants and employees consistent with applicable federal, state, and local laws. Employment decisions are based on qualifications, merit, business needs, and other lawful job-related factors without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by law. As a federal contractor, IMRI complies with Section 503 of the Rehabilitation Act and VEVRAA and takes affirmative action with respect to qualified individuals with disabilities and protected veterans as required by law.

Skills

LinuxCybersecurityPenetration TestingSCADAComplianceCISSPCCNA

Similar Jobs

21

Operational Technology (OT) Engineers

ALTEN · Dungeness, England, United Kingdom

2 days ago

Senior Operational Technology (OT) Analyst

Boeing · USA - Seattle, WA, United States of America +4 · Hybrid

3 days ago

Operational Technology (OT) Project Manager

Chattanooga · Chattanooga, TN, United States, US

1 week ago

Operational Technology (OT) Senior Security Engineer

AbbVie · Dublin, County Dublin, Ireland · Hybrid

2 weeks ago

Cyber Defense & Engineering - Operational Technology (OT) Consulting Manager

Pwc · Seattle - 1420 Fifth Avenue, United States of America +19

2 weeks ago

Operational Technology (OT) Network Security Analyst

Northmark · Spartanburg, SC, United States of America · Hybrid

3 weeks ago

Director, Operational Technology (OT) Engineering

Northmark · Spartanburg, SC, United States of America +1 · Remote, Hybrid

3 weeks ago

Operational Technology (OT) Network Administrator

C3El · Guam

3 weeks ago

Senior Cybersecurity Architect – Cyber & Operational Technology (OT) Systems

ShorePoint · Albuquerque, New Mexico

3 weeks ago

Senior Operational Technology (OT) Analyst

Crescentenergyco · Houston, TX, United States of America

1 month ago

Operational Technology (OT) Cybersecurity & Infrastructure Specialist

Pwc · Argentina AC Olivos

1 month ago

Senior Information Security Engineer - OT/IoT & Operational Technology (OT) Security

Qtsdatacenters · US GA Atlanta Suwanee 1 DC1, United States of America

2 months ago

Program/Project Management Lead (Operational Technology (OT))

Accenture · Midrand, J'burg Waterfall - 3, South Africa · Onsite

2 months ago

Operational Technology (OT) Engineers

ALTEN · Hartlepool, England, United Kingdom

2 months ago

Operational Technology (OT) & Cybersecurity Manager (APAC)

SGS · Shah Alam, Selangor, Malaysia

2 months ago

Process Development Engineer III, Operational Technology (OT) Data

Regeneron · TARRYTOWN, United States of America

2 months ago

Senior Operational Technology (OT) Security Consultant

Pae · GBR-Manchester-Deansgate (103GB), United Kingdom +2 · Hybrid

3 months ago

Operational Technology (OT) Cybersecurity & Infrastructure Specialist

Pwc · Argentina AC Olivos

4 months ago

Operational Technology (OT) Cybersecurity Engineer

WSP · New York, NY, United States, US

4 months ago

OT-Security Consultant (Operational Technology) (m/w/d)

Pco Online

4 months ago

Systems Integration Specialist | IT & Operational Technology (OT) Integration [PCBOCC0032031]

ProSidian Consulting · New Port Richey, FL, United States

1+ year ago