- Location
- Houston, Texas, United States
- Department
- Information Technology
- Seniority
- Senior
- Education
- Master
- Source
- Greenhouse
Description
ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software, ON.energy develops projects worldwide that set new benchmarks for resilience.
Role Summary
We're hiring a Senior OT/SCADA Cybersecurity Engineer to secure the industrial control systems behind our grid-connected energy portfolio — the SCADA, site controllers, PLCs, power conversion systems, and battery management systems that have to run safely and stay dispatchable around the clock.
This is a hands-on role, built around the security stack rather than the control system. You'll own and operate our OT security tooling, and you'll set the standards and verification gates that the EMS, controls, and commissioning teams implement in the field.
Key Responsibilities
- You own and operate: OT network monitoring and industrial IDS, centralized logging and detection content, the OT asset inventory, PKI, and the remote/vendor access platform.
- You define and verify; others implement: hardening baselines, controller and gateway requirements, site network designs, backup and recovery standards, and the security requirements in procurement specs and site acceptance — with your sign-off on the evidence before a site is accepted.
Architecture & Segmentation
- Design IEC 62443-aligned zone and conduit architectures (Purdue Model) across site control, plant SCADA, and enterprise boundaries.
- Specify and validate default-deny rulesets on industrial firewalls, DMZs, and unidirectional gateways between OT, DMZ, and business networks.
- Work with our OT network architect on the reference site network design, and drive it into EPC and integrator scopes of work.
- Define the security of SCADA links to utility control centers, ISOs, and third-party dispatch platforms.
- Provide application security recommendations.
Monitoring, Detection & Response
- Own the passive monitoring and industrial IDS platform: design, configuration, and detection tuning for control-system behavior rather than generic IT signatures.
- Own the OT asset inventory and centralized log collection from SCADA hosts, HMIs, controllers, and industrial network gear.
- Analyze Modbus TCP, IEC 61850, and OPC UA traffic to baseline normal behavior and catch unauthorized commands, scanning, or malformed traffic.
- Write and exercise OT incident response playbooks: loss of view, loss of control, ransomware in the DMZ, compromised vendor access. You direct response remotely; field teams execute recovery.
Standards & Assurance
- Author hardening baselines for SCADA servers, HMIs, engineering workstations, and historians, coordinated with Sr. RHEL Systems Engineers, validated with the EMS team not to disturb real-time performance.
- Define controller and gateway security requirements: run-mode discipline, access control, firmware integrity, logic change detection, to include verifying compliance from monitoring data and evidence.
- Specify OPC UA security modes, and TLS where equipment supports it, with compensating controls where it doesn't.
- Set backup and recovery standards for PLC programs, HMI projects, SCADA databases, and network configs, and require the owning teams to demonstrate restores on a set cadence.
- Run risk-based vulnerability management against ICS advisories (CISA ICS-CERT, OEM bulletins), and own the patch and firmware strategy that O&M executes in outage windows.
- Own the cybersecurity requirements in procurement specs, FAT/SAT plans, and site acceptance, holding OEMs, integrators, and EPC partners to them.
Identity & Access
- Own PKI and certificate lifecycle for site controllers, gateways, and OT-to-cloud telemetry, including provisioning at commissioning and replacement during service events.
- Own the remote access platform: brokered, time-bound, MFA-protected access with session recording for internal engineers and OEM vendors, with no direct inbound paths to field equipment.
- Define how SCADA, HMI, and engineering workstation authentication integrates with centralized identity (Entra ID, federated to AD/LDAPS for OT systems that require it), mandating local break-glass accounts so operators keep control when the directory or WAN link is down.
- Eliminate default and shared control-system credentials; operate privileged access management and enforce least privilege for service and machine-to-machine accounts.
Compliance
- Map controls to IEC 62443 and NIST SP 800-82r3, support NERC CIP where our assets are in scope, and answer utility, offtaker, insurer, and lender security reviews with evidence that holds up.
Key Requirements
- 5–8 years in technical cybersecurity or control systems engineering, most of it in OT/ICS environments.
- Proven experience securing SCADA and ICS in energy, utility, or heavy industrial settings with regards to live plants, not just labs. This role is centralized, but you need that field background for your requirements to survive contact with a real site.
- A track record of getting security implemented through other teams, on technical credibility rather than direct control of the equipment.
- Working knowledge of IEC 62443, the Purdue Model, and NIST SP 800-82r3, and the judgment to say what a control will cost in operational risk and propose the alternative.
- Industrial networking: you can read a plant network drawing, reason about segmentation, and trace a dropped packet between an HMI and a PLC from a capture.
- Centralized identity and directory services (Entra ID, AD/LDAPS, SSO), with the judgment to apply them in OT without creating an availability dependency on the corporate network.
- Practical Linux and Windows administration, plus enough scripting to manage the security stack at fleet scale rather than site by site.
- OT security platforms: Hands-on with a passive monitoring and asset discovery platform (Nozomi, Claroty, Dragos, Tenable OT, Forescout, Cisco Cyber Vision) or open-source equivalents (Zeek, Suricata, Wireshark, Wazuh), plus SIEM/log aggregation, PKI/CA tooling, and a remote access or PAM platform.
- Control systems: Working understanding of at least one SCADA/HMI platform — Ignition, AVEVA, Siemens WinCC, Rockwell FactoryTalk — including its user model, historian, and remote client architecture, enough to write requirements and read its logs; familiarity with PLCs and RTUs (Siemens, Rockwell, Schneider, Beckhoff, SEL) and with PCS, BMS, meters, and protection relays.
- Protocols & networking: Modbus TCP/RTU, IEC 61850, OPC UA, with awareness of IEEE 2030.5 and SunSpec for DER; managed industrial switches and firewalls (Cisco, Fortinet, Palo Alto, Moxa, Tofino), VPN architectures, and data-diode gateways.
- Also useful: identity provider and single sign-on (SSO) platform, such as Authentik, Zabbix or equivalent for OT infrastructure health, and a preference for tailoring open-source tooling over "black box" commercial platforms.
Preferred Experience
- Battery energy storage, solar, wind, or DER. Especially site controller, EMS, and PCS/BMS integration.
- NERC CIP program experience, or preparing OT evidence for utility and regulatory audits.
- MITRE ATT&CK for ICS, and familiarity with known ICS threat activity (Industroyer, TRITON, PIPEDREAM, FrostyGoop).
- Writing cybersecurity requirements into EPC, OEM, or integrator contracts and auditing delivery against them.
- Certifications: GICSP, GRID, GCIP, ISA/IEC 62443 Cybersecurity Fundamentals Specialist or higher, SANS ICS410/ICS515, CISSP.
#LI-AD1
For US-based roles - What you’ll get:
- Competitive salary + annual performance-based bonus eligibility
- Medical, dental, and vision insurance
- 401(k) with company match
- Paid time off and company holidays
For Mexico-based roles - What you’ll get:
- Competitive salary + annual performance bonus eligibility
- Christmas Bonus (Aguinaldo): 30 days
- Major medical expenses and life insurance
- Paid time off and holidays (per local policy)
For all roles:
- Professional development and growth opportunities
- Opportunity to grow with a mission-driven team shaping the future of clean energy
- Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
- Accommodations: If you need an accommodation during the application process, email [email protected]
- Benefits vary by role and location and are subject to change.
Agency Notice: ON.energy does not accept unsolicited resumes from staffing agencies, search firms, or third-party recruiters. Resumes submitted without a fully executed Master Services Agreement (MSA) and a written request from an authorized member of our Talent Acquisition team will be considered the property of ON.energy. No placement fees or compensation will be paid for unsolicited candidate submissions.