OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
Manufacturing · 51-200 employees
About the role
You will design and secure the operational technology backbone for a large-scale manufacturing facility expansion. This includes authoring IEC 62443 zone-and-conduit architectures and managing network security requirements for all equipment and vendors.
What they look for
Requirements
Candidates must possess 7+ years of experience in industrial networking and OT security with a relevant degree. The role requires the ability to manage network design through construction and maintain compliance with U.S. government standards.
Full description
Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence, and Transparency.
As the OT Network & Security Engineer you will design and secure the operational technology backbone for a massive 1 million square foot manufacturing facility expansion. You will produce the OT network design basis for the new facility, author the IEC 62443 zone-and-conduit architecture and write security requirements into every OEM equipment contract or develop them in parallel. This is a high-impact, high-ownership role requiring genuine depth in both industrial networking and OT security.
Responsibilities
- Produce the OT network architecture for a large-format industrial facility: MDF/IDF distribution, fiber backbone topology, switching and routing design, IP schema, and resilience strategy.
- Freeze IDF locations, pathways, and enclosure requirements into construction drawings on the construction schedule’s
- Author and maintain the IEC 62443 zone-and-conduit register, the living document that is the firewall policy. Set security-level targets per zone.
- Write network and security requirements into all equipment packages ahead of Factory Acceptance Tests, and verify them at acceptance alongside Controls Engineers.
- Design and operate the remote access architecture for internal OT network access and OEM support connectivity, with per-vendor approval and session control.
- Coordinate the enterprise boundary with IT: DMZ services, WAN demarcation, identity architecture, and CMMC/CUI compliance evidence for the U.S. government partnership.
- Select and onboard the managed OT detection-and-response provider ahead of first energization; scope the independent IEC 62443 risk assessment and penetration test; own patch-versus-compensating-control decisions with the area controls engineers.
Deliverables You Will Develop, Review, or Support
- OT network design basis, MDF/IDF standards, IP schema, and fiber/cabling specifications with acceptance criteria.
- Zone-and-conduit register, security-level targets, firewall policy set, and the secure remote access design.
- OEM network/security requirement specifications, FAT verification records, CMMC/CUI evidence packages, and the OT incident-response plan.
- Switch and firewall configuration standards under change control, asset inventory, and the managed detection and service integration.
Responsibilities and tasks outlined are not exhaustive and may change as determined by the needs of the business.
Qualifications
- Bachelor’s or Master’s degree in Engineering, Computer Science, or a related field with 7+ years spanning industrial networking and OT security, or equivalent demonstrated depth in both — genuine capability on each side, not one with awareness of the other.
- Ability to design and defend segmentation, switching, routing, and firewall policy for industrial Ethernet environments, and to reason about control-traffic behavior (EtherNet/IP or comparable) when making design trade-offs.
- Ability to apply zone/conduit thinking and risk-based security levels to a real plant - asset inventory, monitoring, secure remote access, and patch/compensating-control judgment under production constraints.
- Ability to take a network design through construction: fiber topologies, IDF and enclosure planning, and working productively with construction and cabling contractors.
- Ability to write requirements vendors can build to and auditors can verify, and to defend security decisions to both operations and compliance audiences.
Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.
Preferred Skills
- Formal IEC 62443 project experience (zone/conduit registers, security-level assessments) or NERC CIP program work that translates directly to it.
- Greenfield or major-expansion industrial network design, including construction-phase coordination.
- Field or professional-services background with an OT security platform or consultancy (Claroty, Dragos, Nozomi class, or an OT security practice).
- Defense industrial base, government-partnered, or otherwise compliance-driven manufacturing environments (CMMC, NIST 800-171/82).
- Experience selecting or managing a managed OT detection-and-response service.
- GICSP, ISA/IEC 62443 certificates, CISSP, CCNP, or equivalent credentials.
- Industrial wireless design and site RF survey experience.
- Familiarity with Rockwell/EtherNet/IP-centric plant architectures and industrial DMZ patterns.
- Experience in regulated industries such as Defense, Aerospace, or Automotive.
Physical and Environmental Requirements
The position requires regular presence on the production floor and the ability to navigate all areas of the facility. Candidates must be able to climb stairs, stand and walk for extended periods, and work in environments that may be hot, humid, or noisy. The role also requires the use of personal protective equipment, including respirators, and adherence to all applicable safety policies, procedures, and regulatory requirements. Employees must be able to complete required fit testing, wear appropriate PPE for the duration of assigned tasks, and respond safely to changing conditions within the production environment.
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom
-
Security Engineer
NCV HOLDCO LLC United States · $71K–$119K/yr