Jobs Companies ON.energy Senior Cybersecurity Engineer - OT/SCADA

About this Senior Cybersecurity Engineer - OT/SCADA role at ON.energy

ON.energy · Onsite · Houston, Texas, United States

ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software, ON.energy develops projects worldwide that set new benchmarks for resilience.

Role Summary

We're hiring a Senior OT/SCADA Cybersecurity Engineer to secure the industrial control systems behind our grid-connected energy portfolio — the SCADA, site controllers, PLCs, power conversion systems, and battery management systems that have to run safely and stay dispatchable around the clock.
This is a hands-on role, built around the security stack rather than the control system. You'll own and operate our OT security tooling, and you'll set the standards and verification gates that the EMS, controls, and commissioning teams implement in the field.


Key Responsibilities

  • You own and operate: OT network monitoring and industrial IDS, centralized logging and detection content, the OT asset inventory, PKI, and the remote/vendor access platform.
  • You define and verify; others implement: hardening baselines, controller and gateway requirements, site network designs, backup and recovery standards, and the security requirements in procurement specs and site acceptance — with your sign-off on the evidence before a site is accepted.

Architecture & Segmentation

  • Design IEC 62443-aligned zone and conduit architectures (Purdue Model) across site control, plant SCADA, and enterprise boundaries.
  • Specify and validate default-deny rulesets on industrial firewalls, DMZs, and unidirectional gateways between OT, DMZ, and business networks.
  • Work with our OT network architect on the reference site network design, and drive it into EPC and integrator scopes of work.
  • Define the security of SCADA links to utility control centers, ISOs, and third-party dispatch platforms.
  • Provide application security recommendations.

Monitoring, Detection & Response

  • Own the passive monitoring and industrial IDS platform: design, configuration, and detection tuning for control-system behavior rather than generic IT signatures.
  • Own the OT asset inventory and centralized log collection from SCADA hosts, HMIs, controllers, and industrial network gear.
  • Analyze Modbus TCP, IEC 61850, and OPC UA traffic to baseline normal behavior and catch unauthorized commands, scanning, or malformed traffic.
  • Write and exercise OT incident response playbooks: loss of view, loss of control, ransomware in the DMZ, compromised vendor access. You direct response remotely; field teams execute recovery.

Standards & Assurance

  • Author hardening baselines for SCADA servers, HMIs, engineering workstations, and historians, coordinated with Sr. RHEL Systems Engineers, validated with the EMS team not to disturb real-time performance.
  • Define controller and gateway security requirements: run-mode discipline, access control, firmware integrity, logic change detection, to include verifying compliance from monitoring data and evidence.
  • Specify OPC UA security modes, and TLS where equipment supports it, with compensating controls where it doesn't.
  • Set backup and recovery standards for PLC programs, HMI projects, SCADA databases, and network configs, and require the owning teams to demonstrate restores on a set cadence.
  • Run risk-based vulnerability management against ICS advisories (CISA ICS-CERT, OEM bulletins), and own the patch and firmware strategy that O&M executes in outage windows.
  • Own the cybersecurity requirements in procurement specs, FAT/SAT plans, and site acceptance, holding OEMs, integrators, and EPC partners to them.

Identity & Access

  • Own PKI and certificate lifecycle for site controllers, gateways, and OT-to-cloud telemetry, including provisioning at commissioning and replacement during service events.
  • Own the remote access platform: brokered, time-bound, MFA-protected access with session recording for internal engineers and OEM vendors, with no direct inbound paths to field equipment.
  • Define how SCADA, HMI, and engineering workstation authentication integrates with centralized identity (Entra ID, federated to AD/LDAPS for OT systems that require it), mandating local break-glass accounts so operators keep control when the directory or WAN link is down.
  • Eliminate default and shared control-system credentials; operate privileged access management and enforce least privilege for service and machine-to-machine accounts.

Compliance

  • Map controls to IEC 62443 and NIST SP 800-82r3, support NERC CIP where our assets are in scope, and answer utility, offtaker, insurer, and lender security reviews with evidence that holds up.

 

Key Requirements

  • 5–8 years in technical cybersecurity or control systems engineering, most of it in OT/ICS environments.
  • Proven experience securing SCADA and ICS in energy, utility, or heavy industrial settings with regards to live plants, not just labs. This role is centralized, but you need that field background for your requirements to survive contact with a real site.
  • A track record of getting security implemented through other teams, on technical credibility rather than direct control of the equipment.
  • Working knowledge of IEC 62443, the Purdue Model, and NIST SP 800-82r3, and the judgment to say what a control will cost in operational risk and propose the alternative.
  • Industrial networking: you can read a plant network drawing, reason about segmentation, and trace a dropped packet between an HMI and a PLC from a capture.
  • Centralized identity and directory services (Entra ID, AD/LDAPS, SSO), with the judgment to apply them in OT without creating an availability dependency on the corporate network.
  • Practical Linux and Windows administration, plus enough scripting to manage the security stack at fleet scale rather than site by site.
  • OT security platforms: Hands-on with a passive monitoring and asset discovery platform (Nozomi, Claroty, Dragos, Tenable OT, Forescout, Cisco Cyber Vision) or open-source equivalents (Zeek, Suricata, Wireshark, Wazuh), plus SIEM/log aggregation, PKI/CA tooling, and a remote access or PAM platform.
  • Control systems: Working understanding of at least one SCADA/HMI platform — Ignition, AVEVA, Siemens WinCC, Rockwell FactoryTalk — including its user model, historian, and remote client architecture, enough to write requirements and read its logs; familiarity with PLCs and RTUs (Siemens, Rockwell, Schneider, Beckhoff, SEL) and with PCS, BMS, meters, and protection relays.
  • Protocols & networking: Modbus TCP/RTU, IEC 61850, OPC UA, with awareness of IEEE 2030.5 and SunSpec for DER; managed industrial switches and firewalls (Cisco, Fortinet, Palo Alto, Moxa, Tofino), VPN architectures, and data-diode gateways.
  • Also useful: identity provider and single sign-on (SSO) platform, such as Authentik, Zabbix or equivalent for OT infrastructure health, and a preference for tailoring open-source tooling over "black box" commercial platforms.

Preferred Experience

  • Battery energy storage, solar, wind, or DER.  Especially site controller, EMS, and PCS/BMS integration.
  • NERC CIP program experience, or preparing OT evidence for utility and regulatory audits.
  • MITRE ATT&CK for ICS, and familiarity with known ICS threat activity (Industroyer, TRITON, PIPEDREAM, FrostyGoop).
  • Writing cybersecurity requirements into EPC, OEM, or integrator contracts and auditing delivery against them.
  • Certifications: GICSP, GRID, GCIP, ISA/IEC 62443 Cybersecurity Fundamentals Specialist or higher, SANS ICS410/ICS515, CISSP.

#LI-AD1


For US-based roles - What you’ll get:

  • Competitive salary + annual performance-based bonus eligibility
  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and company holidays 

For Mexico-based roles - What you’ll get:

  • Competitive salary + annual performance bonus eligibility
  • Christmas Bonus (Aguinaldo): 30 days
  • Major medical expenses and life insurance
  • Paid time off and holidays (per local policy)

For all roles:

  • Professional development and growth opportunities
  • Opportunity to grow with a mission-driven team shaping the future of clean energy
  • Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
  • Accommodations: If you need an accommodation during the application process, email [email protected]
  • Benefits vary by role and location and are subject to change.

Agency Notice: ON.energy does not accept unsolicited resumes from staffing agencies, search firms, or third-party recruiters. Resumes submitted without a fully executed Master Services Agreement (MSA) and a written request from an authorized member of our Talent Acquisition team will be considered the property of ON.energy. No placement fees or compensation will be paid for unsolicited candidate submissions.

Ready to apply to ON.energy?
Apply to ON.energy

About ON.energy

 

Take your next step with ON.energy

 

At ON.energy, we are proud to be an equal opportunity employer, offering a wide range of career opportunities for individuals passionate about driving the energy transition forward. Our culture is dynamic, innovative, and far from the traditional corporate mold. We are built on a foundation of customer satisfaction, teamwork, trust, and an unwavering commitment to excellence.

 

Joining ON.energy means advancing your career in the energy sector with exciting opportunities across many departments and skill-sets. We embrace diverse perspectives and are dedicated to equipping our team with the tools, resources, and support they need to thrive.

 

Be a part of a company that values your ideas, fuels your growth, and empowers you to make a meaningful impact in shaping the future of energy.

 

 


 

Open Positions:

 

See all jobs at ON.energy →

Similar jobs

WaveStrong, Inc.
Security / Soc Analyst III
WaveStrong, Inc.
⚡ Apply early Houston, Texas, United States Onsite ⚠ 6mo+ old
● New 👁 Seen ✓ Applied 8mos ago
Umpisa Inc.
Information Security Analyst Subject Matter Expert (SME) - Project-based
Umpisa Inc.
⚡ Apply early Makati City, Metro Manila, Phi... Onsite
● New 👁 Seen ✓ Applied 7m ago
Zimperium
Technical Product Support Engineer - Endpoint/MTD (Device) & Cybersecurity
Zimperium
⚡ Apply early India (Remote) · location restricted
● New 👁 Seen ✓ Applied 43m ago
Sphere Entertainment Group, LLC
Senior Analyst Security Intelligence
Sphere Entertainment Group, LLC
⚡ Apply early Las Vegas, NV Onsite $83,000–$100,000
● New 👁 Seen ✓ Applied 3h ago
Assurity Trusted Solutions
Cybersecurity Engineer (Incident Response)
Assurity Trusted Solutions
⚡ Apply early Singapore, Singapore, Singapor... Onsite
● New 👁 Seen ✓ Applied 4h ago
Kalles Group
Cybersecurity Engineer -Applications
Kalles Group
⚡ Apply early Seattle, WA Onsite $110,000–$140,000
● New 👁 Seen ✓ Applied 4h ago
Referral Board
Senior Information Security Analyst - Compliance - InfoSec
Referral Board
⚡ Apply early United States Onsite $133,100–$210,600
● New 👁 Seen ✓ Applied 6h ago
Arkose Labs
Security Analyst (Weekend Shift)
Arkose Labs
⚡ Apply early Brisbane, Australia Onsite
● New 👁 Seen ✓ Applied 6h ago
Roblox
Senior Security GRC Analyst
Roblox
⚡ Apply early San Mateo, CA, United States Onsite $209,250–$271,710
● New 👁 Seen ✓ Applied 9h ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at ON.energy

See all jobs at ON.energy →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free