À propos de ce poste OT Cybersecurity Engineer chez Vulcan Elements
Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence and Integrity.
As an OT Cybersecurity Engineer, you will secure the industrial control systems and manufacturing floor devices that keep Vulcan Elements running, including PLCs, historians, and MES across Rockwell/Allen-Bradley, Siemens, and other platforms as our environment grows. You will design and enforce IT/OT network segmentation, protect OT assets, and lead the OT side of our NIST SP 800-53 (Low-Impact Baseline) assessment and Plan of Action and Milestones (POA&M). This role works closely with our Automation and Engineering teams and requires a strong safety-first mindset alongside deep security expertise.
Responsibilities
- Work with the OT Automation group to align on a segmented, defense-in-depth architecture for the OT environment, including PLCs, HMIs, historians, MES, engineering workstations, and virtualized systems.
- Secure Rockwell/Allen-Bradley and Siemens control systems, and support additional ICS/SCADA platforms as the manufacturing environment expands.
- Ensure sufficient IT/OT boundary controls and zone/conduit segmentation, and manage firewall and ACL policy aligned with NIST guidance and industry frameworks such as ISA/IEC 62443.
- Develop, own, align, and enforce internal security standards to be used by manufacturing equipment/OT vendors as the expected contractual handover requirements for anything in the internal OT environment.
- Monitor OT network asset list and industrial protocols (Modbus, EtherNet/IP, PROFINET, and others as adopted) for anomalous activity, staying vendor- and protocol-agnostic as new platforms are added.
- Lead the assessment of OT-relevant controls against the NIST SP 800-53 Low-Impact Baseline, contribute to the System Security Plan (SSP), and help build and close out the Plan of Action and Milestones (POA&M).
- Partner with our external CMMC compliance partner and IT security team to keep OT controls consistent with our NIST SP 800-171/CMMC Level 2 program.
- Own the specification and implementation of native OT monitoring systems and the development of Incident Response Plans.
- Partner with Automation, Engineering, and IT teams to build security into new production lines and control system upgrades from the start.
Responsibilities and tasks outlined are not exhaustive and may change as determined by the needs of the business.
Qualifications
- 3+ years of experience in OT/ICS security, controls engineering, or industrial networking, ideally in manufacturing, defense, or critical infrastructure.
- Hands-on experience with Rockwell/Allen-Bradley (ControlLogix, FactoryTalk) and/or Siemens (S7, TIA Portal, WinCC) required; comfort working across other ICS/SCADA platforms and industrial protocols and the associated industrial switch technology (Modbus, EtherNet/IP, PROFINET) as the environment grows.
- Working knowledge of ISA/IEC 62443, NIST SP 800-82, and NIST SP 800-53; experience contributing to an SSP or POA&M for OT systems is a strong plus.
Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.
Preferred Qualifications
- Experience being the point of contact with integrators/OEMs for cybersecurity as contracts are executed and commissioning/implementation is happening
- Worked with advanced monitoring software and hardware products made for OT environments such as Claroty, Dragos, Nozomi
- Experience or knowledge of MQTT, Sparkplug, Kafka, OPCUA
- Prior experience supporting DoD programs, federal contractors, or CUI/export-controlled (ITAR/EAR) environments.
- Ability to work on the manufacturing floor, including around industrial equipment, and to lift up to 50 lbs as needed.
- CMMC Registered Practitioner (RP), CMMC Certified Professional (CCP), GICSP, CCNA, an ISA/IEC 62443 certificate, or CompTIA Security+.