OT Security Engineer, Cyber Risk
Department:
Job Summary
Kroll is seeking an OT Security Engineer to support the delivery of Operational Technology Security engagements from India. The role requires a strong foundation in enterprise and industrial networking combined with hands-on experience deploying and supporting OT asset visibility and threat monitoring platforms such as Nozomi Networks Claroty or Armis.
The role will support the design and implementation of secure OT architectures including segmentation industrial DMZs firewall policy design secure remote access implementation of OT IDS and controlled IT/OT connectivity. The engineer will work closely with Kroll teams across EMEA and North America as well as client engineering teams and technology vendors to deliver practical and resilient solutions that account for operational availability safety and business requirements.
Day-to-Day Responsibilities:
- Design review and document OT architectures including Purdue-model zones and conduits industrial DMZs secure remote access and IT/OT interconnections.
- Support OT network segmentation projects from discovery and current-state assessment through target-state design firewall rule definition implementation planning testing and validation.
- Deploy configure tune upgrade and troubleshoot OT asset visibility and security monitoring platforms such as Nozomi Networks Claroty or Armis.
- Plan sensor and collector placement configure SPAN/TAP connectivity validate packet visibility and integrate monitoring platforms with SIEM SOC MDR ticketing and identity systems.
- Perform network discovery and traffic analysis to identify assets protocols communication paths dependencies and segmentation requirements across industrial environments.
- Configure and troubleshoot network technologies including switching routing VLANs VRFs ACLs firewalls VPNs NAT redundancy and high-availability designs in enterprise and OT environments.
- Develop network diagrams low-level designs firewall rule matrices implementation runbooks test plans rollback plans and as-built documentation.
- Support client workshops technical discussions Proofs of Concept solution demonstrations and coordination with network controls engineering SOC and vendor teams.
- Contribute to OT Zero Trust and micro-segmentation initiatives; experience with solutions such as Zscaler or ColorTokens is an advantage.
Essential Traits:
- Strong hands-on networking mindset with a structured approach to troubleshooting and root-cause analysis.
- Ability to translate discovered OT traffic flows and operational dependencies into practical segmentation designs and implementation plans.
- Delivery-focused approach that balances cybersecurity objectives with safety availability and production requirements.
- Confidence working with client network engineering controls security operations and technology vendor teams.
- Clear communication style and the ability to explain network and security issues to both technical and non-technical stakeholders.
- Strong ownership attention to detail and disciplined creation of diagrams runbooks rule matrices and as-built documentation.
Prerequisites:
- Bachelors degree in Cybersecurity Information Technology Computer Science Electronics Engineering or a related field.
- Approximately 5-8 years of relevant experience in network engineering network security or OT/ICS security with meaningful hands-on delivery experience.
- Strong networking fundamentals including TCP/IP subnetting switching routing VLANs STP HSRP/VRRP OSPF/BGP DNS DHCP NAT VPNs and packet analysis.
- Hands-on experience with enterprise firewalls switches routers and network management or troubleshooting tools; experience with major vendors such as Cisco Palo Alto Networks Fortinet or Check Point is preferred.
- Hands-on deployment or operational support experience with at least one OT monitoring or asset visibility platform: Nozomi Networks Claroty or Armis.
- Experience supporting network segmentation or firewall migration projects including traffic-flow analysis rule-base development implementation coordination and post-change validation.
- Working knowledge of industrial protocols such as Modbus TCP DNP3 OPC/OPC UA EtherNet/IP PROFINET BACnet and IEC.
- Understanding of OT security standards and guidance such as ISA/IEC 62443 and NIST SP 800-82.
- Experience with OT Zero Trust software-defined segmentation or micro-segmentation solutions such as Zscaler or ColorTokens is preferred.
- Experience integrating OT monitoring solutions with SIEM SOC MDR identity vulnerability management or ticketing platforms.
- Relevant certifications such as CCNA/CCNP PCNSE NSE/FCP GICSP GRID or ISA/IEC 62443 are advantageous.
Strong analytical troubleshooting documentation and client communication skills with the ability to work independently and collaboratively across time zones.
#LI-Hybrid
#LI-SP1
Required Experience:
IC
About Company
Kroll’s Restructuring Administration practice, formerly Prime Clerk, offers end-to-end restructuring administration services with unrivaled experts and technology. Read more.