Senior Cybersecurity Engineer - OT/SCADA
at On.Energy · 101-250 employees
- Seniority
- Senior
- Location
- Houston, Texas, United States
- Posted
- 5d ago
at On.Energy · 101-250 employees
On.Energy is a Miami-headquartered independent power producer that develops, integrates and operates AI-driven battery energy storage systems across the Americas.
<div class="content-intro"><p>ON.energy<span class="Apple-converted-space"> </span>is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software,<span class="Apple-converted-space"> </span>ON.energy<span class="Apple-converted-space"> </span>develops projects worldwide that set new benchmarks for resilience.</p></div><h3>Role Summary</h3> <p>We're hiring a Senior OT/SCADA Cybersecurity Engineer to secure the industrial control systems behind our grid-connected energy portfolio — the SCADA, site controllers, PLCs, power conversion systems, and battery management systems that have to run safely and stay dispatchable around the clock.<br>This is a hands-on role, built around the security stack rather than the control system. You'll own and operate our OT security tooling, and you'll set the standards and verification gates that the EMS, controls, and commissioning teams implement in the field.</p> <h3><br>Key Responsibilities</h3> <ul> <li>You own and operate: OT network monitoring and industrial IDS, centralized logging and detection content, the OT asset inventory, PKI, and the remote/vendor access platform.</li> <li>You define and verify; others implement: hardening baselines, controller and gateway requirements, site network designs, backup and recovery standards, and the security requirements in procurement specs and site acceptance — with your sign-off on the evidence before a site is accepted.</li> </ul> <p>Architecture & Segmentation</p> <ul> <li>Design IEC 62443-aligned zone and conduit architectures (Purdue Model) across site control, plant SCADA, and enterprise boundaries.</li> <li>Specify and validate default-deny rulesets on industrial firewalls, DMZs, and unidirectional gateways between OT, DMZ, and business networks.</li> <li>Work with our OT network architect on the reference site network design, and drive it into EPC and integrator scopes of work.</li> <li>Define the security of SCADA links to utility control centers, ISOs, and third-party dispatch platforms.</li> <li>Provide application security recommendations.</li> </ul> <p>Monitoring, Detection & Response</p> <ul> <li>Own the passive monitoring and industrial IDS platform: design, configuration, and detection tuning for control-system behavior rather than generic IT signatures.</li> <li>Own the OT asset inventory and centralized log collection from SCADA hosts, HMIs, controllers, and industrial network gear.</li> <li>Analyze Modbus TCP, IEC 61850, and OPC UA traffic to baseline normal behavior and catch unauthorized commands, scanning, or malformed traffic.</li> <li>Write and exercise OT incident response playbooks: loss of view, loss of control, ransomware in the DMZ, compromised vendor access. You direct response remotely; field teams execute recovery.</li> </ul> <p>Standards & Assurance</p> <ul> <li>Author hardening baselines for SCADA servers, HMIs, engineering workstations, and historians, coordinated with Sr. RHEL Systems Engineers, validated with the EMS team not to disturb real-time performance.</li> <li>Define controller and gateway security requirements: run-mode discipline, access control, firmware integrity, logic change detection, to include verifying compliance from monitoring data and evidence.</li> <li>Specify OPC UA security modes, and TLS where equipment supports it, with compensating controls where it doesn't.</li> <li>Set backup and recovery standards for PLC programs, HMI projects, SCADA databases, and network configs, and require the owning teams to demonstrate restores on a set cadence.</li> <li>Run risk-based vulnerability management against ICS advisories (CISA ICS-CERT, OEM bulletins), and own the patch and firmware strategy that O&M executes in outage windows.</li> <li>Own the cybersecurity requirements in procurement specs, FAT/SAT plans, and site acceptance, holding OEMs, integrators, and EPC partners to them.</li> </ul> <p>Identity & Access</p> <ul> <li>Own PKI and certificate lifecycle for site controllers, gateways, and OT-to-cloud telemetry, including provisioning at commissioning and replacement during service events.</li> <li>Own the remote access platform: brokered, time-bound, MFA-protected access with session recording for internal engineers and OEM vendors, with no direct inbound paths to field equipment.</li> <li>Define how SCADA, HMI, and engineering workstation authentication integrates with centralized identity (Entra ID, federated to AD/LDAPS for OT systems that require it), mandating local break-glass accounts so operators keep control when the directory or WAN link is down.</li> <li>Eliminate default and shared control-system credentials; operate privileged access management and enforce least privilege for service and machine-to-machine accounts.</li> </ul> <p>Compliance</p> <ul> <li>Map controls to IEC 62443 and NIST SP 800-82r3, support NERC CIP where our assets are in scope, and answer utility, offtaker, insurer, and lender security reviews with evidence that holds up.</li> </ul> <p> </p> <h3>Key Requirements</h3> <ul> <li>5–8 years in technical cybersecurity or control systems engineering, most of it in OT/ICS environments.</li> <li>Proven experience securing SCADA and ICS in energy, utility, or heavy industrial settings with regards to live plants, not just labs. This role is centralized, but you need that field background for your requirements to survive contact with a real site.</li> <li>A track record of getting security implemented through other teams, on technical credibility rathe