Principal Consultant, ICS/ OT Security (Unit 42)
Palo Alto NetworksAbout the role
Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
FLEXWORK is an employee-centric reimagining of how we work. We built FLEXWORK based on employee feedback – it is about flexibility, trust, and choice whenever possible. It’s been a journey of disruption that has yielded the best of our values. We offer as much flexibility as possible, and choices that enable you to be most productive, including benefits that meet your needs and learning opportunities that you feel passionate about.
Job Description
Your Career
As Principal ICS/OT Consultant is responsible for ICS / OT focused assessments and remediation activities along with providing recommendations across a broad range of security domains. You must be proficient with industrial networking and be able to support ICS vulnerability assessments and remediation efforts. In addition, you will be able to drive large scale OT transformation consulting projects with the goal of improving the client’s overall ICS/OT security posture. The Senior Consultant will be the client’s advocate for ICS/OT risk management and will provide strong recommendations in this domain.
We expect office-based employees to be in the office four days per week, with one day working from where they choose. We believe being together facilitates casual conversations and those magic moments where we can work on issues and ideas informally. These moments build capability and deepen trusted relationships and allow our people to feel safe in taking risks and being disruptive. Like so many companies, we are working through the details and things could change …. but in general if a role is deemed office-based we want our teams to be together four days per week.
Your Impact
- Performing analysis of the architecture and infrastructure of Industrial Control Systems and/or Operational Technology (ICS/OT) in terms of cybersecurity posture
- Designing and implementing cybersecurity solutions for Industrial Control Systems
- Supporting ICS security projects within a Security Transformation program
- Developing ICS Control Frameworks, based on industry best practices as well as international and applicable national standards
- Implementing or improving ICS security management processes at the clients’ organization
- Monitor progress, track budget, manage risk and ensure key stakeholders are kept informed about progress and expected outcomes while defining potential impacts and creating an effective mitigation strategy for multiple projects at a given time
- Skilled at proactively identifying security risks and vulnerabilities while eliminating cybersecurity threats via stakeholder interviews, documentation review, and deep-dive testing and ICS/OT control validation
- Ensure client controls meet legal, regulatory, privacy, policy, standards and security requirements
- Effectively write and communicate audit, assessment, or compliance results, findings, and recommendations to stakeholders
- Effectively and efficiently communicate to external stakeholders in a professional manner
- Ability to scope new opportunities with prospective clients, including drafting statements of work and proposals
- Ability to perform travel requirements as needed to meet business demands (on average ~30%)
Qualifications
Your Experience
- 6+ years of experience control systems security background with relevant previous experience in a technical or consulting environments
- Experience with OT/ICS systems and OT/ICS security industry practices along with exposure to IIoT technologies
- Working knowledge of one or more of the following industry frameworks - IEC 62443/ISA 99, ISO 27001, NIST SP 800-82, CPNI
- Former professional services and consulting experience preferred
- Experience with security assessments/audits, drafting findings and recommendations, and prioritizing recommendations via quantitative risk scoring
- Demonstrate a track record in strengthening existing and developing new client relationships
- Knowledge of computer forensic tools, technologies and methods
- Identified ability to grow into a valuable contributor to the practice and, specifically
- have an external presence via public speaking, conferences, and/or publications
- have credibility, executive presence, and gravitas
- be able to have a meaningful and rapi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s