OT Security Penetration Tester
Job Description
Packetlabs is seeking an OT Security Consultant to evaluate risk in sensitive Operational Technology environments, including ICS, SCADA, and field devices. The work emphasizes offensive-security judgment with operational restraint, focused on architecture review, actionable risk assessment, and client-facing improvements.
Security Architecture Reviews
- Lead security architecture reviews with an operationally grounded approach.
- Conduct holistic tabletop reviews that consider both technical and non-technical risk across OT environments.
- Avoid engaging in high-risk manual or automated activity during reviews.
- Analyze sensitive, legacy networks to identify areas of negative impact, high risk, and single points of failure (SPOF).
- Use structured judgment to determine where risk concentrates and where controls are missing.
- Adjust review depth and methods based on the operational realities of each client environment.
OT Risk Identification & Assessment
- Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices.
- Assess legacy and sensitive networks where conventional testing methods present unacceptable operational risk.
- Differentiate between theoretical and operationally relevant risk so findings remain actionable.
- Prove impact when appropriate, while exercising restraint when the environment requires it.
Client Advisory & Program Improvement
- Support OT clients with security program improvements by clarifying which critical controls are needed.
- Refine testing scope in collaboration with clients as engagements progress and the environment becomes clearer.
- Translate technical findings into guidance that can be implemented by both technical teams and leadership audiences.
- Build client confidence through credibility, clear communication, and operational awareness.
Methodology & Continuous Improvement
- Contribute to the maturity of Packetlabs’ OT testing methodology and day-to-day practice.
- Stay current on OT threats, attack techniques, and defensive controls.
- Share knowledge with the broader team to reduce blind spots and strengthen collective capability.
- Help raise the standard of OT security work across the firm.
Key Requirements
- Graduate of an Information Security or Computer Science degree program.
- Professional qualifications preferred (one or more): GICSP, GRID, GCIP, CSSA, CACE, CISSP, OSCP.
- 3+ years of experience assessing or operating within OT, ICS, or SCADA environments.
- Strong understanding of the operational constraints that differentiate OT testing from IT testing.
- Excellent communication skills, including the ability to communicate risk clearly to both technical and non-technical audiences.
- Demonstrated commitment to continuous learning in a rapidly evolving field.
- Strong analytical and problem-solving skills, with the ability to work independently in unfamiliar or highly specialized environments.
- Must be located in Texas or Florida.
Location and Work Setup
- Location: Florida (remote).
- Fully remote within Texas or Florida.
Benefits
- Immediate and ongoing offensive security training, mentorship, and professional development.
- Competitive compensation and growth opportunity.
- GRRSP with corporate matching in Canada.
- Participation in corporate benefit plans within Canada.
- Flexible work environment designed to enable employees to do their best work.
What Success Looks Like
- Clients receive a clear, accurate understanding of OT risk without operational disruption.
- Findings are credible, impactful, and directly actionable for both technical and leadership audiences.
- Engagements are delivered to a consistently high standard with strong client confidence.
- Scope is managed effectively as engagements evolve, with risk surfaced early and clearly.
- Packetlabs’ OT methodology and practice continue to mature through ongoing contributions.
- Clients trust Packetlabs as a testing partner that understands the stakes of working in sensitive environments.
Role Context: Offensive Judgment With Operational Restraint
The position requires disciplined decision-making in sensitive OT settings, balancing risk clarity and impact with the understanding that high-risk activity is not appropriate for all environments.