OT Network Security Engineer positions focus on delivering results in their domain. This page aggregates open OT Network Security Engineer roles and what employers typically expect.
Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence, and Transparency. As the OT Network & Security Engineer you will design and secure the operational technology backbone for a massive 1 million square foot manufacturing facility expansion. You will produce the OT network design basis for the new facility, author the IEC 62443 zone-and-conduit architecture and write security requirements into every OEM equipment contract or develop them in parallel. This is a high-impact, high-ownership role requiring genuine depth in both industrial networking and OT security. Responsibilities Produce the OT network architecture for a large-format industrial facility: MDF/IDF distribution, fiber backbone topology, switching and routing design, IP schema, and resilience strategy. Freeze IDF locations, pathways, and enclosure requirements into construction drawings on the construction schedule’s Author and maintain the IEC 62443 zone-and-conduit register, the living document that is the firewall policy. Set security-level targets per zone. Write network and security requirements into all equipment packages ahead of Factory Acceptance Tests, and verify them at acceptance alongside Controls Engineers. Design and operate the remote access architecture for internal OT network access and OEM support connectivity, with per-vendor approval and session control. Coordinate the enterprise boundary with IT: DMZ services, WAN demarcation, identity architecture, and CMMC/CUI compliance evidence for the U.S. government partnership. Select and onboard the managed OT detection-and-response provider ahead of first energization; scope the independent IEC 62443 risk assessment and penetration test; own patch-versus-compensating-control decisions with the area controls engineers. Deliverables You Will Develop, Review, or Support OT network design basis, MDF/IDF standards, IP schema, and fiber/cabling specifications with acceptance criteria. Zone-and-conduit register, security-level targets, firewall policy set, and the secure remote access design. OEM network/security requirement specifications, FAT verification records, CMMC/CUI evidence packages, and the OT incident-response plan. Switch and firewall configuration standards under change control, asset inventory, and the managed detection and service integration. Responsibilities and tasks outlined are not exhaustive and may change as determined by the needs of the business. Qualifications Bachelor’s or Master’s degree in Engineering, Computer Science, or a related field with 7+ years spanning industrial networking and OT security, or equivalent demonstrated depth in both — genuine capability on each side, not one with awareness of the other. Ability to design and defend segmentation, switching, routing, and firewall policy for industrial Ethernet environments, and to reason about control-traffic behavior (EtherNet/IP or comparable) when making design trade-offs. Ability to apply zone/conduit thinking and risk-based security levels to a real plant - asset inventory, monitoring, secure remote access, and patch/compensating-control judgment under production constraints. Ability to take a network design through construction: fiber topologies, IDF and enclosure planning, and working productively with construction and cabling contractors. Ability to write requirements vendors can build to and auditors can verify, and to defend security decisions to both operations and compliance audiences. Must be a U.S. Person due to required access to U.S. export-controlled information or facilities. Preferred Skills Formal IEC 62443 project experience (zone/conduit registers, security-level assessments) or N…