Back to Jobs

Senior/Staff/Principal SWE – OT Security Engineering

Remote, USA Full-time Posted 2026-06-16

Job Description:

Secure Remote Access Platform:

Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments.

Protocol-Aware Policy Authoring:

A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model.

Evidence and Audit Baseline:

Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements.

Session Governance:

Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments.

Asset Context Ingestion (Phase 2+):

API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path.

Design and implement

backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns.

Build and maintain

REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations.

Apply Zero Trust principles

to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments.

Integrate

with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP.

Own features end-to-end,

from architecture through production deployment in real customer environments.

(Staff / Principal)

Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales. Requirements:

Experience:

Hands-on background building or operating secure remote access systems — VPN, ZTNA, jump servers, privileged access, session brokers, or equivalent.

OT Domain Knowledge:

Direct experience in or with OT / ICS environments — manufacturing, energy, utilities, oil and gas, water, transportation, or defense.

Technical Fundamentals:

• Strong systems programming in Go, Rust, or a comparable language

  • Solid networking (TCP/IP, TLS, firewalls) and identity (SAML, OIDC, PKI) fundamentals
  • Familiarity with the Purdue Model and IT/OT DMZ design patterns
  • Working knowledge of OT protocols: Modbus, DNP3, OPC-UA, EtherNet/IP

Mindset:

High ownership, end-to-end accountability, comfortable in a small team where you solve problems before they become fires. Benefits: Apply tot his job Apply To this Job

Similar Jobs

Experienced Product Security Engineer (Virtual)

Remote, USA Full-time

Staff Cyber Security Engineer (AI)

Remote, USA Full-time

Traveling Security Field Engineer - Electronic / Integrated Security

Remote, USA Full-time

Senior Data Security Engineer, Big ID Deployment Lead

Remote, USA Full-time

Endpoint Security Analyst - Hybrid - NYC

Remote, USA Full-time

IAM Governance & Controls Security Analyst

Remote, USA Full-time

IT Security Specialist - Penetration Tester

Remote, USA Full-time

Identity & Access Mgmt Analyst - IT Security - Full Time (Remote)

Remote, USA Full-time

Penetration Tester II

Remote, USA Full-time

(Contractor) Senior Penetration Tester – QA Automation & Security

Remote, USA Full-time

Experienced Data Entry Clerk – Full Remote Opportunity with arenaflex

Remote, USA Full-time

Endoscopy Clinical Specialist - Chicago

Remote, USA Full-time

Experienced Remote Customer Support Representative – Deliver Exceptional Travel Experiences with arenaflex

Remote, USA Full-time

Experienced Entry-Level Chat Operator – Work from Home, No Calls, No Experience Required at arenaflex

Remote, USA Full-time

Data Engineer

Remote, USA Full-time

Senior Software Engineer, Windows/Desktop Applications - São Paulo, Brazil

Remote, USA Full-time

Full‑Time Remote Data Entry Specialist – Precision Data Management & Reporting Role at arenaflex

Remote, USA Full-time

Training Specialist, Property & Casualty Training and Development

Remote, USA Full-time

Experienced Customer Service Guide (Human Services Specialist 1) – Supporting Oregonians in Need

Remote, USA Full-time

Mathematics AI Training Expert - PhD - (Portugal)

Remote, USA Full-time