Brown and Caldwell
Cybersecurity, OT-IT Security Consultant
Share this job
Job Description
As a Cybersecurity Engineer at Brown and Caldwell, you will play a pivotal role in securing the operational technology (OT) and information technology (IT) environments that keep water and environmental infrastructure running safely and reliably. We are using modern technology to transform the way that water is managed across the country. Your work will directly impact our clients' ability to protect critical infrastructure, maintain regulatory compliance, and build resilient digital solutions that ensure a future of clean water, thriving communities, and environmental protection.
Responsibilities
- Lead strategic cyber engineering consultation projects.
- Make critical business development recommendations to balance risk and opportunity related to security solutions in accordance with the company's strategy and operations.
- Perform contract reviews.
- Perform complex security assessments for engineering designs and client systems to identify areas of risk and compliance gaps.
- Compare engineering designs with security frameworks, such as AWWA and NIST CSF, to identify potential gaps.
- Lead the delivery of the security-related service offerings for our clients.
- Validate security solution architecture, design, and implementation.
- Support business development from a cybersecurity standpoint.
- Ensure compliance with company policies and external regulations related to digital security.
- Flexibility to adapt and execute various additional assignments based on evolving needs.
Preferred Requirements
- Collaborate with interdisciplinary teams of environmental engineers, SCADA/controls engineers, data engineers, and software developers to assess, design, and implement cybersecurity solutions for client OT and IT environments.
- Lead cybersecurity risk and vulnerability assessments of industrial control systems (ICS), SCADA networks, and enterprise IT environments for water, wastewater, and environmental clients, aligned to NIST SP 800-82, NIST CSF, and IEC 62443.
- Design secure network architectures for converged IT/OT environments, including network segmentation, zone and conduit models, secure remote access, OT aware security gateways, and SOC integration strategies.
- Support clients in meeting regulatory and compliance requirements, including America's Water Infrastructure Act (AWIA) risk and resilience assessments, EPA cybersecurity guidance, and state level critical infrastructure requirements.
- Develop cybersecurity governance deliverables, including policies, incident response plans, system security plans, and roadmaps that balance operational reliability with security posture improvement.
- Evaluate and specify security technologies for OT environments (asset discovery and monitoring platforms, intrusion detection, firewalls, unidirectional gateways) with an understanding of the availability and safety constraints unique to industrial systems.
- Advise on secure design and deployment of emerging digital solutions — including cloud connected SCADA, IoT/edge sensing, digital twins, and AI/agentic systems — addressing risks such as API credential handling, data flow security, and prompt injection exposure.
- Support business development through proposal contributions, scopes of work, client presentations, and thought leadership on OT/IT convergence and critical infrastructure security.
- Stay up to date with emerging threats, technologies, and best practices in ICS/OT security, cloud security, and AI system security to drive continuous improvement.
Mentorship
* Provide mentorship, guidance, support, and knowledge-sharing to help less experienced team members develop their skills and grow within their roles.
Skills and Competencies
- Advanced understanding of cyber security risks and mitigation solutions.
- Demonstrated competency in security solution architecture, design, and implementation.
- Advanced knowledge in contract review and security reviews.
- Proven ability to conduct complex and insightful security assessments.
- Strong knowledge in network infrastructure security (physical and virtual) solutions and tactics.
- Strong Informational Technology (IT), Operational Technology (OT), and Industrial Control Systems (ICS) knowledge.
- Highly adept in policy adherence and compliance in the context of cyber security.
- Excellent skills in business development support and strategic decision-making.
Experience
- Typically, a minimum of 8 years of relevant cyber security consultant experience is required.
- Relevant cyber security certifications (Security+, CISSP, GICSP, etc).
- Experience with on-premise and cloud-based system architecture is required.
- Previous experience in NIST or related security frameworks is required.
Preferred Experience
Technical Proficiency
- OT/ICS Security: Deep working knowledge of SCADA, PLC/RTU, HMI, and historian architectures; familiarity with industrial protocols (Modbus, DNP3, OPC UA, EtherNet/IP) and their security limitations.
- Frameworks & Standards: Demonstrated experience applying NIST SP 800-82, NIST CSF, IEC 62443, and CIS Controls; familiarity with NIST AI RMF is a plus.
- Network Security: Strong understanding of network architecture and segmentation (Purdue Model), firewalls, VPNs, secure remote access, and OT network monitoring platforms (e.g., Claroty, Dragos, Nozomi).
- IT Security: Solid grounding in enterprise security domains, including identity and access management, endpoint protection, vulnerability management, and security operations/SIEM.
Cloud & Platform Experience
- Experience securing Azure environments, including Azure security services (Defender, Sentinel, Key Vault, Entra ID), DevSecOps practices, and secure CI/CD pipelines.
- Understanding of cloud-to-OT connectivity patterns and the security implications of hybrid architectures, edge compute, and IoT data pipelines.
- Domain Specifics:
- Water Sector: Experience with water/wastewater utility environments, AWIA compliance, and EPA/WaterISAC guidance is a strong plus.
- Assessments & Advisory: Experience delivering client facing cybersecurity assessments, gap analyses, and roadmaps in a consulting or professional services context.
Soft Skills
- Strong problem solving skills and the ability to work in a collaborative, cross functional environment spanning engineering, operations, and IT stakeholders.
- Excellent communication skills to interact with technical and non-technical audiences, with the ability to translate cyber risk into terms that resonate with utility leadership and operations staff.
- A passion for staying updated with the latest trends, threats, and technologies in OT/IT security and critical infrastructure protection.
Education
* A relevant degree or equivalent experience is required.
Preferred Education
- Bachelor's or Master's degree in Cybersecurity, Computer Science, Computer/Electrical Engineering, Information Systems, or a related field.
- 8+ years of experience in cybersecurity, with at least 3 years focused on OT/ICS environments or critical infrastructure sectors (water/wastewater, energy, manufacturing, or similar).
- Relevant certifications strongly preferred: GICSP, ISA/IEC 62443 Cybersecurity Expert, CISSP, GRID, or equivalent.
Learn more about our work
Climate Change and Resilience - Brown and Caldwell (https://brownandcaldwell.com/services/climate-change/)
Data Center Water - Brown and Caldwell (https://brownandcaldwell.com/services/data-center-water/)
Emerging Contaminants and PFAS - Brown and Caldwell (https://brownandcaldwell.com/services/emerging-contaminants-and-pfas/)
Digital Solutions - Brown and Caldwell (https://brownandcaldwell.com/services/smart-utility/)
News - Brown and Caldwell (https://brownandcaldwell.com/news/)
Projects - Brown and Caldwell (https://brownandcaldwell.com/projects/)
Industrial Water - Brown and Caldwell (https://brownandcaldwell.com/services/industrial-water/)
Salary Range
The anticipated starting pay range for this position is based on the employee’s primary work location and may be more or less depending upon skills, experience, and education. These ranges may be modified in the future.
Location A: $129,000 - $177,000
Location B: $142,000 - $194,000
Location C: $155,000 - $212,000
You can view which BC location applies to you here. (http://bit.ly/3uQe7gi) If you have any questions, please speak with your Recruiter.
Benefits and Other Compensation: We provide a comprehensive benefits package that promotes employee health, performance, and success which includes medical, dental, vision, short and long-term disability, life insurance, an employee assistance program, paid time off and parental leave, paid holidays, 401(k) retirement savings plan with employer match, performance-based bonus eligibility, employee referral bonuses, tuition reimbursement, pet insurance and long-term care insurance. Click here (https://brownandcaldwell.com/careers/benefits/) to see our full list of benefits.
About Brown and Caldwell
Headquartered in Walnut Creek, California, Brown and Caldwell is a full-service environmental engineering and construction services firm with 50 offices and over 2,100 professionals across North America and the Pacific. For more than 75 years, we have created leading-edge environmental solutions for municipalities, private industry, and government agencies. We strive to be the company of choice—to our clients, who benefit from our passion for delivering exceptional quality, and to our employees, present and future, who share our commitment to client service, collaboration, and innovation. Join us, and you will find a home where you can do your best work, reach new levels of expertise, and enjoy exceptional development opportunities. For more information, visit www.brownandcaldwell.com (http://www.brownandcaldwell.com)
This position is subject to a pre-employment background check and a pre-employment drug test.
Notice to Third Party Agencies: Brown and Caldwell does not accept unsolicited resumes from recruiters or employment agencies. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement and approved engagement request with Brown and Caldwell, Brown and Caldwell reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency.
Brown and Caldwell is proud to be an EEO/AAP Employer. Brown and Caldwell encourages protected veterans, individuals with disabilities, and applicants from all backgrounds to apply. Brown and Caldwell ensures nondiscrimination in all programs and activities in accordance with Title VI of the Civil Rights Act.
#LI-Remote
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.
Keep looking
Similar Remote Jobs That Pay Well
University of Phoenix
Info Security Engineer- Identity Governance and Access Management
University of Phoenix
Info Security Engineer- Vulnerability and Exposure Management
Trail of Bits