City Of London, England
Job Summary
We are recruiting an OT Security Engineer to lead the physical deployment, commissioning and onboarding of OT/ICS network monitoring (intrusion detection) sensors across multiple operational sites. These passive sensors provide asset discovery, network visualisation, vulnerability assessment and threat/anomaly detection, feeding their data to a central management platform (on-premises and/or cloud-hosted). The role is hands-on and field-based: racking and cabling physical sensor appliances, configuring monitoring sources (SPAN/TAP/mirror), establishing and validating the connection from each sensor to the central/cloud management platform, provisioning licences, and confirming that assets, alerts and data ingestion are healthy at each site. You will work closely with site engineering, network and OT operations teams, and follow strict OT change-control and safety practices throughout. This role suits an engineer who combines OT/ICS networking knowledge with practical experience of an OT monitoring/IDS platform and enjoys structured, multi-site rollout delivery in a critical-infrastructure environment.
Key Responsibilities
1. Implement And Enhance Operational Systems Using Aws Security Practices And Cisco Asa Configurations To Improve Management Reporting And Streamline Information Flow In Support Operations.
2. Analyze And Interpret Client Requirements, Ensuring The Support Team Effectively Meets Client Expectations Through Proactive Engagement And Feedback Mechanisms.
3. Lead And Mentor The Project Team By Providing Guidance On Aws Security And Cisco Asa Best Practices, Ensuring Transparent Communication Of Project Goals And Objectives.
4. Drive Process Innovation By Introducing New Ideas And Methodologies In Aws Security And Network Security Protocols, Contributing To Overall Organizational Progress.
5. Deliver Tailored Solutions That Align With Customer Needs, Utilizing Aws Security Features And Cisco Asa Capabilities To Achieve Desired Business Outcomes.
Skill Requirements
OT monitoring / IDS platform — hands-on experience deploying and administering at least one OT/ICS network monitoring or intrusion-detection platform (physical sensor appliances plus central/cloud management), and onboarding, licensing and validating sensors. • OT/ICS networking — solid understanding of the Purdue model, network segmentation/zoning, VLANs, switching, and passive monitoring via SPAN/TAP/mirror ports. • Networking fundamentals — TCP/IP, DNS, NTP, routing, and firewall rule design; ability to specify and verify the connectivity a sensor needs to reach its management platform. • Linux / appliance CLI — comfortable operating on a Linux-based sensor OS for configuration, diagnostics and troubleshooting. • Industrial protocols — working familiarity with common OT protocols (e.g. Modbus, DNP3, IEC 60870-5-104, IEC 61850, EtherNet/IP, PROFINET, S7, OPC/OPC-UA) and the devices that use them (PLCs, RTUs, DCS, HMIs). • Physical hardware — appliance racking, cabling, power, and fibre/copper/SFP handling in data-centre and industrial site environments. • Documentation — clear as-builts, runbooks and change records suitable for audit and BAU handover.
Other Requirements
Plan and execute the physical installation of OT monitoring/IDS sensor appliances at multiple sites: racking, power, structured cabling, copper/fibre and SFP selection. • Conduct or review site surveys to confirm rack space, power, monitoring source (SPAN/TAP/mirror-port) availability and network paths before deployment. • Configure sensor monitoring interfaces and validate that the correct traffic is being captured from the target OT network segments. • Establish and validate the connection from each sensor to the central/cloud management platform (management URL/endpoint, enrolment token/credentials), and confirm successful synchronisation. • Provision and validate licensing/entitlement for each sensor (including confirming assets fall within the licensed tier) and resolve licensing/entitlement issues with the platform team/vendor. • Coordinate network and firewall changes (e.g. required outbound connectivity, DNS, NTP, certificate trust) so each site\'s sensor can reach its management platform. • Validate post-deployment health: asset discovery/inventory, alert generation and routing, integration data flow (e.g. SIEM/log pipeline), data ingestion and overall sensor health. • Support sensor migration, replacement and refresh activities, including repointing sensors to a new platform/tenant, physical swap of appliances where remote access is unavailable, and re-enrolment/rotation of units. • Troubleshoot connectivity, licensing, data-visibility and performance issues, escalating to the vendor with appropriate diagnostic detail when required. • Produce and maintain deployment documentation: site as-builts, runbooks, checklists, change records and handover packs to operations. • Work within OT change management, safety and permit-to-work processes; minimise operational risk and downtime during site work. • Provide knowledge transfer and handover to BAU/operations teams at project close.
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-