POSITION: Operational Technology (OT) Penetration Tester
SUMMARY: IMRI is seeking an Operational Technology (OT) Penetration Tester to support cybersecurity assessment and penetration testing activities for government client environments that may include operational technology, industrial control systems, SCADA-connected systems, specialized public-safety technologies, segmented infrastructure, isolated networks, air-gapped environments, and other mission-critical operational assets. This role provides technical expertise to safely assess OT and OT-adjacent environments, identify exploitable weaknesses, validate attack paths, and deliver practical remediation guidance while maintaining operational continuity and safety.
LOCATION/SCHEDULE: Hybrid or onsite as required supporting Nassau County, NY. Majority of work will be performed during standard business hours Monday-Friday, 8:00 AM-5:00 PM EST, with occasional nights, weekends, or approved maintenance-window support during OT/ICS discovery, rules-of-engagement coordination, testing execution, validation, reporting, and stakeholder briefings. (Anticipated 400 hours per contract year.)
KEY RESPONSIBILITIES:
- Plan and execute OT/ICS, SCADA, and operational-environment assessment activities in accordance with approved rules of engagement, safety constraints, maintenance windows, and stakeholder coordination requirements.
- Perform passive and active discovery, architecture review, segmentation analysis, firewall and access-control review, vulnerability validation, and controlled exploit testing where explicitly authorized.
- Assess OT-adjacent systems such as radio communications, CAD-related infrastructure, evidence management systems, building or facilities systems, public-safety support networks, isolated enclaves, and other specialized operational technologies.
- Evaluate network segmentation, trust relationships, remote access paths, authentication mechanisms, jump hosts, management interfaces, insecure services, default credentials, unsupported systems, and operational exposure risks.
- Coordinate closely with government client IT, legal or investigative stakeholders, public-safety representatives, authorized liaisons, system owners, and operational stakeholders to minimize disruption and protect mission-critical operations.
- Use OT-safe testing methods that emphasize passive validation, configuration review, protocol-aware assessment, and controlled testing rather than disruptive scanning or exploitation.
- Analyze findings using risk-based methods aligned to NIST CSF, NIST SP 800-53, NIST SP 800-82, NIST SP 800-115, CIS Controls, CVE/CVSS, and applicable CJIS considerations.
- Develop detailed technical findings, evidence, attack-path narratives, operational impact analysis, prioritized remediation recommendations, and executive-ready summaries.
- Support annual penetration testing, operational security validation, wireless assessment, firewall review, infrastructure hardening review, and modernization roadmap activities involving OT or OT-adjacent environments.
- Participate in client briefings, remediation planning, retesting, lessons learned, and knowledge transfer activities to support long-term operational resilience.
REQUIRED QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, Industrial Control Systems, or related field, or equivalent professional experience.
- 5+ years of cybersecurity assessment, penetration testing, vulnerability assessment, network security, security engineering, or operational technology security experience.
- Hands-on experience assessing OT/ICS, SCADA, industrial networks, critical infrastructure, public-safety systems, segmented environments, or mission-critical operational networks.
- Strong understanding of OT network architecture, industrial protocols, segmentation models, engineering workstations, HMIs, PLCs, RTUs, historian systems, remote access controls, and operational safety considerations.
- Experience with penetration testing methodologies, vulnerability validation, attack-path analysis, firewall and network-device review, wireless assessment, and secure reporting practices.
- Ability to conduct testing in production or sensitive environments using disciplined coordination, change control, safety planning, and non-disruptive assessment techniques.
- Strong written communication, technical reporting, stakeholder coordination, and executive briefing skills.
PREFERRED QUALIFICATIONS:
- Experience supporting cybersecurity assessments for utilities, transportation agencies, defense organizations, law enforcement, emergency services, municipal environments, or other critical infrastructure operators.
- Familiarity with NIST SP 800-82, NERC CIP concepts, CJIS security requirements, IEC 62443 principles, MITRE ATT&CK for ICS, OWASP, PTES, and OSSTMM-aligned testing practices.
- Experience with tools such as Tenable/Nessus, Nmap, Wireshark, Burp Suite, Metasploit, Kali Linux, OT protocol analyzers, firewall review tools, and safe discovery or configuration-review utilities.
- Relevant certifications such as GICSP, GRID, GCIP, GPEN, CISSP, CISM, CRISC, CEH, PenTest+, Security+, Network+, CCNA, or equivalent OT/cybersecurity credentials.
- Experience preparing executive and technical reports that include operational impacts, compensating controls, remediation sequencing, and retesting criteria.