"ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges delivering custom solutions for AI data centers mission-critical facilities and front-of-the-meter assets. ON recently announced a 5GW partnership with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software ON.energy develops projects worldwide that set new benchmarks for resilience.
We're hiring a Senior OT/SCADA Cybersecurity Engineer to secure the industrial control systems behind our grid-connected energy portfolio — the SCADA site controllers PLCs power conversion systems and battery management systems that have to run safely and stay dispatchable around the clock. This is a hands-on role built around the security stack rather than the control system. You'll own and operate our OT security tooling and you'll set the standards and verification gates that the EMS controls and commissioning teams implement in the field.
You own and operate OT network monitoring and industrial IDS centralized logging and detection content the OT asset inventory PKI and the remote/vendor access platform. You define and verify others implement hardening baselines controller and gateway requirements site network designs backup and recovery standards and the security requirements in procurement specs and site acceptance — with your sign-off on the evidence before a site is accepted. Architecture & Segmentation Design IEC 62443-aligned zone and conduit architectures (Purdue Model) across site control plant SCADA and enterprise boundaries. Specify and validate default-deny rulesets on industrial firewalls DMZs and unidirectional gateways between OT DMZ and business networks. Work with our OT network architect on the reference site network design and drive it into EPC and integrator scopes of work. Define the security of SCADA links to utility control centers ISOs and third-party dispatch platforms. Provide application security recommendations. Monitoring Detection & Response Own the passive monitoring and industrial IDS platform design configuration and detection tuning for control-system behavior rather than generic IT signatures. Own the OT asset inventory and centralized log collection from SCADA hosts HMIs controllers and industrial network gear. Analyze Modbus TCP IEC 61850 and OPC UA traffic to baseline normal behavior and catch unauthorized commands scanning or malformed traffic. Write and exercise OT incident response playbooks loss of view loss of control ransomware in the DMZ compromised vendor access. You direct response remotely field teams execute recovery. Standards & Assurance Author hardening baselines for SCADA servers HMIs engineering workstations and historians coordinated with Sr. RHEL Systems Engineers validated with the EMS team not to disturb real-time performance. Define controller and gateway security requirements run-mode discipline access control firmware integrity logic change detection to include verifying compliance from monitoring data and evidence. Specify OPC UA security modes and TLS where equipment supports it with compensating controls where it doesn't. Set backup and recovery standards for PLC programs HMI projects SCADA databases and network configs and require the owning teams to demonstrate restores on a set cadence. Run risk-based vulnerability management against ICS advisories (CISA ICS-CERT OEM bulletins) and own the patch and firmware strategy that O&M executes in outage windows. Own the cybersecurity requirements in procurement specs FAT/SAT plans and site acceptance holding OEMs integrators and EPC partners to them. Identity & Access Own PKI and certificate lifecycle for site controllers gateways and OT-to-cloud telemetry including provisioning at commissioning and replacement during service events. Own the remote access platform brokered time-bound MFA-protected access with session recording for internal engineers and OEM vendors with no direct inbound paths to field equipment. Define how SCADA HMI and engineering workstation authentication integrates with centralized identity (Entra ID federated to AD/LDAPS for OT systems that require it) mandating local break-glass accounts so operators keep control when the directory or WAN link is down. Eliminate default and shared control-system credentials operate privileged access management and enforce least privilege for service and machine-to-machine accounts. Compliance Map controls to IEC 62443 and NIST SP 800-82r3 support NERC CIP where our assets are in scope and answer utility offtaker insurer and lender security reviews with evidence that holds up. Key
5–8 years in technical cybersecurity or control systems engineering most of it in OT/ICS environments. Proven experience securing SCADA and ICS in energy utility or heavy industrial settings with regards to live plants not just labs. This role is centralized but you need that field background for your requirements to survive contact with a real site. A track record of getting security implemented through other teams on technical credibility rather than direct control of the equipment. Working knowledge of IEC 62443 the Purdue Model and NIST SP 800-82r3 and the judgment to say what a control will cost in operational risk and propose the alternative. Industrial networking you can read a plant network drawing reason about segmentation and trace a dropped packet between an HMI and a PLC from a capture. Centralized identity and directory services (Entra ID AD/LDAPS SSO) with the judgment to apply them in OT without creating an availability dependency on the corporate network. Practical Linux and Windows administration plus enough scripting to manage the security stack at fleet scale rather than site by site. OT security platforms Hands-on with a passive monitoring and asset discovery platform (Nozomi Claroty Dragos Tenable OT Forescout Cisco Cyber Vision) or open-source equivalents (Zeek Suricata Wireshark Wazuh) plus SIEM/log aggregation PKI/CA tooling and a remote access or PAM platform. Control systems Working understanding of at least one SCADA/HMI platform — Ignition AVEVA Siemens WinCC Rockwell FactoryTalk — including its user model historian and remote client architecture enough to write requirements and read its logs familiarity with PLCs and RTUs (Siemens Rockwell Schneider Beckhoff SEL) and with PCS BMS meters and protection relays. Protocols & networking Modbus TCP/RTU IEC 61850 OPC UA with awareness of IEEE 2030.5 and SunSpec for DER managed industrial switches and firewalls (Cisco Fortinet Palo Alto Moxa Tofino) VPN architectures and data-diode gateways. Also useful identity provider and single sign-on (SSO) platform such as Authentik Zabbix or equivalent for OT infrastructure health and a preference for tailoring open-source tooling over ""black box"" commercial platforms.
Battery energy storage solar wind or DER. Especially site controller EMS and PCS/BMS integration. NERC CIP program experience or preparing OT evidence for utility and regulatory audits. MITRE ATT&CK for ICS and familiarity with known ICS threat activity (Industroyer TRITON PIPEDREAM FrostyGoop). Writing cybersecurity requirements into EPC OEM or integrator contracts and auditing delivery against them. Certifications GICSP GRID GCIP ISA/IEC 62443 Cybersecurity Fundamentals Specialist or higher SANS ICS410/ICS515 CISSP. LI-AD1 For US-based roles - What you’ll get Competitive salary + annual performance-based bonus eligibility Medical dental and vision insurance 401(k) with company match Paid time off and company holidays For Mexico-based roles - What you’ll get Competitive salary + annual performance bonus eligibility Christmas Bonus (Aguinaldo) 30 days Major medical expenses and life insurance Paid time off and holidays (per local policy) For all roles Professional development and growth opportunities Opportunity to grow with a mission-driven team shaping the future of clean energy Equal Opportunity ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment discrimination or retaliation. Accommodations If you need an accommodation during the application process email recruitment@onenergystorage.com
vary by role and location and are subject to change. Agency Notice ON.energy does not accept unsolicited resumes from staffing agencies search firms or third-party recruiters. Resumes submitted without a fully executed Master Services Agreement (MSA) and a written request from an authorized member of our Talent Acquisition team will be considered the property of ON.energy. No placement fees or compensation will be paid for unsolicited candidate submissions."
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.