Senior/Staff/Principal SWE – OT Security Engineering

🕒 il y a 29 jours

🗣️🇺🇸🇬🇧 Anglais requis

Firewalls

GRPC

Rust

Splunk

TCP/IP

Go

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of AppGate

AppGate

501 - 1000 employés

🔒 Cybersecurity

🏢 Entreprise

Cybersecurity • Enterprise

AppGate est une entreprise mondiale de cybersécurité qui propose des solutions d'accès réseau à confiance zéro (ZTNA) à haute performance pour les entreprises et les agences gouvernementales. Sa plateforme applique des politiques d'accès adaptatives basées sur l'identité en utilisant une évaluation des risques en temps réel, une découverte d'applications alimentée par l'IA, et une architecture de routage direct conçue pour éviter les goulots d'étranglement du cloud et s'adapter aux environnements exigeants. AppGate offre également des services professionnels et des conseils en cyber sécurité — incluant la simulation d'adversaires, les tests de pénétration et les évaluations des risques d'accès tiers — pour aider les organisations à mettre en œuvre et à opérationnaliser les contrôles de confiance zéro.

Description

• **Secure Remote Access Platform: **Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments. • **Protocol-Aware Policy Authoring: **A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model. • **Evidence and Audit Baseline: **Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements. • **Session Governance: **Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments. • **Asset Context Ingestion (Phase 2+): **API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path. • **Design and implement **backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns. • **Build and maintain **REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations. • **Apply Zero Trust principles **to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments. • **Integrate **with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP. • **Own features end-to-end, **from architecture through production deployment in real customer environments. • **(Staff / Principal) **Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.

🎯 Exigences

• **Experience: **Hands-on background building or operating secure remote access systems — VPN, ZTNA, jump servers, privileged access, session brokers, or equivalent. • **OT Domain Knowledge: **Direct experience in or with OT / ICS environments — manufacturing, energy, utilities, oil and gas, water, transportation, or defense. • **Technical Fundamentals: ** • Strong systems programming in Go, Rust, or a comparable language • Solid networking (TCP/IP, TLS, firewalls) and identity (SAML, OIDC, PKI) fundamentals • Familiarity with the Purdue Model and IT/OT DMZ design patterns • Working knowledge of OT protocols: Modbus, DNP3, OPC-UA, EtherNet/IP • **Mindset: **High ownership, end-to-end accountability, comfortable in a small team where you solve problems before they become fires.

Postuler Maintenant

Emplois Similaires

🕒 il y a 29 jours

Zscaler

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🏢 Entreprise

Specialty Sales Account Executive at Zscaler leveraging AI for data security in healthcare. Impacting sales and product roadmap for Data Protection portfolio with Channel partners.

🇺🇸 États-Unis – Télétravail

💵 $122 500 - $175 000 / an

💰 Secondary Market en 2017-11

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 29 jours

Corelight

201 - 500

🔒 Cybersecurity

🏢 Entreprise

☁️ SaaS

Network Security Trainer developing cybersecurity training curriculum and leading in-person and virtual training sessions. Bringing SOC experience into curriculum development for operational training.

🇺🇸 États-Unis – Télétravail

💵 $180 000 - $214 000 / an

💰 €75 000 000 Series D en 2021-09

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 29 jours

Collibra

1001 - 5000

🏢 Entreprise

☁️ SaaS

Senior Product Security Engineer responsible for securing application products at Collibra. Identifying vulnerabilities and providing remediation consulting for global development teams.

🇺🇸 États-Unis – Télétravail

💵 $168 000 - $210 000 / an

💰 Venture Round en 2022-01

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Federal & Government Sales Account Executive leading U.S. sales strategy for cybersecurity solutions at Searchlight Cyber. Developing relationships and executing strategies across federal agencies and government accounts.

🇺🇸 États-Unis – Télétravail

💵 $150 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

AAA

5001 - 10000

🚗 Transport

👥 B2C

IT Security Engineer specializing in DLP and CASB engineering at CSAA Insurance Group. Involves design, optimization, and management of data protection solutions.

🗣️🇺🇸🇬🇧 Anglais requis