ForgeApply · Job listing
OT Network & Security Engineer
Vulcanelements
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence, and Transparency.
As the OT Network & Security Engineer you will design and secure the operational technology backbone for a massive 1 million square foot manufacturing facility expansion. You will produce the OT network design basis for the new facility, author the IEC 62443 zone-and-conduit architecture and write security requirements into every OEM equipment contract or develop them in parallel. This is a high-impact, high-ownership role requiring genuine depth in both industrial networking and OT security.
Responsibilities
• Produce the OT network architecture for a large-format industrial facility: MDF/IDF distribution, fiber backbone topology, switching and routing design, IP schema, and resilience strategy.
• Freeze IDF locations, pathways, and enclosure requirements into construction drawings on the construction schedule’s
• Author and maintain the IEC 62443 zone-and-conduit register, the living document that is the firewall policy. Set security-level targets per zone.
• Write network and security requirements into all equipment packages ahead of Factory Acceptance Tests, and verify them at acceptance alongside Controls Engineers.
• Design and operate the remote access architecture for internal OT network access and OEM support connectivity, with per-vendor approval and session control.
• Coordinate the enterprise boundary with IT: DMZ services, WAN demarcation, identity architecture, and CMMC/CUI compliance evidence for the U.S. government partnership.
• Select and onboard the managed OT detection-and-response provider ahead of first energization; scope the independent IEC 62443 risk assessment and penetration test; own patch-versus-compensating-control decisions with the area controls engineers.
Deliverables You Will Develop, Review, or Support
• OT network design basis, MDF/IDF standards, IP schema, and fiber/cabling specifications with acceptance criteria.
• Zone-and-conduit register, security-level targets, firewall policy set, and the secure remote access design.
• OEM network/security requirement specifications, FAT verification records, CMMC/CUI evidence packages, and the OT incident-response plan.
• Switch and firewall configuration standards under change control, asset inventory, and the managed detection and service integration.
Responsibilities and tasks outlined are not exhaustive and may change as determined by the needs of the business.
Qualifications
• Bachelor’s or Master’s degree in Engineering, Computer Science, or a related field with 7+ years spanning industrial networking and OT security, or equivalent demonstrated depth in both — genuine capability on each side, not one with awareness of the other.
• Ability to design and defend segmentation, switching, routing, and firewall policy for industrial Ethernet environments, and to reason about control-traffic behavior (EtherNet/IP or comparable) when making design trade-offs.
• Ability to apply zone/conduit thinking and risk-based security levels to a real plant - asset inventory, monitoring, secure remote access, and patch/compensating-control judgment under production constraints.
• Ability to take a network design through construction: fiber topologies, IDF and enclosure planning, and working productively with construction and cabling contractors.
• Ability to write requirements vendors can build to and auditors can verify, and to defend security decisions to both operations and compliance audiences.
Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.
Preferred Skills
• Formal IEC 62443 project experience (zone/conduit registers, security-level assessments) or NERC CIP program work that translates directly to it.
• Greenfield or major-expansion industrial network design, including construction-phase coordination.
• Field or professional-services background with an OT security platform or consultancy (Claroty, Dragos, Nozomi class, or an OT security practice).
• Defense industrial base, government-partnered, or otherwise compliance-driven manufacturing environments (CMMC, NIST 800-171/82).
• Experience selecting or managing a managed OT detection-and-response service.
• GICSP, ISA/IEC 62443 certificates, CISSP, CCNP, or equivalent credentials.
• Industrial wireless design and site RF survey experience.
• Familiarity with Rockwell/EtherNet/IP-centric plant architectures and industrial DMZ patterns.
• Experience in regulated industries such as Defense, Aerospace, or Automotive.
Physical and Environmental Requirements
The position requires regular presence on the production floor and the ability to navigate all areas of the facility. Candidates must be able to climb stairs, stand and walk for extended periods, and work in environments that may be hot, humid, or noisy. The role also requires the use of personal protective equipment, including respirators, and adherence to all applicable safety policies, procedures, and regulatory requirements. Employees must be able to complete required fit testing, wear appropriate PPE for the duration of assigned tasks, and respond safely to changing conditions within the production environment.
Salary insight
This posting doesn't disclose pay. Across 56 Raleigh-Durham jobs with disclosed salaries on ForgeApply, the median is $125k.
See full Security Engineer salary data for Raleigh-Durham →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Vulcanelements?
Apply in about a minuteSimilar jobs
- Staff Network Security Engineer — Digitalocean98 · Remote
- Staff Network Security Engineer — Digitalocean98 · Seattle
- Network Security Engineer — Zoox · Foster City, CA
- Network Security Engineer — Etched · San Jose
- Network Security Engineer — Accenturefederalservices · Washington, DC
- Network Security Engineer — Lightningai · San Francisco, California, United States; Seattle, Washington, United States
- Network Security Engineer — Guidepointsecurity · Remote
- Network Security Engineer — Xai · Austin, Texas; New York, New York; Palo Alto, California; Washington, D.C.
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Raleigh-Durham · More jobs at Vulcanelements · Browse all jobs