
Technology & Security Consultant
AECOM
full-time
Posted on:
Location Type: Remote
Location: Virginia • United States
Visit company websiteExplore more
Salary
💰 $135,000 - $155,000 per year
Tech Stack
About the role
- Develop and formulate solutions to client problems on assigned projects.
- Under general direction, responsible for the creation of work plans and task definitions.
- Has broad technical knowledge but possesses an area of specialization or focus.
- Gather and correlate engineering data using established and well-defined procedures.
- Work on detailed and/or routine design and/or consulting assignments.
- Propose solutions to solve new and/or complex problems encountered.
- Provide guidance and direction to internal mid-level consultants and production staff.
- Perform work in accordance with the agreed-upon budget and schedule with minimal supervision.
- Perform cybersecurity assessments of OT/ICS environments, including SCADA systems, PLCs, RTUs, HMIs, field devices, and supporting network infrastructure.
- Identify vulnerabilities, analyze risk posture, and develop actionable remediation plans aligned with industry standards and federal requirements.
- Support implementation and documentation of controls in accordance with the Risk Management Framework (RMF) and applicable cybersecurity frameworks (e.g., NIST-based standards).
- Develop and maintain required cybersecurity documentation, including System Security Plans (SSPs), security assessment reports, Plans of Action & Milestones (POA&Ms), and related compliance artifacts.
- Collaborate with engineering, network, and project management teams to ensure cybersecurity requirements are integrated into system design and deployment.
- Support Authority to Operate (ATO) efforts and ongoing compliance monitoring activities.
- Conduct technical reviews, analyze system configurations, and recommend improvements to enhance system resilience and regulatory compliance.
- Provide clear, concise, and technically sound written deliverables for Federal clients.
- Support project planning, scheduling, and execution activities as needed.
Requirements
- BA/BS Cybersecurity, Information Technology, Engineering or related field + 2 years of related experience or demonstrated equivalency of experience a education.
- 2+ years of relevant industry experience in OT/ICS cybersecurity.
- Experience securing SCADA, PLC, and industrial network environments.
- Experience with cybersecurity frameworks and Risk Management Framework (RMF).
- Due to the nature of this work, US Citizenship is required.
- Knowledge of cybersecurity and privacy laws, regulations, and compliance standards.
- Experience conducting security risk assessments and developing remediation plans.
- Previous experience supporting Federal projects.
- Experience developing and maintaining Authority to Operate (ATO) packages.
- Hands-on experience with vulnerability management, network segmentation, and system hardening in OT environments.
- Relevant certifications such as Security+, CISSP, CISM, or equivalent industry certifications are a plus.
- Experience supporting DoD, DHS, or other Federal agencies.
- Possess an active security clearance.
- Strong technical writing, analytical, and governance skills.
- Fluent in English (read, write, and speak).
Benefits
- medical
- dental
- vision
- life
- AD&D
- disability benefits
- paid time off
- leaves of absences
- voluntary benefits
- perks
- flexible work options
- well-being resources
- employee assistance program
- business travel insurance
- service recognition awards
- retirement savings plan
- employee stock purchase plan
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity assessmentsOT/ICS environmentsSCADA systemsPLCsRTUsHMIsvulnerability managementnetwork segmentationsystem hardeningrisk assessments
Soft Skills
technical writinganalytical skillsgovernance skillsguidancecollaborationproblem-solvingcommunication
Certifications
Security+CISSPCISM