Operational Technology (OT) Network Administrator

DEFTEC CorporationSånta Rita-Sumai, GU
Onsite

About The Position

The Operational Technology (OT) Network Administrator serves as the senior technical authority responsible for designing, securing, and sustaining highly available industrial and building automation networks that support mission‑critical FRCS, ICS, SCADA, and BMS environments. This role configures and maintains ruggedized network hardware, implements deterministic Layer‑2 topologies, enforces strict segmentation aligned with the Purdue Model, and manages PPSM to ensure only authorized industrial protocols traverse secured enclaves. The administrator leads OT boundary defense through NGFWs and unidirectional gateways, applies and tests OT‑specific STIGs safely, and conducts advanced protocol analysis to resolve connectivity and performance issues affecting physical facility systems. Additional responsibilities include developing SOPs and baselines, supporting RMF artifacts and cybersecurity compliance, evaluating contractor designs and BOMs, and providing SME oversight during integration, testing, commissioning, and MILCON modernization efforts. The position requires a U.S. citizen with an active Tier 5 Top Secret clearance and extensive, specialized experience securing and operating OT networks without disrupting critical facility operations.

Requirements

  • Must be a United States citizen.
  • Must possess an active Tier 5 (T5) Top Secret security.
  • Minimum of 5 years of advanced network administration experience, with at least 3 years explicitly focused on ICS, SCADA, BMS, FRCS or IT/OT network environments.
  • Deep technical expertise in Operational Technology (OT) network administration, focusing on strict network segmentation, firewall rule development, and the routing of industrial protocols (e.g., BACnet/IP, Modbus TCP).
  • Proven ability to securely apply DoD cybersecurity mandates, NIST SP 800-82 standards, and OT-safe network monitoring practices within the Purdue Model, ensuring deterministic traffic flows and highly available connectivity without disrupting critical facility operations or life-safety systems.
  • Ability to communicate in English fluently and effectively, both orally and in writing.
  • Demonstrated ability to read and interpret Command policies, technical documents, and manuals.
  • Demonstrated ability to prepare correspondence, write reports, and communicate effectively with other governmental professionals and stakeholder representatives of various backgrounds (including Government senior civilians, military personnel, and contract management).
  • Demonstrated experience in the use and application of the Microsoft Office Suite (Word, Excel, PowerPoint, Outlook, etc.).
  • Capable of the physical exertion required to perform the necessary services. This includes long periods of standing; walking over rough, uneven, or rocky surfaces; recurring bending, crouching, stooping, and reaching; climbing ladders; lifting and moving IT/OT equipment (up to 25 lbs); and other physical activities common to mechanical rooms and facility environments.
  • Must have sufficient vision to identify safety hazards.
  • Work Role Code (WRC): 441
  • Work Role Title: FRCS Network Administrator
  • Required Proficiency Level: Intermediate
  • Must possess and maintain at least one of the following commercial certifications prior to onboarding: CEH, Cloud+, GCIH, GICSP, GSEC, Security+, SSCP, SecurityX (CASP+), CCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, GFACT

Responsibilities

  • Configure and maintain industrial-grade network hardware (e.g., Cisco Industrial Ethernet, Palo Alto, Data Diode, Allen-Bradley Stratix, Ruggedcom, standard enterprise switches adapted for OT) deployed in mechanical rooms and harsh physical environments.
  • Manage network topologies (e.g., Resilient Ethernet Protocol (REP), Device Level Ring (DLR)) to ensure rapid failover and continuous deterministic traffic flow for time-sensitive control processes and environmental controls.
  • Maintain comprehensive backup solutions for all industrial and building switch, router, and firewall configuration files.
  • Implement strict network segmentation and micro-segmentation adhering to the Purdue Enterprise Reference Architecture (PERA).
  • Manage Ports, Protocols, and Services Management (PPSM) across the IT/OT boundary, ensuring only authorized protocols (e.g., BACnet IP, LonWorks, Modbus TCP, Fox Protocol, DNP3, CIP) traverse network enclaves.
  • Configure and manage OT-specific Next-Generation Firewalls (NGFW) and Unidirectional Gateways (Data Diodes).
  • Apply network-specific Security Technical Implementation Guides (STIGs) securely, testing configurations in non-production settings to prevent accidental physical equipment shutdowns.
  • Act as the primary escalation point for severe network degradation, packet loss, or routing failures within the FRCS/ICS/BMS environment.
  • Utilize advanced protocol analyzers (e.g., Wireshark) tailored for industrial and building protocols to conduct root-cause analysis on connectivity drops impacting physical machinery and facility controls.
  • Coordinate with facility/mechanical engineers, SCADA/BMS vendors, and IT cybersecurity teams to resolve boundary crossing anomalies.
  • Evaluate network capacity and provide engineering recommendations for lifecycle replacements, bandwidth upgrades, and hardware specifications.
  • Author network-specific Standard Operating Procedures (SOPs) and system baselines for the OT environment.
  • Support the RMF process for Platform IT (PIT) and FRCS by providing technical artifacts, topology diagrams, hardware/software lists, PPSM, and supporting vulnerability scans.
  • Participate in facility modernization and Military Construction (MILCON) project design reviews (35%, 65%, 95%, 100% phases).
  • Evaluate proposed contractor network architectures, hardware Bills of Materials (BOM), and PPSM for compliance with Command OT standards, the Purdue Model, and DoD cybersecurity mandates.
  • Provide SME support and oversight during integration, testing, and commissioning of new control systems and HVAC/Building systems.
  • Collaborate with government stakeholders and the cybersecurity commissioning team (CyCx) prior to final project handover and government acceptance.

Benefits

  • medical
  • dental
  • vision
  • holiday
  • paid time off
  • 401K with a match
  • life insurance
  • short/long-term disability
  • educational reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service