OT Network & Security Engineer

Vulcan ElementsResearch Triangle Park, NC
Onsite

About The Position

Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence, and Transparency. As the OT Network & Security Engineer you will design and secure the operational technology backbone for a massive 1 million square foot manufacturing facility expansion. You will produce the OT network design basis for the new facility, author the IEC 62443 zone-and-conduit architecture and write security requirements into every OEM equipment contract or develop them in parallel. This is a high-impact, high-ownership role requiring genuine depth in both industrial networking and OT security.

Requirements

  • Bachelor’s or Master’s degree in Engineering, Computer Science, or a related field with 7+ years spanning industrial networking and OT security, or equivalent demonstrated depth in both — genuine capability on each side, not one with awareness of the other.
  • Ability to design and defend segmentation, switching, routing, and firewall policy for industrial Ethernet environments, and to reason about control-traffic behavior (EtherNet/IP or comparable) when making design trade-offs.
  • Ability to apply zone/conduit thinking and risk-based security levels to a real plant - asset inventory, monitoring, secure remote access, and patch/compensating-control judgment under production constraints.
  • Ability to take a network design through construction: fiber topologies, IDF and enclosure planning, and working productively with construction and cabling contractors.
  • Ability to write requirements vendors can build to and auditors can verify, and to defend security decisions to both operations and compliance audiences.
  • Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.

Nice To Haves

  • Formal IEC 62443 project experience (zone/conduit registers, security-level assessments) or NERC CIP program work that translates directly to it.
  • Greenfield or major-expansion industrial network design, including construction-phase coordination.
  • Field or professional-services background with an OT security platform or consultancy (Claroty, Dragos, Nozomi class, or an OT security practice).
  • Defense industrial base, government-partnered, or otherwise compliance-driven manufacturing environments (CMMC, NIST 800-171/82).
  • Experience selecting or managing a managed OT detection-and-response service.
  • GICSP, ISA/IEC 62443 certificates, CISSP, CCNP, or equivalent credentials.
  • Industrial wireless design and site RF survey experience.
  • Familiarity with Rockwell/EtherNet/IP-centric plant architectures and industrial DMZ patterns.
  • Experience in regulated industries such as Defense, Aerospace, or Automotive.

Responsibilities

  • Produce the OT network architecture for a large-format industrial facility: MDF/IDF distribution, fiber backbone topology, switching and routing design, IP schema, and resilience strategy.
  • Freeze IDF locations, pathways, and enclosure requirements into construction drawings on the construction schedule’s
  • Author and maintain the IEC 62443 zone-and-conduit register, the living document that is the firewall policy. Set security-level targets per zone.
  • Write network and security requirements into all equipment packages ahead of Factory Acceptance Tests, and verify them at acceptance alongside Controls Engineers.
  • Design and operate the remote access architecture for internal OT network access and OEM support connectivity, with per-vendor approval and session control.
  • Coordinate the enterprise boundary with IT: DMZ services, WAN demarcation, identity architecture, and CMMC/CUI compliance evidence for the U.S. government partnership.
  • Select and onboard the managed OT detection-and-response provider ahead of first energization; scope the independent IEC 62443 risk assessment and penetration test; own patch-versus-compensating-control decisions with the area controls engineers.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service