Prepin
Log in
Aurora Organic Dairy

engineering opportunity

OT Cyber Security Engineer

The OT Cybersecurity Engineer is responsible for securing industrial control systems and manufacturing automation environments through network segmentation, monitoring, and incident response. The role also involves collaborating with IT and plant operations to maintain system integrity, manage vulnerabilities, and ensure compliance with security governance.

Boulder, Colorado, United StatesonsiteFULL_TIME

Posted

About the role

What will you do at Aurora Organic Dairy?

PURPOSE: The OT Cybersecurity Engineer is accountable for securing Aurora Organic Dairy’s Operational Technology (OT) environments, including industrial control systems (ICS), SCADA networks, PLCs, HMIs, manufacturing automation, and plant-floor network infrastructure. This role focuses on implementing OT-specific security controls, monitoring for anomalies, managing OT threats, ensuring system integrity, and maintaining alignment with operational reliability and safety.

The position also works closely with the Cybersecurity Analyst on audits, DR/BC documentation, compliance evidence, and security governance and with the IT Cybersecurity Engineer role for issues communicated to the OT Cybersecurity Engineer related to OT systems.

PRIMARY RESPONSIBILITIES:

• Engineers, implements, and maintains OT cybersecurity protections including firewalls, segmented zones, secure remote access, and industrial security controls.

• Monitors OT networks and industrial systems for malicious activity, unauthorized changes, or operational anomalies using OT-specific monitoring tools.

• Leads OT incident response across production environments, ensuring safe and minimal-disruption containment, eradication, and recovery.

• Maintains OT network segmentation, including zoning, conduits, firewall policies, and IT/OT isolation boundaries.

• Works closely with engineering, plant operations, and controls technicians to secure PLCs, HMIs, historians, VFDs, and automation systems.

• Manages OT patching, vulnerability remediation, and secure configuration baselines aligned with production safety constraints.

• Maintains up-to-date OT network diagrams, architecture documentation, asset inventories, and system mapping.

• Provides OT cybersecurity guidance to plant engineering and operations groups.

• Supports secure commissioning, upgrades, and lifecycle projects for plant automation equipment.

• Collaborate with IT, Engineering, and Operations on cross-domain cybersecurity reviews.

• Assist with OT-focused security awareness initiatives.

• Participate in after-hours maintenance windows and emergency response activities.

* Lead annual Disaster Recovery / Business Continuity preparation, table-top exercises, strategy and improvements across Aurora Organic Dairy.

* Manages tasks in a fast-paced environment, driving all issues to resolution with a strong focus on customer satisfaction and efficient task execution.

* Provides Tier 2 and 3 support for complex issues that cannot be resolved by Service Desk support team.

* Coordinates problem resolution with vendors and maintains communications with internal / external stakeholders during the problem resolution process.

* Works with network engineering to recommend and implement improvements to overall performance and reliability, including installing, upgrading/patching, monitoring, problem resolution, automation, and configuration management.

SECONDARY / ADVISORY RESPONSIBILITIES:

• Provides cybersecurity guidance related to IT/OT boundary controls and OT network connectivity; IT enterprise network ownership remains with IT Operations and IT Cybersecurity Engineer.

* Regularly attends cybersecurity training courses, webinars, and programs to maintain understanding of the ever-evolving threat landscape, industry standards, best practices, and security technologies.

* Responsible for remediating gaps identified through vulnerabilities scans and monitoring software.

* Supports, communicates, and monitors compliance to information security policies.

* Implements and maintains information security awareness and training initiatives for all employees.

* Works with IT Operations team to maintain AOD network documentation and assets.

MEASURES OF SUCCESS:

* OT network segmentation implemented and maintained per approved architecture

* OT asset inventory complete and current

* OT incidents detected, contained, and documented with no unapproved downtime

* No material audit findings related to OT cybersecurity controls without VP of IT Exception Approval.

* Clear escalation of unresolved OT risks to VP IT

OTHER REQUIRED RESPONSIBILITIES:

* Manages tasks in a fast-paced environment, driving all issues to resolution with a strong focus on customer satisfaction and efficient task execution.

* Excellent communication skills, especially when working with users or other IT team members to resolve technology issues.

* Periodic after-hours and weekend work is required to address urgent issues, perform routine maintenance, and monitor business email and other communication channels to ensure timely response to critical notifications.

* AVAILABILITY / RESPONSE EXPECTATIONS Due to the operational and cybersecurity criticality of IT Operations, employees in this role may be assigned to a formal on-call rotation. When scheduled as the on-call resource, employees must:

• Maintain access to email, phone, and text messaging to receive incident notifications

• Acknowledge and triage incidents within response times defined in the After-Hours IT Coverage Procedure

• Escalate unresolved incidents per established procedures

After-hours on-call coverage is scheduled in advance. Response expectations apply only during assigned on-call periods.

4. COMPETENCIES REQUIRED FOR SUCCESS: Which competencies are required for successful performance? See HR for list of competencies.

Analysis Skills

Judgement/Decision Making

Pragmatism

Initiative

Follow Through

Problem Resolution

Excellence

Adaptability

Customer Focus

Team Player

Communication – Oral / Written

Initiative

Emotional Intelligence

Organization / Planning

Independence

Creativity

Pragmatism

KNOWLEDGE & EXPERIENCE:

• Bachelor’s degree in Cybersecurity, Engineering, Information Systems, or a related field—or equivalent experience.

• 3–5 years working with industrial control systems (PLC, SCADA, HMI, DCS) in manufacturing or industrial operations.

• Experience designing and implementing OT network segmentation, industrial DMZs, and secure remote access solutions.

• Strong understanding of OT protocols including Modbus, Ethernet/IP, Profinet, OPC UA, and BACnet.

• Familiarity with ICS cybersecurity frameworks such as ISA/IEC 62443 and NIST SP 800-82.

• Experience with OT-specific asset discovery, anomaly detection, or industrial security platforms.

• Knowledge of patching limitations, lifecycle constraints, safety considerations, and uptime requirements for OT.

• Demonstrated experience collaborating with IT, Controls Engineers, and plant operations teams.

• Preferred certifications include GICSP, ISA/IEC 62443 Cybersecurity Certificate, Security+, or CySA+.

* Bachelor's degree in Computer Information Systems or related work experience.

* Experience with CISCO and Fortinet (firewalls, routers, switches). Fortinet, Cisco and Microsoft Server certifications preferred.

* Experience with ITIL, with ITIL Foundations Certification preferred.

* Experience working with Microsoft Windows Server 2012 R2 and above.

* 3-5 years of network, server and systems administration experience in a multi-site enterprise environment.

* 3-5 years of experience in working with wide and local area networks.

* Experience with installing, administering and troubleshooting using network security solutions.

* Experience advising as to security best practices and participating in executing key security initiatives.

* Experience remediating network vulnerabilities based on security assessments and penetration tests.

* Experience with tools that actively defend against threats, such as anti-virus, MDR, EDR.

* Experience with information security technologies such as event log management, IDS/IDP, SIEM and SOAR, and vulnerability assessments.

* Proficient in LAN/WAN/WLAN infrastructures including switches, NICs, fiber, and various network devices and appliances.

* Proficient in administering an enterprise class WiFi network. Experience with Meraki and Ubiquiti preferred.

* Experience in troubleshooting routing protocols (BGP, EIGRP, OSPF, Layer 3 switching).

* Must possess a valid driver’s license, reliable mode of transportation and proof of automobile insurance with required levels of coverage.

6. Physical

Requirements

  • Describe the specific physical requirements needed for this position.
  • Must be able to work safely in plant and farm environments; to lift up to 50 lbs., work with equipment on the floor (under desks) and from a ladder. Regular standing, walking, bending, stooping, sitting in various positions for long periods of time. Use of hands to handle, grasp and reach with hands and arms for long periods of time. Climb, balance, kneel, crouch, and crawl. Available for regular scheduled travel to remote facilities via automobile or airline.

Which skills does this role require?

OT CybersecurityIndustrial Control SystemsSCADAPLCHMINetwork SegmentationIncident ResponseVulnerability ManagementNIST SP 800-82Network AdministrationDisaster RecoveryICSDCSModbusEthernet/IPProfinetOPC UABACnetSecurity+CySA+BGPEIGRPOSPF

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.