IT/OT Systems Engineer
On-siteCentral, Louisiana, United States
Job Summary
Design cybersecured, resilient IT/OT architectures for railway operational environments, integrating applications with servers, networks, storage, and cybersecurity solutions. Configure, administer, and troubleshoot routers, switches, firewalls, and virtualisation platforms while implementing secure network segmentation and demilitarised zones. Conduct cybersecurity threat assessments, develop hardening standards, and support incident response for critical railway infrastructure. Assist with Factory Acceptance Tests, site commissioning, and operational readiness assessments across control centres, stations, and depots. Provide Level 2 or Level 3 technical support, maintain asset inventories, and manage change requests to ensure system availability and safety.
Required Qualifications
- Bachelor's degree or equivalent qualification in Computer Engineering, Computer Science, Information Technology, Electrical or Electronic Engineering, Telecommunications, Control and Automation, Systems Engineering, Railway Engineering, Cybersecurity, or a related discipline
- Typically five or more years of relevant professional experience in railway transportation, critical infrastructure, industrial automation, utilities, aviation, defence, or another high-availability environment
- Practical experience in IT/OT integration, network engineering, infrastructure engineering, system integration, cybersecurity, or operational support
- Experience working with suppliers, system integrators, internal engineering teams, and operational stakeholders
- Experience producing clear, auditable engineering documentation
- Familiarity with formal change, configuration, incident, problem, and risk-management processes
- Strong knowledge in TCP/IP, VLANs, switching, routing, multicast, VPNs, and network segmentation
- Experience with Enterprise or industrial firewalls and secure remote-access solutions
- Windows Server and Linux administration
- Active Directory, LDAP, RADIUS, or equivalent identity technologies
- VMware, Hyper-V, or comparable virtualisation platforms
- Storage, backup, restoration, and disaster recovery
- Public key infrastructure, certificates, and encryption
- Centralised logging, infrastructure monitoring, and network management
- Industrial control systems, SCADA, human-machine interfaces, and engineering workstations
- OT vulnerability management, secure configuration, and compensating controls
- Packet capture, event correlation, and systems troubleshooting
- High-availability and geographically resilient system architectures
- Knowledge of railway systems—such as signalling, CBTC, ETCS/ERTMS, station systems, traction-power SCADA, telecommunications, rolling stock, or operational control centres
Desired Qualifications
- Railway or public-transport experience
- Working knowledge of CLC/TS 50701 – Railway applications cybersecurity
- Working knowledge of IEC 62443 series – Industrial automation and control-system security
- Working knowledge of EN 50126 / IEC 62278 – Railway RAMS lifecycle
- Working knowledge of EN 50128 / IEC 62279 – Railway control and protection software
- Working knowledge of EN 50129 / IEC 62425 – Safety-related signalling systems
- Working knowledge of EN 50159 – Safety-related railway communications
- Working knowledge of ISO/IEC 27001 and ISO/IEC 27002
- Working knowledge of NIST Cybersecurity Framework and NIST SP 800-82
- Working knowledge of CIS Controls and CIS Benchmarks
- Working knowledge of Applicable national cybersecurity, critical-infrastructure, and data-protection requirements
- ISA/IEC 62443 Cybersecurity Certificate Program
- Global Industrial Cyber Security Professional – GICSP
- Certified Information Systems Security Professional – CISSP
- Certified Information Security Manager – CISM
- Certified in Risk and Information Systems Control – CRISC
- GIAC Response and Industrial Defense – GRID
- GIAC Critical Infrastructure Protection – GCIP
- Cisco CCNA, CCNP Enterprise, or CCNP Security
- Relevant Fortinet, Palo Alto Networks, or equivalent security certification
- Microsoft, VMware, Red Hat, or Linux Foundation certification
- TÜV Functional Safety or railway RAMS qualification
- CLC/TS 50701, EN 50126, EN 50128, or EN 50129 training
- Certified Systems Engineering Professional – CSEP
- Relevant railway cybersecurity training typically combines IEC 62443 and TS 50701 with asset identification, risk assessment, segmentation, hardening, incident response, and lifecycle governance
- Strong analytical and structured troubleshooting skills
- Sound engineering judgement in safety- and availability-sensitive environments
- Ability to balance cybersecurity, operational continuity, maintainability, performance, and cost
- Clear written and verbal communication
- Ability to explain technical risks to both technical and non-technical stakeholders
- Confidence in reviewing supplier solutions and constructively challenging technical assumptions
- Strong collaboration across IT, OT, engineering, safety, cybersecurity, operations, and maintenance teams
- Commitment to accurate documentation, knowledge sharing, and continuous improvement
- Knowledge of railway systems—such as signalling, CBTC, ETCS/ERTMS, station systems, traction-power SCADA, telecommunications, rolling stock, or operational control centres would be an advantage
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.