Director, OT/IoT Security Services- Remote (Anywhere in the U.S.)

GuidePoint Security · Remote · Engineering

Posted 2026-10-02

Apply for this role →

General Description

The systems our OT clients run treat drinking water, move natural gas, run production lines, and keep hospital equipment working. Many were installed before anyone thought about attackers, and plenty still run software the vendor stopped supporting years ago. You can't take a refinery controller offline on a Tuesday afternoon to patch it, and you can't reboot a substation to check whether a fix worked. This work needs people who understand the physical process as well as the network, and we've built a team of them. When we do it well, nobody outside the plant ever hears about it. GuidePoint Security is hiring a Director, OT/IoT Security Services to lead that team.

You'll report to the SVP of Offensive Security and own the practice: the team, the service catalog, delivery quality, and the P&L. The delivery managers already run day-to-day projects well, so expect to spend most of your time with engineers and clients, and to be the senior escalation point when a technical or client issue gets complicated. The rest goes to supporting regional sales teams, other GuidePoint Security practices, and technology partners.

In this practice, "Wow Them" means an account executive gets a scope and price back quickly, our engineers work safely on a running plant floor, and the client calls us for their next site.

About the OT/IoT Security Services Practice

The OT/IoT Security Services practice protects the industrial systems our clients depend on in energy, water, manufacturing, healthcare, transportation, and other critical infrastructure sectors. We deliver in every GuidePoint Security region and provide the services behind GuidePoint Security's OT technology partnerships.

Most of the team came to security from the plant floor or the military: veterans and former engineers from utilities, oil and gas, manufacturing, and nuclear power. They know what an operator is thinking when a consultant walks into the control room with a laptop, and safety and uptime come first on every job.

A typical client relationship starts with finding out what's actually on the OT network and where it's exposed. From there we design segmentation and controls that don't interrupt operations, and many clients stay with us for ongoing OT vulnerability management. The work in between includes OT risk assessments against ISA/IEC 62443, NIST SP 800-82, NERC CIP, and the TSA security directives; OT penetration tests scoped for live environments; and deployment and tuning of OT visibility and secure remote access platforms.

OT has problems you won't find in IT security, like hunting for an attacker on a network that can't handle an active scan, or explaining a firewall change to someone who has to keep a turbine running. Every site is different, and that's a big part of why we stay.

What sets the practice apart

A multi-vendor OT lab with PLC hardware and several visibility and remote access platforms, so clients can compare them side by side before buying

Vendor-objective advice. We work with many platforms and can tell a client which one fits their environment

A fast-growing OT practice on track to become one of GuidePoint Security's top practices, with leadership support and the autonomy to shape the service catalog, lab, and team

Roles and Responsibilities

Lead and grow the OT team of managers, engineers, and operations staff while fostering an environment that supports long-term retention. Meet regularly one-on-one with your managers, spend time with the engineers, and stay close enough to active engagements that problems come up early instead of at closeout. Adapt the team structure as the practice scales, guided by input from those performing the work.

Build a mentorship program that pairs experienced OT engineers with those who are new to OT or to client-facing services delivery, and define clear career and certification paths. Give engineers supported time in client conversations before asking them to lead one.

Standardize how the practice runs: shared templates, delivery playbooks, and a clear path from scoping through closeout for each service, building on what the team already has.

Refine the delivery methods the team already uses: OT-safe rules of engagement, passive-first testing, quality review, and coordination with plant operations around change and outage windows.

Own the practice's financials, including bookings, revenue, delivery margin, utilization, and operating cost. Produce a monthly forecast leadership can plan on, and plan staffing and capacity so the team can take on new work without burning out.

Support a growing service catalog: OT assessments (ISA/IEC 62443, NIST SP 800-82, NERC CIP, TSA security directives), architecture and segmentation, OT penetration testing, platform implementation and tuning, managed OT vulnerability services, and IoT security services.

Make our deployment and operations services the obvious add-on when a client buys an OT platform. Work with technology partners to define a services path for each platform, and report results to clients in terms they can check: assets covered, detections tuned, alerts reviewed, vulnerabilities fixed.

Support regional sales leaders and account executives on OT opportunities. Turn scoping requests around quickly, help qualify and price deals, and work on key pursuits and RFPs. The account executive owns the client relationship. Your job is to make bringing in the OT team simple for them.

Manage the OT lab. Work with leadership and partners to keep it current, use it for training and presales, and set up a model for charging for workshops and demos.

Represent the practice in the OT security community through select speaking, writing, and standards work, while keeping your focus on the team and clients.

Required Experience and Education

BS/BA + 7 -10 years of experience OR MS/MA + 5-12 years of experience

5+ years leading people managers on OT/IoT security delivery or consulting teams, including coaching managers as they grow leaders of their own, with accountability for bookings, margin, or utilization

Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Experience developing engineers into consultants, presales contributors, or leaders

CISSP, GICSP, or GRID, or equivalent experience

Preferred Experience and Education

You don't need all of these. If you have most of them, or comparable experience, we'd like to hear from you.

A recognized presence in the OT/ICS security community, for example speaking at industry events or contributing to standards and research, and a track record peers, partners, and clients can vouch for

Hands-on work in industrial environments (ICS, SCADA, DCS, PLCs, safety systems, industrial protocols) as an engineer, operator, integrator, or consultant in utilities, oil and gas, manufacturing, nuclear, transportation, healthcare, or the military

Working knowledge of OT frameworks or regulations, such as ISA/IEC 62443, NIST SP 800-82, NERC CIP, or the TSA security directives, and the ability to explain it to both a CISO and a plant manager

Experience deploying or tuning OT visibility platforms and working with technology partners

Experience turning custom engagements into standard, priced services that a larger sales team sold regularly

Additional certifications such as GCIP, ISA/IEC 62443, or CISM

Travel Requirements

Up to 30% travel to client industrial sites, regional sales teams, and occasional industry events

Physical Requirements

Sedentary work

Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day

Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

Occasional travel to client industrial sites, which may involve walking plant floors and entering operational areas, and to conferences that involve prolonged standing or walking

Apply for this role →

← Back to all jobs