Title: Operational Technology (OT) Security Specialist
EXEMPT
POSITION DESCRIPTION Job Code #
POSITION TITLE: Operational Technology (OT) Security Specialist DATE: February 2026
REPORTS TO: Regional IT Manager GRADE:
DEPARTMENT: Corporate IT LOCATION: Riverside, CA
ROLE DESCRIPTION: The Operational Technology (OT) Security Specialist is a key member of the Global Cybersecurity team who works collaboratively with Plant Engineering, Maintenance, Quality, and Corporate IT departments to define, implement, and maintain Cybersecurity standards across a global footprint of Production environments.
The OT Security Specialist is responsible for executing OT Security projects, supporting planning efforts, and serving as a project lead to ensure high-quality delivery and ongoing controls management. This hands-on position uses the latest cybersecurity tools and cyber risk management approaches to perform or oversee OT Security technical work globally for Bourns. This position is responsible for the management of systems and controls in protecting production lines, automation and robotics systems, production networks, Programmable Logic Controllers (PLC), Industrial Control Systems (ICS), and IIoT devices against cyber and other threats. Responsibilities include the planning and implementation of OT Security controls, and solutions in alignment with corporate standards and best practices.
- DUTIES AND ACCOUNTABILITIES PRIMARY
- Conduct security risk assessments for Operational Technology (OT), and various and work with related owners to track identified gap remediation to completion.
- Manage and oversee an OT vulnerability and patching management program, including tools and methodologies used, procedures, remediation, and reporting.
- Manage and respond to customer and compliance-initiated security audits, working with OT and Business owners to implement remediation solutions, processes, and procedures.
- Create and maintain the OT Security components of the Bourns Cyber Security Program, including Policies, Operating Procedures, Control Documents, and Architectural Diagrams in alignment with security standards such as IATF, ISO, NIST, and CIS.
- Continuously update the OT Security program to comply with changing regulatory and customer requirements and to protect against evolving cyber threats.
- Provide management with periodic OT Security presentation updates and reports, depicting current state of the program, accomplishments, risk areas, and security defense roadmaps.
- Develop and maintain OT incident response procedures including threat containment, eradication, root cause analysis, and remediation. Test and update these procedures annually and actively oversee and document OT security incidents as they occur.
- Review security risks associated with new OT solutions, services, applications, and infrastructure, ensuring their compliance with security policies and standards.
- Maintain a standardized and centrally managed inventory of OT assets along with an OT environment summary including diagrams depicting key components and data flows by location or product line
- Use a standard security scanning and cleaning solution to secure OT machines which cannot be managed and secured by corporate systems
- Implement a common process to scan and move data from OT systems to Corporate or other systems
- Develop and maintain a common policy and control for remote and third-party access to OT systems, including monitoring/logging, time-limited sessions, and network access method
- Develop and maintain standard policies and controls to ensure OT devices and systems are backed up and recovery tested at appropriate intervals
- Isolate and filter OT environments from other Bourns Networks and Internet using Layer 3 Segmentation, DMZ's, Firewalls, VLAN's, and ACL’s
- Deploy and maintain corporate standard Management and Security tools on supportable OT workstations, servers, and endpoints where possible
- Processes to determine and prevent exploitation of OT environment devices no longer supported and security patched by their manufacturer
- Develop security awareness program for Plant Operators tailored to their environments
- Conduct annual OT environment Risk Assessments and Tabletop exercises
- Develop and deploy OT security monitoring solution, feeding into the Bourns Security Operations Center (SOC)
- Maintain Business Contingency Plans (BCP) which cover recovery from an OT cybersecurity event
- Partner effectively with plant operations, maintenance, and engineering teams to implement and maintain OT security policies, controls, and security defense systems
- INTERPERSONAL SKILLS:
- Ability and skill to interact courteously and effectively with personnel at all levels and locations within the organization, with positive enthusiasm to deliver excellent service.
- Demonstrate independence, resourcefulness and the ability to organize and prioritize assignments.
- Self-motivated with the ability to effectively manage workloads.
- Results-oriented with the ability to multi-task and meet deadlines in a dynamic environment.
- Take ownership for issues and demonstrate pride in follow through to proper resolution.
- Possess strong work ethics, be approachable and lead by example.
- Must be able to handle stressful situations effectively and be eager to learn and grow.
IV. COMMUNICATIONS :
ORAL: Must be able to effectively communicate with both technical and non-technical personnel locally, regionally and globally, as well as with outside vendors and clients.
WRITTEN: Must be able to document in clear and concise detail, business Security requests and prepare detailed written instructions for training and reference. Must have excellent written skills to provide instructions, present ideas, concepts, and solutions to all levels of employees via e-mail, memos, graphs, charts, etc., and be able to analyze and generate reports and documentation.
V. SCHEDULING AND PLANNING:
SCHEDULING: Must be able to organize, prioritize and manage multiple projects, assignments, incidents, and requests.
PLANNING: Hardware, software, and services system design, implementation, application and system testing, workload and estimate project completion.
VI. ANNUAL OPERATING BUDGET: N/A
VII. BASIC JOB REQUIREMENTS:
EDUCATION: Bachelor’s Degree in Computer Science, Cybersecurity, Information Technology, or combination of education and work equivalent.
TRAINING AND EXPERIENCE: Five or more years of experience in OT/ICS Security and or Cybersecurity in a corporate environment with evidence of increasing responsibilities. Cybersecurity and Project Management certification(s) Preferred (CISSP, PMP, CEH, SANS, CASP+, Security+, etc.). Excellent interpersonal, written, and verbal communication skills required.
Experience required:
- Experience in managing Operational Technology Security Program in a multi-site, global organization.
- Experience with PLCs, Robotics, CNC equipment, motion control, and safety systems.
- Understanding of industrial communication protocols (EtherNet/IP, OPC UA, Profinet, Modbus TCP, CIP Safety).
- Hands‑on experience with industrial firewalls, managed switches, segmentation, VLANs, traffic filtering, and network architecture.
- Experience in the deployment and management of defenses and processes to avoid and mitigate malware, ransomware, and operational disruptions impacting manufacturing.
- Skilled at project management, prioritization, and analyzing business processes.
- A deep understanding of OT security best practices, current and evolving vulnerabilities, defenses, and attack methods, cryptography, authentication, authorization and security protocols.
- Working knowledge of industry security frameworks and standards such as IATF-16949, ISO-27001, NIST-800, TISAX, and other security standards and regulatory frameworks.
- Experience with end user and systems authentication architectures, EndPoint protection, Security Training,
- Security risk management, assessment, and gap remediation.
- Experience in managing and performing security vulnerability management, security penetration tests, and gap remediation.
- Experience working with OT and production teams to ensure secure and ongoing application security or production environments.
- Experience in security incident management programs, policy and procedure creation, management, and testing, as well as overseeing security incidents, forensics, and remediation.
- Fundamental knowledge of IT and OT network and security concepts, systems, protocols and best practices.
- Ability to successfully analyze, diagnose, and remediate complex security issues.
- EQUIPMENT OPERATED:
Telephone, personal computer, servers, network and personal printers, scanners, network switches and routers, various copy and facsimile machines.
- PHYSICAL EFFORT:
The physical demands described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
|
Physical Demands |
|
Lifting & Carrying Requirement |
|
Working Conditions |
|||
|
Sit |
Frequent |
|
Lift |
Light |
|
Confined Area |
No |
|
Stand |
Frequent |
|
Carry |
Light |
|
Atmospheric Conditions |
No |
|
Walk |
Frequent |
|
Push / Pull |
Light |
|
Exposed to Weather |
No |
|
Climb |
Occasional |
|
|
|
|
Hazardous Materials / Conditions |
No |
|
Crawl |
Occasional |
|
|
|
|
Extreme Temperatures |
No |
|
Bend/Stoop |
Occasional |
|
|
|
|
Noise Exposure |
No |
|
Knee/Squat |
Occasional |
|
|
|
|
Vibrations |
No |
|
Balance |
Occasional |
|
|
|
|
Potential allergens/irritants |
No |
|
Finger |
Frequent |
|
|
|
|
Other (Specify) |
|
|
Reach |
Occasional |
|
|
|
|
|
|
|
Feel |
Frequent |
|
|
|
|
|
|
|
Handle |
Frequent |
|
|
|
|
|
|
|
Hear |
Constant |
|
|
|
|
|
|
|
See |
Constant |
|
|
|
|
|
|
|
Talk |
Frequent |
|
|
|
|
|
|
|
Drive Vehicle(s) |
Occasional |
|
|
|
|
|
|
Definitions
100% - 95% Constant 50 + lbs. Strenuous Exposure Definite Yes
94% - 50% Frequent 21 – 50 lbs. Medium No Exposure No
49% - 01% Occasional 00 – 20 lbs. Light
0% Never
Physical Demands: Input a frequency criterion.
Lifting & Carrying: Input frequency and weight criteria.
Working Conditions: Input an exposure descriptor.
- WORKING ENVIRONMENT:
Exposed to higher than normal noise levels and environmentally controlled computer (cool) room.
- ADDITIONAL INFORMATION:
This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Position may require working occasional evenings and weekends.