Fortinet OT Security Engineer

Zappsec Inc.

India

On-site

INR 3,000,000 - 5,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zappsec Technologies Inc. seeks a Fortinet OT Security Engineer to secure OT networks in manufacturing sectors. You will segment plant networks, design DMZs, place FortiGate devices, and ensure visibility without disrupting operations.

The role requires NSE 5+ Fortinet certification, 5+ years in network security with FortiGate/FortiOS in production OT, and hands-on on-site work. You will collaborate with control engineers and safety teams to implement secure, compliant solutions.

Qualifications

  • Five+ years in network security with FortiGate/FortiOS in production OT.
  • Fortinet NSE 5+ certification required (NSE 5 or equivalent).
  • On-site work in OT environments with Purdue IEC 62443 knowledge.
  • Experience with industrial protocols and segmentation.
  • Ability to write client-facing documentation.

Responsibilities

  • Map client estate to the Purdue model and IEC 62443 zones.
  • Design and build the industrial DMZ between plant and IT.
  • Place FortiGate at cell/area boundaries including ruggedised models.
  • Use transparent mode and virtual domains where routing changes are not acceptable.
  • Segment legacy assets that cannot be patched or taken offline.
  • Write policy for industrial protocols (Modbus TCP, DNP3, IEC 60870-5-104, IEC 61850, EtherNet/IP, PROFINET, S7comm, BACnet, OPC UA).
  • Apply Fortinet industrial security service for protocol control and intrusion prevention.
  • Use virtual patching to protect unpatchable assets.
  • Baseline real traffic, then write policy from plant behavior.
  • Deploy FortiNAC for asset discovery and enforcement.
  • Integrate with OT visibility platforms (Nozomi, Claroty, Dragos).
  • Feed OT telemetry into FortiAnalyzer or FortiSIEM.
  • Replace shared VPN with identity-based access; build ZTNA.
  • Configure MFA and privileged session control; include session recording.
  • Design jump host and broker patterns.
  • Work inside plant change windows; site safety induction.
  • Coordinate with control engineers and operations leads.
  • Validate changes have no process impact.

Skills

Fortinet FortiGate
FortiOS
OT security
Purdue model
IEC 62443
Documentation

Tools

FortiNAC
FortiAnalyzer
FortiSIEM
FortiManager
FortiSwitch Rugged

Job description

Fortinet OT Security Engineer
Zappsec Technologies Inc.
About the role

Zappsec secures operational technology environments for clients in manufacturing, energy, utilities, and process industries. OT means the control systems that run physical processes, as distinct from corporate IT.

You will segment plant networks with Fortinet, build policy from observed industrial traffic, and give clients visibility into assets they currently cannot see. You will do it without stopping production.

This is a hands-on engineering role. Availability comes first in these environments. You will monitor before you block and alert before you enforce.

Certification requirement

Fortinet certification at NSE 5 level or above is mandatory for this role. This is a hard requirement, not a preference.

Fortinet has renamed its program twice in recent years, so read this before you rule yourself out.

  • Certifications issued between October 2023 and July 2026 used the FCP, FCSS, and FCX names. FCP covered the NSE 4 to NSE 6 band. FCSS mapped to NSE 7. FCX mapped to NSE 8.
  • Fortinet returned to NSE 1 through NSE 8 numbering in July 2026.
  • If your certification sits at NSE 5 or higher under either naming, you meet the requirement.
What you will own
Segmentation and architecture
  • Map the client estate against the Purdue model and agree the zone and conduit design under IEC 62443.
  • Design and build the industrial demilitarised zone between the plant network and corporate IT.
  • Place FortiGate at cell and area boundaries, including ruggedised models on the plant floor.
  • Use transparent mode and virtual domains where the client cannot accept routing changes.
  • Segment legacy assets that cannot be patched, upgraded, or taken offline.
Industrial protocol control
  • Write policy for industrial protocols including Modbus TCP, DNP3, IEC 60870-5-104, IEC 61850, EtherNet/IP, PROFINET, S7comm, BACnet, and OPC UA.
  • Apply the Fortinet industrial security service for protocol-aware application control and intrusion prevention.
  • Use virtual patching to protect assets that cannot take a vendor patch.
  • Baseline real traffic first, then write policy from what the plant actually does rather than from a document.
Asset visibility
  • Deploy FortiNAC for asset discovery, device profiling, and port level enforcement.
  • Build passive discovery using SPAN ports and network taps where active scanning is unsafe.
  • Integrate with OT visibility platforms already in the client estate, such as Nozomi, Claroty, or Dragos.
  • Feed OT telemetry into FortiAnalyzer or FortiSIEM where monitoring is in scope.
Secure remote access
  • Replace shared vendor VPN accounts with identity-based access for maintenance and support staff.
  • Build ZTNA, which stands for Zero Trust Network Access, for engineers and third party vendors.
  • Configure multi-factor authentication and privileged session control, including session recording where the client requires it.
  • Design jump host and broker patterns that satisfy both plant operations and the security team.
Change control and safety
  • Work inside plant change windows and planned maintenance outages, not around them.
  • Complete site safety induction and follow plant rules on the floor. Expect site work during commissioning and cutover.
  • Coordinate directly with control engineers, maintenance teams, and operations leads.
  • Validate that a change had no process impact before you close the window.
Compliance and documentation
  • Document zones, conduits, and data flows to a standard an auditor will accept.
  • Support client obligations under IEC 62443, NERC CIP, or the framework their regulator applies.
  • Produce high level designs, low level designs, runbooks, and as-built records.
  • Run knowledge transfer so plant and IT teams can operate what you built.
Requirements
  • Fortinet certification at NSE 5 level or above, as set out in the certification section.
  • Five or more years in network security with production FortiGate and FortiOS experience.
  • Direct hands-on work inside OT or industrial control system environments, on site rather than from a design document.
  • Working knowledge of the Purdue model and of IEC 62443 zone and conduit principles.
  • Familiarity with industrial protocols and how they behave on a live network.
  • Segmentation experience where availability constraints ruled out the obvious design.
  • Strong fundamentals across routing, switching, VLANs, IPsec, and firewall policy.
  • Ability to write client-facing documentation that does not need an editor to rewrite it.
  • Credibility with control engineers. You can explain a security control in terms of process risk.
Preferred
  • NSE 7 level certification, or the FCSS equivalent in Secure Networking.
  • Fortinet OT security certification, either current or previously held under the retired FCSS OT Security track.
  • ISA or IEC 62443 certification, or GICSP.
  • FortiNAC deployment experience in a production OT environment.
  • Exposure to FortiSIEM, FortiDeceptor, or FortiPAM.
  • Working knowledge of Rockwell, Siemens, or Schneider control platforms.
  • Experience in energy, utilities, mining, water, or discrete and process manufacturing.
Tools you will work with
  • Platform: FortiGate, FortiGate Rugged, FortiOS, FortiSwitch Rugged
  • OT security: Fortinet industrial security service, protocol application control, virtual patching
  • Visibility: FortiNAC, FortiAnalyzer, FortiSIEM, third party OT monitoring platforms
  • Access: ZTNA, FortiClient, FortiAuthenticator, FortiToken, FortiPAM
  • Management: FortiManager
  • Analysis: Packet capture, SPAN and tap collection, protocol analysis
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Fortinet OT Security Engineer
Fortinet OT Security Engineer

Zappsec • India

On-site
INR 1,800,000 - 3,000,000
Fortinet SASE and SD-WAN Engineer
Fortinet SASE and SD-WAN Engineer

Zappsec • India

On-site
INR 1,800,000 - 2,500,000
Fortinet SASE and SD-WAN Engineer
Fortinet SASE and SD-WAN Engineer

Zappsec Inc. • India

On-site
INR 1,200,000 - 1,800,000
Principal Systems Engineer - OT Security
Principal Systems Engineer - OT Security

Perception Point • Attibele

On-site
INR 1,800,000 - 3,200,000
Principal Systems Engineer - OT Security
Principal Systems Engineer - OT Security

Fortinet • Bengaluru

On-site
INR 500,000 - 800,000
senior Systems Engineer
senior Systems Engineer

Fortinet • Mumbai

On-site
INR 3,500,000 - 5,200,000
OT Security Engineer, Cyber Risk
OT Security Engineer, Cyber Risk

Kroll • Bengaluru

On-site
INR 1,800,000 - 3,800,000
Senior Systems Engineer
Senior Systems Engineer

Fortinet, Inc. • Mumbai

On-site
INR 4,000,000 - 7,000,000
Manager - Network & Infrastructure Security
Manager - Network & Infrastructure Security

EY • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior AI Infrastructure Security Consultant
Senior AI Infrastructure Security Consultant

EY • Bengaluru

On-site
INR 350,000 - 600,000