Part-Time Operational Technology (OT) Penetration Tester

Information Management Resources, Inc.

New York, Northern (NY, KY)

Hybrid

USD 124,000 - 193,000

Part time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical coverage
401(k) with company match
Paid vacation and sick leave
Life insurance

Job summary

IMRI is seeking a part-time OT Penetration Tester to support OT, ICs, SCADA, and critical infrastructure environments. The role involves hands-on testing, risk-based analysis, and delivering practical remediation guidance while maintaining operational continuity.

You will work hybrid or onsite in Nassau County, NY, with standard business hours and occasional after-hours support. The position emphasizes disciplined coordination, safety planning, and clear executive communication.

Qualifications

  • Bachelor’s degree or equivalent professional experience in cybersecurity/IT/engineering.
  • 5+ years of cybersecurity assessment and OT/ICS security experience.
  • Hands-on OT/ICS or critical infrastructure security testing.
  • Strong understanding of OT networks, protocols, HMIs, PLCs, RTUs, remote access, and safety.
  • Experience with Horizon3.ai and OT testing tools; secure reporting practices.
  • Ability to conduct tests in production with disciplined coordination and safety planning.

Responsibilities

  • Perform hands-on OT/ICS penetration testing across OT/ICS environments.
  • Conduct passive/active discovery, architecture review, and risk-based validation.
  • Lead or support annual penetration testing and security validation activities.
  • Coordinate with stakeholders to minimize disruption to mission-critical operations.
  • Produce detailed findings, narratives, and remediation guidance for executives and technical teams.
  • Maintain non-disruptive testing approaches and proper engagement with clients.

Skills

OT/ICS security
Penetration testing
Vulnerability assessment
Risk assessment
Security engineering
Written communication
Executive briefing
Change control
Discipline coordination
Non-disruptive testing

Education

Bachelor's degree in Cybersecurity/IT/Engineering or related field

Tools

Horizon3.ai
Tenable/Nessus
Nmap
Wireshark
Burp Suite
Metasploit
Kali Linux
OT testing tools

Job description

COMPANY OVERVIEW

Join our award-winning team at Information Management Resources, Inc. (IMRI), a small business leader in the technology industry known for our commitment to innovation, excellence, and authenticity. Founded in 1992, IMRI has been at the forefront of delivering advanced cybersecurity and IT solutions, safeguarding organizations against evolving threats. We have built a reputation for our expertise in Cybersecurity, Digital Transformation, Strategic Business Consulting, and Staff Augmentation. Guided by our core values of innovation, excellence, and a solution-driven mindset, we have served a diverse portfolio of customers that includes federal agencies, state and local governments, and Fortune 1000 companies.

At IMRI, we recognize the integral part our employees play in our ongoing success. To support this, we offer a comprehensive benefits package, tailored to meet the individual needs of our employees. We are committed to promoting their overall well-being and equipping them with the necessary tools to flourish in their careers. We welcome you to be a part of our ongoing mission as we continue to navigate the digital landscape, committed to empowering organizations with our innovative solutions.

POSITION:Part-Time Operational Technology (OT) Penetration Tester

SUMMARY: IMRI is seeking a part-time OT Penetration Tester to support OT, ICs, SCADA, critical infrastructure, public-safety, segmented OT, and OT-adjacent environment and enterprise penetration testing. This role provides hands-on technical testing expertise to identify exploitable weaknesses, validate attack paths, assess risk, use manual and automated penetration testing approaches, and deliver practical remediation guidance while maintaining operational continuity, safety, and compliance with approved rules of engagement.

LOCATION/SCHEDULE: Hybrid or onsite as required supporting Nassau County, NY. Majority of work will be performed during standard business hours Monday-Friday, 8:00 AM-5:00 PM EST, with occasional nights, weekends, or approved maintenance-window support during OT/ICS discovery, rules-of-engagement coordination, testing execution, validation, reporting, and stakeholder briefings. (Anticipated 400 hours percontract year.)

KEY RESPONSIBILITIES:

  • Perform hands-on internal and external penetration testing, web application security testing, wireless assessment, firewall review, vulnerability validation, segmentation analysis, and controlled exploit testing across approved enterprise, government, and operational environments.
  • Perform passive and active discovery, architecture review, segmentation analysis, firewall and access-control review, vulnerability validation, and controlled exploit testing where explicitly authorized.
  • Support approximately 900 hours of annual senior penetration testing activities for County IT, District Attorney, Police Department, web application, wireless, firewall, infrastructure, and enterprise security validation activities.
  • Support approximately 400 hours of annual OT penetration testing activities for OT, ICs, SCADA, critical infrastructure, public-safety, segmented OT, and OT-adjacent assessment activities, including radio communications, CAD-related infrastructure, evidence systems, specialized operational networks, and related environments where applicable.
  • Coordinate closely with government client IT, legal or investigative stakeholders, public-safety representatives, authorized liaisons, system owners, and operational stakeholders to minimize disruption and protect mission-critical operations.
  • Use OT-safe testing methods that emphasize passive validation, configuration review, protocol-aware assessment, and controlled testing rather than disruptive scanning or exploitation.
  • Use automated penetration testing and attack-path validation tools, including Horizon3.ai where applicable, in coordination with approved rules of engagement, testing windows, credential handling requirements, and safety constraints.
  • Analyze findings using risk-based methods aligned to NIST CSF, NIST SP 800-53, NIST SP 800-82, NIST SP 800-115, CIS Controls, CVE/CVSS, and applicable CJIS considerations.
  • Develop detailed technical findings, evidence, attack-path narratives, operational impact analysis, prioritized remediation recommendations, and executive-ready summaries.
  • Support annual penetration testing, operational security validation, wireless assessment, firewall review, infrastructure hardening review, and modernization roadmap activities involving OT or OT-adjacent environments.
  • Participate in client briefings, remediation planning, retesting, lessons learned, and knowledge transfer activities to support long-term operational resilience.

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, Industrial Control Systems, or related field, or equivalent professional experience.
  • 5+ years of cybersecurity assessment, penetration testing, vulnerability assessment, network security, security engineering, or OT security experience, including senior-level enterprise penetration testing experience and hands-on OT/ICS or critical infrastructure security experience.
  • Hands-on experience assessing OT/ICS, SCADA, industrial networks, critical infrastructure, public-safety systems, segmented environments, or mission-critical operational networks.
  • Strong understanding of OT network architecture, industrial protocols, segmentation models, engineering workstations, HMIs, PLCs, RTUs, historian systems, remote access controls, and operational safety considerations.
  • Experience with penetration testing methodologies, vulnerability validation, attack-path analysis, firewall and network-device review, wireless assessment, automated penetration testing tools including Horizon3.ai, OT penetration testing tools, and secure reporting practices.
  • Ability to conduct testing in production or sensitive environments using disciplined coordination, change control, safety planning, and non-disruptive assessment techniques.
  • Strong written communication, technical reporting, stakeholder coordination, and executive briefing skills.

PREFERRED QUALIFICATIONS:

  • Experience supporting cybersecurity assessments for utilities, transportation agencies, defense organizations, law enforcement, emergency services, municipal environments, or other critical infrastructure operators.
  • Familiarity with NIST SP 800-82, NERC CIP concepts, CJIS security requirements, IEC 62443 principles, MITRE ATT&CK for ICs, OWASP, PTES, and OSSTMM-aligned testing practices.
  • Experience with tools such as Horizon3.ai, Tenable/Nessus, Nmap, Wireshark, Burp Suite, Metasploit, Kali Linux, OT penetration testing tools, OT protocol analyzers, firewall review tools, and safe discovery or configuration-review utilities.
  • Relevant certifications such as GICSP, GRID, GCIP, GPEN, CISSP, CISM, CRISC, CEH, PenTest+, Security+, Network+, CCNA, or equivalent OT/cybersecurity credentials.
  • Experience preparing executive and technical reports that include operational impacts, compensating controls, remediation sequencing, and retesting criteria.

IMRI offers top-tier benefits that include: medical coverage through nationally recognized carriers, ancillary coverages, paid vacation and sick leave in compliance with all state and local laws, 401(k) with company match, company paid life insurance and LTD, and several additional voluntary coverages.

Pay will be commensurate with the experience, skills, and qualifications that the candidate brings to the position.

Equal Employment Opportunity Statement

IMRI is an Equal Employment Opportunity employer. IMRI prohibits unlawful discrimination and harassment and provides equal employment opportunity to all applicants and employees consistent with applicable federal, state, and local laws. Employment decisions are based on qualifications, merit, business needs, and other lawful job-related factors without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by law. As a federal contractor, IMRI complies with Section 503 of the Rehabilitation Act and VEVRAA and takes affirmative action with respect to qualified individuals with disabilities and protected veterans as required by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Part-Time Sr. Penetration Tester
Part-Time Sr. Penetration Tester

Information Management Resources, Inc. • New York (NY), Northern (KY)

On-site
USD 30,000 - 54,000
Medical coverage
Ancillary coverages
Paid vacation and sick leave
+4
OT Security Penetration Tester — Part-Time, Hybrid/Onsite
OT Security Penetration Tester — Part-Time, Hybrid/Onsite

Information Management Resources, Inc. • New York (NY), Northern (KY)

Hybrid
USD 124,000 - 193,000
Medical coverage
401(k) with company match
Paid vacation and sick leave
+1
Hybrid Part-Time Senior Penetration Tester
Hybrid Part-Time Senior Penetration Tester

Information Management Resources, Inc. • New York (NY), Northern (KY)

Hybrid
USD 30,000 - 54,000
Medical coverage
Ancillary coverages
Paid vacation and sick leave
+4
Senior Operational Technology (OT) Cybersecurity Engineer
Senior Operational Technology (OT) Cybersecurity Engineer

MITRE • Bedford (MA)

On-site
USD 129,000 - 194,000
Operational Technology (OT) Security Analyst / ICS Penetration Tester
Operational Technology (OT) Security Analyst / ICS Penetration Tester

IPSecure • Chicago (IL)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+10
Junior Offensive Cyber Security Specialist
Junior Offensive Cyber Security Specialist

Kids for the Future • Tampa (FL)

On-site
USD 70,000 - 100,000
Operational Technology Cyber Threat Intelligence, Lead
Operational Technology Cyber Threat Intelligence, Lead

MITRE • McLean (VA)

On-site
USD 159,000 - 238,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

IMRI • Long Beach (CA)

On-site
USD 120,000 - 170,000
Medical coverage
401(k) with company match
Paid vacation and sick leave
+2
Penetration Tester
Penetration Tester

Ochtec • Washington

On-site
USD 120,000 - 160,000
PTO & Holidays
Medical Insurance
401(k)
Penetration Testing Lead
Penetration Testing Lead

Ochtec • Washington

On-site
USD 180,000 - 240,000
Paid time off and Holidays
Medical, Dental, Vision Insurance
401(k)
+1