Description
The Principal Consultant specializing in Operational Technology (OT) Strategy for Industrial Cybersecurity (Senior Managing Consultant – Industrial Cybersecurity) is a senior advisory and technical leadership role responsible for helping OT-centric entities develop secure, resilient, compliant, and operationally sustainable OT environments.
This role combines deep expertise in standards such as NERC Critical Infrastructure Protection (CIP) Reliability Standards, NIST CSF, ISA 62443 and TSA Cybersecurity Directives, industrial control systems, cybersecurity architecture, utility operations, risk management, and regulatory compliance. The Principal Consultant serves as a trusted advisor to executive leadership, compliance organizations, engineering teams, cybersecurity personnel, control-room operations, and field organizations.
The successful candidate will translate regulatory requirements into practical OT strategies, architectures, governance models, implementation roadmaps, and operational controls while balancing resiliency, cybersecurity, reliability, operational safety, technology lifecycle considerations, and business objectives.
The role requires the ability to operate at both strategic and technical levels: from advising executives on multi-year OT modernization and regulatory risk to evaluating system architectures, remote-access solutions, security monitoring capabilities, control-system configurations, and audit evidence.
What You’ll Do
As a Principal Consultant, you will lead strategic OT cybersecurity and regulatory compliance engagements for utility and industrial clients. You will serve as a technical leader, trusted advisor, and subject matter expert while supporting business development, mentoring staff, and helping grow 1898 & Co.'s Operational Technology Strategy and Industrial Cybersecurity practice.
Key responsibilities include, but are not limited to:
Strategy & Compliance Advisory
- Serve as a subject matter expert in NERC CIP Reliability Standards, implementation guidance, regulatory expectations, and industry best practices.
- Advise clients on BES Cyber System categorization, compliance applicability, scoping, and risk management strategies.
- Develop practical compliance programs, governance structures, policies, standards, procedures, and supporting operating models.
- Evaluate compliance gaps and develop risk-based remediation strategies that balance operational, regulatory, cybersecurity, and business considerations.
- Support self-certifications, compliance audits, investigations, mitigation plans, and related compliance monitoring activities.
- Advise organizations on establishing sustainable evidence management and audit readiness programs.
OT & Cybersecurity Strategy
- Develop enterprise-wide OT cybersecurity strategies aligned with operational objectives, cybersecurity risks, and regulatory requirements.
- Create multiyear modernization roadmaps for control systems, substations, generation facilities, EMS/SCADA environments, industrial networks, and supporting security technologies.
- Perform OT cybersecurity assessments, architecture reviews, risk assessments, and maturity evaluations.
- Advise clients on network architecture, segmentation, remote access, authentication, monitoring, vulnerability management, backup and recovery, and secure administration practices.
- Develop target-state OT architectures that appropriately separate enterprise IT, operational technology, vendor access environments, and cybersecurity services.
- Evaluate cybersecurity technologies for compatibility with operational reliability, safety, performance, and lifecycle requirements.
Governance & Program Development
- Design and enhance cybersecurity and compliance governance frameworks, including organizational roles, responsibilities, decision rights, and oversight mechanisms.
- Advise cybersecurity, engineering, operations, and compliance leaders on program maturity, accountability, and performance.
- Develop policies, standards, procedures, control frameworks, RACI matrices, and compliance management processes.
- Establish repeatable processes for regulatory change management and implementation of new requirements.
- Support integration of cybersecurity practices across engineering, operations, compliance, risk management, legal, procurement, and vendor management functions.
Audit & Regulatory Readiness
- Lead mock audits, readiness assessments, evidence reviews, and control validation activities.
- Prepare executives, engineers, operators, cybersecurity personnel, and compliance teams for regulatory audits and interviews.
- Identify control weaknesses, documentation gaps, and operational risks before formal compliance assessments.
- Develop defensible compliance approaches supported by objective evidence and sustainable operational processes.
- Provide guidance on the appropriate application of regulatory requirements, implementation guidance, and industry best practices.
Client & Practice Leadership
- Lead complex consulting engagements involving multiple stakeholders, facilities, technical disciplines, and regulatory requirements.
- Serve as an executive-level advisor for major OT cybersecurity and digital modernization initiatives.
- Facilitate workshops and strategic planning sessions with executive leadership, engineering, operations, cybersecurity, compliance, legal, and audit organizations.
- Develop proposals, scopes of work, implementation strategies, executive presentations, and board-level briefings.
- Mentor consultants and technical professionals across the OT cybersecurity practice.
- Contribute to thought leadership, service development, methodologies, and industry engagement initiatives.
- Monitor emerging cybersecurity threats, industry technologies, operational trends, and regulatory developments affecting critical infrastructure operators.
Preferred Experience & Skills
- Bachelor's degree in engineering, cybersecurity, information technology, computer science, industrial engineering, or a related technical discipline; equivalent industry experience may be considered.
- Professional certifications such as CISSP, GICSP, CISM, CRISC, CISA, ISA/IEC 62443, GIAC, or similar credentials.
- Professional Engineer (PE) license or significant electric utility engineering experience.
- Experience supporting multiple NERC-registered entity types and working across multiple NERC regions.
- Experience interacting directly with NERC and Regional Entities during audits, investigations, self-reports, or mitigation activities.
- Experience implementing OT security monitoring, Security Information and Event Management (SIEM), network monitoring, or threat detection capabilities.
- Experience supporting major OT modernization initiatives, NERC CIP program transformations, mergers and acquisitions, or large-scale network redesign efforts.
- Knowledge of industry frameworks and standards including NIST CSF, NIST SP 800-82, ISA/IEC 62443, DOE C2M2, and related cybersecurity guidance.
- Experience in executive consulting, client development, practice growth, and mentoring senior technical staff.
- Ten or more years of experience in operational technology, industrial control systems, cybersecurity, regulatory compliance, utility operations, engineering, or consulting.
- Seven or more years of direct experience supporting NERC Reliability Standards and NERC CIP compliance programs.
- Demonstrated expertise in NERC CIP compliance, audit readiness, regulatory interpretation, governance development, and compliance program implementation.
- Experience working in utility OT environments, including EMS/SCADA, generation facilities, substations, industrial networks, control systems, or related infrastructure.
- Strong understanding of OT cybersecurity architecture, industrial networking, segmentation, remote access, authentication, monitoring, logging, vulnerability management, and recovery strategies.
- Experience leading complex technical, compliance, or transformation initiatives involving cross-functional stakeholders.
- Strong written, verbal, and presentation skills with the ability to communicate complex technical and regulatory concepts to audiences ranging from executives to technical practitioners.
Critical Competencies
The successful candidate will demonstrate:
- Regulatory judgment: Distinguishes clearly between mandatory NERC requirements, implementation guidance, industry practices, and discretionary security enhancements.
- Operational awareness: Understands that cybersecurity controls must support safe and reliable BES operations without creating unnecessary operational risk.
- Strategic thinking: Connects individual compliance controls to enterprise architecture, lifecycle investments, organizational resilience, and business risk.
- Technical depth: Engages credibly with protection engineers, control system engineers, network engineers, cybersecurity professionals, system operators, and architects.
- Audit defensibility: Designs processes and controls that are not only compliant but also supported by objective and defensible evidence.
- Risk-based decision making: Evaluates regulatory, cybersecurity, operational, safety, financial, and implementation risks in a balanced manner.
- Executive communication: Translates complex regulatory and technical concepts into clear decisions, priorities, and investment recommendations.
- Leadership: Builds consensus across organizations where operational, cybersecurity, engineering, compliance, and business priorities may compete.
Success Measures
Performance in this role will be demonstrated by the ability to assist clients in:
- Reducing material NERC CIP compliance and cybersecurity risk.
- Producing defensible, sustainable, and operationally practical compliance solutions.
- Improving OT cybersecurity maturity and resilience.
- Increasing audit readiness and quality of objective evidence.
- Delivering strategic roadmaps that clients can realistically fund and execute.
- Establishing trusted relationships with executives, engineering teams, operations personnel, cybersecurity organizations, and compliance leaders.
- Leading complex engagements to measurable operational and regulatory outcomes.
Qualifications
- Bachelor's degree in engineering, business or related degree from an accredited program and 13 years of relevant consulting experience.
- Or master's degree, MBA preferred.
- Excellent business acumen with proven success in managing consulting engagements.
- Strong analytical skills with the ability to quickly and efficiently interpret large data sets.
- Ability to uncover customer needs, develop recommendations and deliver them persuasively.
- Expert facilitation, collaboration, organization, and problem-solving skills.
- Strong understanding of financial concepts.
- Excellent planning and analytical skills.
- Must demonstrate excellent oral and written communication skills, strong interpersonal skills, and the ability to clearly and effectively present complex information to all levels of employees, management, and clients.
- This job posting will remain open a minimum of 72 hours and on an ongoing basis until filled.
This job posting will remain open a minimum of 72 hours and on an ongoing basis until filled.
EEO/Disabled/Veterans
Job Engineering
Primary Location US-MO-Kansas City
Other Locations US-NC-Charlotte
Schedule: Full-time
Travel: Yes, 15 % of the Time
About 1898 & Co. 1898 & Co. is a business, technology and security solutions consultancy where experience and foresight come together to unlock lasting advancements. We innovate today to fuel our clients’ future growth, catalyzing insights that drive smarter decisions, improve performance and maximize value. As part of Burns & McDonnell, we draw on more than 120 years of deep and broad experience in complex industries as we envision and enable the future for our clients.
Req ID: 263786
Job Hire Type Experienced #LI-EH #E98 N/A