Principal Consultant - Cyber/Physical Security
Remote, Remote, US
A WORLD LEADER IN TESTING, INSPECTION & CERTIFICATION SERVICES
Bureau Veritas offers dynamic, exciting employment opportunities with an attractive salary/benefit package and an opportunity to play a vital role with a global organization. If you would enjoy working in a dynamic environment and are looking for an opportunity to become part of a stellar team of professionals, we invite you to apply online today.
Bureau Veritas is an Equal Opportunity Employer, and as such we recruit, hire, train, and promote persons in all job classifications without regard to race, color, religion, sex, national origin, disability, age, marital status, citizen status, sexual orientation, gender identity, genetics, status as a protected veteran, or any other non-job-related characteristics.
This position is responsible to ensure equal opportunity in employment in that all persons are treated equally and on the basis of merit, in decisions regarding selection, placement, promotions, training, work assignments, transfers and other personnel actions.
City: Remote
State: Remote
Role Overview
The Principal Consultant, Cyber-Physical Security serves as the technical practice leadand senior seller-doer responsible for delivering high-quality consulting services whilehelping expand the organization’s cyber-physical security practice across industrialsectors including Oil & Gas, Electric Utilities, and Manufacturing.This role combines deep industrial control systems expertise, consulting management,and practice capability development. The individual will support client acquisition, leadcomplex technical engagements, build internal laboratory environments, establishtechnical delivery standards, work with marketing and sales to maintain servicecollateral and mentor junior consultants.The role acts as the technical authority and delivery arm of the engagements, ensuringtechnical rigor, structured methodologies, and high-quality deliverables while workingclosely with practice leadership to grow services and client relationships.
Key Responsibilities
Technical Practice Leadership
• Serve as the technical authority for cyber-physical security services withinthe practice.
• Define and maintain technical methodologies, architecture frameworks,and delivery standards for client engagements.
• Establish technical quality assurance processes for client deliverables.
• Translate cybersecurity risk findings into engineering-level designimprovements and operational outcomes.
• Maintain structured documentation to be used across engagements.Client Engagement & Business Development
• Act as a trusted technical advisor to industrial clients across sectors oneor more sectors such as Oil & Gas, utilities, and manufacturing.
• Support business development activities including:o Discovery workshopso Solutioning discussions
• Contribute to the development of repeatable Cyber Physical service offerings.
• Support growth of strategic accounts through technical credibility anddelivery excellence.
Technical Delivery Leadership
• Lead complex Cyber Physical security consulting engagements, includingbut not limited to:
o Regulatory Assessments
o Cyber Risk and Capability Assessmentso Product Security Assessments
o Architecture and Control Designo Security Validation and Assurance
o Security Operations Design and Operationalization
• Ensure engagements maintain engineering rigor, operational awareness,and safety considerations.Industrial Control Systems Expertise
• Apply deep understanding of industrial automation and control systemenvironments and architectures, including:
o PLC-based controlo Distributed Control Systems (DCS)
o SCADA systemso Safety Instrumented Systems (SIS)
o Industrial networks and field devices
• Understand and assess security implications of networking services andprotocols
• Evaluate cybersecurity risks within real operational environments andsafety-critical systems.Lab Development & Technical Innovation
• Design and lead development of internal laboratory environments tosupport:o Research and developmento Tool validation and testingo Cyber-physical attack simulationo Client demonstrationso Internal training
• Identify and manage emerging technologies relevant to industrialcybersecurity.Capability Development & Team Mentorship
• Mentor and train junior consultants and engineers.
• Develop structured technical training materials and knowledgerepositories.
• Promote strong engineering discipline, safety awareness, and structuredproblem solving within the team.
• Establish consistent documentation and reporting standards acrossprojects.
Required Experience
• 10+ years of experience in industrial or operational technologyenvironments such as:
o Oil & Gaso Electric Utilities
o Manufacturingo Industrial automation or critical infrastructure
• Of which, Minimum 3 years of consulting-type experience
• Hands-on experience with industrial control systems, buildingmanagement systems or security design and implementation
• Experience delivering complex technical programs in industrialenvironments.
• Familiarity with industrial cybersecurity frameworks and regulatoryenvironments including:
o North American experience in NERC CIP, TSA security directiveso Standards such as ISA/IEC 62443, NIST SP 800-82
• Certifications are not required but may be beneficial:
o ISA/IEC 62443 certificationso GIAC ICS certificationso CISSP
o Industrial automation or vendor certifications
If you are an individual with a disability and you would like us to assist you with searching the Careers Page site for employment opportunities and/or assistance with completing your profile and application, please contact us at 1-888-357-7020 or email us with your request to NorthAmericaTA@bureauveritas.com.
We are happy to assist you and encourage you to consider Bureau Veritas for your next great career opportunity!
If you would like additional information regarding Bureau Veritas' federal obligations in regards to equal employment opportunity, please click the link below:
https://www.dol.gov/agencies/ofccp/posters