Senior/Staff/Principal SWE - OT Security Engineering

AppGate Cybersecurity, Inc.
New York, NY

About AppGate

AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate is the only direct-routed ZTNA solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards Fortune 500 enterprises worldwide. Learn more at appgate.com.

About the Role

We're looking for an OT Security Engineer (Senior / Staff / Principal) who will design, build, and evolve the secure remote access capabilities at the heart of AppGate's OT platform.

 

You'll work directly with the CTO and OT Technical Product Manager to take secure remote access for OT from concept to production deployment in real industrial environments - electric utilities navigating NERC CIP requirements, manufacturers managing third-party vendor access, and defense programs requiring CMMC-compliant remote access controls.

 

We are open to candidates at the Senior level (hands-on engineer with deep OT remote-access experience) and Staff / Principal level (hands on technical leader who can own architecture and mentor as the team scales to 5–7 engineers).

Key Responsibilities

Your engineering work will directly enable next-generation OT capabilities, including:

 

Secure Remote Access Platform: Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments.

Protocol-Aware Policy Authoring: A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model.

Evidence and Audit Baseline: Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements.

Session Governance: Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments.

Asset Context Ingestion (Phase 2+): API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path.

Design and implement backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns.

Build and maintain REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations.

Apply Zero Trust principles to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments.

Integrate with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP.

Own features end-to-end, from architecture through production deployment in real customer environments.

(Staff / Principal) Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.

Required Qualifications

Experience: Hands-on background building or operating secure remote access systems — VPN, ZTNA, jump servers, privileged access, session brokers, or equivalent.

OT Domain Knowledge: Direct experience in or with OT / ICS environments — manufacturing, energy, utilities, oil and gas, water, transportation, or defense.

Technical Fundamentals:

• Strong systems programming in Go, Rust, or a comparable language

• Solid networking (TCP/IP, TLS, firewalls) and identity (SAML, OIDC, PKI) fundamentals

• Familiarity with the Purdue Model and IT/OT DMZ design patterns

• Working knowledge of OT protocols: Modbus, DNP3, OPC-UA, EtherNet/IP

Mindset: High ownership, end-to-end accountability, comfortable in a small team where you solve problems before they become fires.

Preferred Qualifications

• Experience with OT/SRA/PAM platforms: Claroty, Dragos, Nozomi, Xona, Cyolo, Dispel, SSH PrivX OT, CyberArk, or BeyondTrust

• Exposure to IEC 62443, NIST SP 800-82, NERC CIP-005/007, or CMMC

• Background in safety-critical, regulated, or compliance-driven environments

• (Staff / Principal) Track record owning platform architecture and mentoring engineering teams

This is your chance to build the secure access layer that protects the world's most critical industrial systems.

If you're a Senior/ Staff/ Principal -level engineer with deep OT and secure remote access experience, we want to hear from you.

 

AppGate is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.

Posted 2026-05-12

Recommended Jobs

History Teacher - Upper Division

Horace Mann School
New York, NY

Job Summary The Upper Division History Department is seeking a dynamic and experienced history teacher for grades 9-12. The successful candidate must be able to teach Atlantic World History and Uni…

View Details
Posted 2026-05-12

New Store - Produce Team Member (Clerk, Floor Service) - Part Time - Holbrook, NY - Winter 2026

Whole Foods Market
Holbrook, NY

A career at Whole Foods Market is more than just the work you do- it's about your personal growth and creating meaningful change. Our purpose is to nourish people and the planet. That means improving…

View Details
Posted 2026-05-06

Dining Services Associate

Elderwood
Cheektowaga, NY

Salary: $16.00 - $18.31/hr Overview: Dining Service Associate (DSA) team members are responsible for ensuring the health and wellbeing of our residents by being responsible for food and beverage prep…

View Details
Posted 2026-03-30

Demand & Finance Ops Manager

Retrospective Goods LLC
New York, NY

Hi, we’re Speks, a Brooklyn-based product design company creating premium sensory products for teens and adults. We sell globally across wholesale, retail, and DTC, and we’re growing fast. We’re l…

View Details
Posted 2026-05-11

Media Director

Noble People
New York, NY

We are Noble People. A modern creative media agency. We develop original, bold and provocative media ideas for some of the most exciting brands in the world. Media ideas that aren’t media. Media tha…

View Details
Posted 2026-05-07

Receiving Clerk

Jetro / Restaurant Depot
Colonie, NY

Position Title:  Receiving Clerk (aka CRT Clerk) Department:  Receiving Supervisor:  Inventory Controller FLSA:  Non-exempt Position Summary: Works closely with Receiving Manager/Supervis…

View Details
Posted 2026-05-06

SENIOR GROUP DIRECTOR, CLIENT ENGAGEMENT & COMMUNICATION

New York, NY

At Chanel, we are focused on creating an inclusive culture that nurtures personal growth, contributing to collective progress. We believe the uniqueness of each individual increases the diversity, co…

View Details
Posted 2026-04-21

Team OTR Hazmat Company Driver W2 Job in Brooklyn, NY by Silvicom

Silvicom
Brooklyn, NY

Hazmat Company Truck Driver - Brooklyn, NY Join the Silvicom family as a professional CDL A Team driver in Brooklyn. We specialize in hauling hazmat freight nationwide, ensuring our drivers rece…

View Details
Posted 2026-04-30

Lead Treasury Analyst

KeyBank
Buffalo, NY

Location: 127 Public Square, Cleveland Ohio Within the Asset and Liability Management Group in the Corporate Treasury Department, the Lead Treasury ALM Analyst position will report to the Inter…

View Details
Posted 2026-05-11

Middle School Math Teacher

Uncommon Schools
Rochester, NY

Company Description Uncommon Schools is a nonprofit network of high-performing public charter schools dedicated to providing an exceptional K-12 education in economically disadvantaged communities…

View Details
Posted 2026-05-13