Arlington, Virginia, United States Hybrid USD 145,000 - 166,000 Yearly

AECOM is hiring a Technology & Security Consultant

This position involves supporting cybersecurity initiatives within operational technology and industrial control systems environments, including SCADA, PLCs, and industrial networks. Candidates must have an active security clearance and be prepared for occasional travel in support of federal projects.

Responsibilities

  • Conduct cybersecurity evaluations of OT/ICS systems, including SCADA, PLCs, RTUs, HMIs, field devices, and associated network components.
  • Detect system vulnerabilities, assess risk levels, and create practical remediation strategies consistent with industry and federal standards.
  • Assist in deploying and documenting security controls using the Risk Management Framework and recognized cybersecurity standards such as those from NIST.
  • Produce and update key cybersecurity documentation, including System Security Plans, security assessment reports, Plans of Action & Milestones, and compliance records.
  • Work with engineering, network, and project teams to integrate cybersecurity requirements into system design and implementation.
  • Support Authority to Operate processes and maintain continuous compliance monitoring.
  • Perform technical evaluations of system configurations and recommend enhancements to improve resilience and compliance.
  • Deliver clear, accurate, and technically robust written reports for federal clients.
  • Assist with project planning, scheduling, and execution as required.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Engineering, or a related field, plus four years of relevant experience, or equivalent combination of education and experience.
  • Minimum of four years of direct experience in OT/ICS cybersecurity.
  • Proven experience securing SCADA systems, PLCs, and industrial network environments.
  • Familiarity with cybersecurity frameworks and the Risk Management Framework (RMF).
  • U.S. Citizenship is mandatory due to the nature of the work.
  • Experience supporting Department of Defense, Department of Homeland Security, or other federal agencies.
  • Must hold an active Secret or Top-Secret security clearance.

Nice to Have

  • Understanding of cybersecurity and privacy laws, regulations, and compliance standards.
  • Experience conducting security risk assessments and creating remediation strategies.
  • Prior work on federal government projects.
  • Experience preparing and maintaining Authority to Operate documentation.
  • Hands-on experience with vulnerability management, network segmentation, and system hardening in OT settings.
  • Certifications such as Security+, CISSp, CISM, or equivalent are advantageous.
  • Strong capabilities in technical writing, analysis, and governance.

Tech Stack

SCADA, PLC, RTU, HMI, OT/ICS, NIST, Risk Management Framework (RMF), System Security Plans (SSP), Plans of Action & Milestones (POA&M), Authority to Operate (ATO)

Benefits

  • Medical benefits
  • Dental benefits
  • Vision benefits
  • Life insurance
  • AD&D (Accidental Death & Dismemberment) benefits
  • Disability benefits
  • Paid time off
  • Leaves of absence
  • Voluntary benefits
  • Perks
  • Flexible work options
  • Well-being resources
  • Employee assistance program
  • Business travel insurance
  • Service recognition awards
  • Retirement savings plan
  • Employee stock purchase plan

Work Arrangement

hybrid — remote working situation available

Team

Over 50,000 professionals globally, including planners, designers, engineers, scientists, digital innovators, and program and construction managers; reports to the Technology Solutions Group (TSG) team.

  • Driven by a shared mission to deliver a better world
  • Supports professional growth and career development
  • Values respect, collaboration, and community
  • Encourages growth within a broad landscape of opportunities
  • Focuses on innovative, sustainable, and resilient solutions
  • Committed to equal opportunity employment

Additional Information

  • An active security clearance is required to perform in this role.
  • U.S. Citizenship is required.
  • Occasional travel is expected.
  • Relocation assistance is not provided for this position.
  • No sponsorship available for U.S. employment authorization, currently or in the future.
  • Work will involve projects at both local community and global scales.
  • Access to advanced technology and a network of subject matter experts is available.
  • Award-winning training and professional development programs are offered.
  • All applicant information will be handled confidentially in accordance with EEO guidelines.

Sponsorship for U.S. employment authorization is not available now or in the future for this position.

Required Skills
SCADAPLCRTUHMIOT/ICSNISTRisk Management Framework (RMF)System Security Plans (SSP)Plans of Action & Milestones (POA&M)Authority to Operate (ATO) SCADAPLCRTUHMIOT/ICSNISTRisk Management Framework (RMF)System Security Plans (SSP)Plans of Action & Milestones (POA&M)Authority to Operate (ATO)
About company
AECOM
AECOM is the world's trusted infrastructure consulting firm, delivering solutions in water, environment, energy, transportation, and buildings. The company partners with public- and private-sector clients to solve complex challenges and build legacies through advisory, planning, design, engineering, and construction management. A Fortune 500 firm with $16.1 billion revenue in fiscal year 2025.
All jobs at AECOM Visit website
Job Details
Department Information Technology
Category security
Posted 2 months ago