Dragos is on a relentless mission to defend industrial organizations that provide us with the necessities of modern civilization; running water, functioning electricity, and safe industrial working environments. As the market leader in ICS/OT Cybersecurity, we are dedicated to arming our customers with best-in-class technology, threat intelligence, and services to protect their systems as effectively and efficiently as possible. We’re a remote-first culture with operations in North America, Europe, the Middle East, and APAC. We’re looking for mission-oriented teammates who embody our core values of authenticity, transparency, and trust. Are you ready to make a difference? Come join a mission that can save the world!
About the Role:
Our Professional Services Team is seeking Associate Principal OT Penetration Tester who will provide technical leadership across vulnerability assessments, penetration testing, and adversary emulation activities supporting customer services engagements. You will shape engagement strategy and uncover real‑world attack paths across ICS/OT networks through hands‑on exploitation and deep technical analysis, working closely with customers across critical infrastructure sectors such as oil and gas, electric, water treatment, and manufacturing. You will also translate findings into clear, actionable remediation guidance, influencing detection and platform development. You will mentor team members and be an advisor and representative of Dragos within the broader OT security community.
Responsibilities:
-
Lead customer‑facing professional services engagements centered on industrial penetration testing, acting as the primary technical lead and trusted advisor on high‑impact pen test, purple team, and vulnerability assessment engagements.
- Shape engagement strategy and direction, aligning deep technical execution with customer business objectives to deliver meaningful, risk‑focused security value.
- Set the technical standard for OT penetration testing across the organization by defining methodologies, assessment frameworks, and adversary emulation approaches informed by current threat intelligence.
- Design and execute advanced offensive campaigns that uncover complex attack paths across IT/OT boundaries and within industrial environments.
- Translate field insights into strategic inputs for Dragos R&D, influencing tooling, detection content, and analytics by identifying gaps in customer visibility, response, and prevention.
- Mentor and guide cross‑functional teams while evolving internal playbooks and operational practices, and represent Dragos through executive engagements and industry thought leadership.
Qualifications:
- 5+ years of hands-on cybersecurity experience focused on OT/ICS environments, including vulnerability assessments, penetration testing, and red teaming engagements.
- Deep expertise in OT penetration testing methodologies across white-, gray-, and black-box scenarios, with strong understanding of industrial protocols and control systems.
- Hands-on experience with assessment and penetration testing tools such as Metasploit, NMAP, Kali Linux, Cobalt Strike, Burp Suite Pro, and common LOTL toolsets
- Advanced networking and threat analysis expertise, covering network infrastructure components, traffic analysis, attack paths, exploits, adversary TTPs, and host-based data analysis.
- Strong communication, reporting, and customer-facing skills, with the ability to clearly present technical findings to both technical and non-technical audiences.
- Self-motivated, team-oriented and able to work independently in a remote/distributed environment.
- Willing to travel up to 30% for customer engagements.
Compensation:
- Salary: $150,000
- Competitive Equity Package
- Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE
Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.