Skip to main content
Fervo Energy Company logo

Senior OT Security Analyst

Fervo Energy Company
22 hours ago
Remote
United States

The Senior OT Security Analyst is a hands-on cybersecurity professional responsible for strengthening the security and resilience of Fervo's operational technology environments. The role partners with Operations, OT and controls engineering, project delivery, IT, enterprise cybersecurity, compliance, legal, and third parties to translate OT security program objectives into durable technical controls, operating processes, and defensible evidence.


This analyst evaluates OT architectures and data flows, supports secure commissioning and change management, improves asset and configuration visibility, governs remote and vendor access, develops monitoring and incident-response capabilities, and maintains risk and remediation records. The role applies NIST SP 800-82 Rev. 3 and IEC 62443 concepts and supports NERC CIP governance where applicable, without independently determining regulatory applicability or certifying compliance.

Requirements

 ResponsibilitiesOT Program Governance and Risk

  • Translate program objectives into execution. Develop and maintain practical OT security standards, procedures, control requirements, checklists, and review cadences that can be used by site, engineering, project, and vendor teams.
  • Maintain the OT risk lifecycle. Document risk scenarios, operational consequences, existing safeguards, treatment plans, owners, due dates, exceptions, accepted risks, and closure evidence.
  • Support governance and assurance. Prepare status metrics, decision records, issue escalations, control evidence, and review materials for OT cybersecurity and compliance forums.
  • Support NERC CIP readiness where applicable. Partner with Compliance and accountable business owners on asset scoping, control ownership, recurring evidence, exception management, and audit preparation; avoid unsupported compliance conclusions.

Asset, Vulnerability, and Configuration Management

  • Improve OT asset awareness. Maintain or validate inventories for controllers, RTACs, HMIs, historians, engineering workstations, network devices, security appliances, communications gateways, and supporting services.
  • Assess vulnerabilities in context. Evaluate exposure, exploitability, operational consequence, compensating controls, vendor guidance, and outage requirements rather than relying on CVSS scores alone.
  • Strengthen configuration control. Define secure baselines, configuration backup expectations, account and service reviews, network rule reviews, time synchronization, and change records for critical OT components.
  • Coordinate remediation. Work with asset owners and vendors to plan testing, approvals, maintenance windows, rollback, validation, and closure evidence for patches and other risk treatments.

Monitoring, Incident Response, and Recovery

  • Develop safe OT monitoring coverage. Identify priority log sources and passive network visibility points; support secure collection, normalization, alerting, retention, and documented blind-spot management.
  • Investigate OT security events. Triage anomalies and alerts, correlate technical evidence with operating conditions, preserve records, coordinate escalation, and distinguish cyber activity from equipment or process faults.
  • Advance response readiness. Maintain OT-specific playbooks, contacts, decision paths, communications procedures, evidence handling, and interfaces with enterprise incident response and site emergency processes.
  • Validate recovery capability. Support backup and restoration testing, controller and network configuration recovery, clean rebuild planning, manual or degraded operating procedures, and lessons-learned tracking.

Identity, Remote Access, and Third-Party Security

  • Govern privileged and remote access. Promote individual identities, MFA, brokered access, least privilege, time-bound approval, controlled file transfer, session logging, emergency access, and prompt revocation.
  • Review vendor access and support models. Validate business need, technical reach, approval authority, support windows, monitoring, account ownership, contractual responsibilities, and offboarding.
  • Reduce shared-service risk. Assess OT dependencies on identity, DNS, time, virtualization, cloud, cellular, and IT-managed services and document resilient or degraded-mode options.

Collaboration, Documentation, and Continuous Improvement

  • Serve as a trusted OT security partner. Explain risks in operational terms and help engineering and operations teams choose controls that are proportionate, maintainable, and supportable.
  • Maintain authoritative records. Keep architecture baselines, data-flow records, standards, procedures, exceptions, risk decisions, evidence packages, and remediation status current and reviewable.
  • Build OT security capability. Deliver role-appropriate guidance and exercises for operators, engineers, project teams, service providers, and incident responders.
  • Measure program effectiveness. Track meaningful indicators such as asset coverage, critical logging coverage, remote-access accountability, overdue high-risk actions, backup validation, and exception aging.

Required Qualifications

  • Typically 5 or more years in cybersecurity, controls, industrial networking, or related engineering, including at least 3 years focused on OT/ICS security or closely related operational environments.
  • Working knowledge of SCADA, PLCs or RTACs, HMIs, historians, engineering workstations, industrial communications gateways, firewalls, managed switches, and remote-site communications.
  • Strong understanding of TCP/IP, routing, switching, VLANs, firewalls, VPNs, and common industrial protocols such as DNP3, Modbus TCP, OPC UA, or comparable control-system communications.
  • Demonstrated ability to assess architectures, analyze logs and incidents, manage vulnerabilities, document risk, define controls, and coordinate remediation in environments with uptime and safety constraints.
  • Practical familiarity with NIST SP 800-82 Rev. 3 and IEC 62443 concepts; working knowledge of NERC CIP governance and evidence expectations is required where assigned responsibilities involve applicable assets or processes.
  • Ability to produce clear technical documentation, explain operational consequences to varied audiences, facilitate cross-functional decisions, and escalate material risk constructively.
  • Bachelor's degree in cybersecurity, engineering, computer science, information systems, or a related discipline, or equivalent combination of education and relevant experience.
  • Ability to travel to Fervo sites and participate in approved commissioning, maintenance, incident, or recovery windows as business needs require.

Preferred Qualifications

  • Experience in power generation, geothermal operations, utilities, renewable energy, substations, industrial process control, or other critical infrastructure.
  • Hands-on experience with OT network monitoring, SIEM, secure remote access, privileged access, vulnerability-management, firewall-management, or configuration-backup platforms.
  • Experience supporting greenfield design, commissioning, site acceptance, management of change, and transition from project delivery to sustained operations.
  • Relevant certifications such as GICSP, GRID, CISSP, or equivalent technical and industry credentials.
  • Experience coordinating third-party integrators, OEMs, EPCs, operations vendors, or managed service providers in industrial environments.

LocationFervo Energy has offices in Houston, TX, Golden, CO, Reno, NV, Oakland, CA, and Salt Lake City, UT. This position will be eligible for some hybrid work flexibility, but regular in-office presence in Houston will be required.