Full-Time

OT Security Penetration Tester

Updated on 8/23/2026

Packetlabs

Packetlabs

1-10 employees

Expert penetration testing and security assessments

No salary listed

Texas, USA + 1 more

More locations: Florida, USA

Remote

Bachelor's

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
Penetration Testing

Get referred to Packetlabs

See people who can refer or advise you

Requirements
  • The candidate must be located in Texas or Florida.
  • The candidate must be a graduate of an Information Security or Computer Science degree program.
  • Professional qualifications such as GICSP, GRID, GCIP, CSSA, CACE, CISSP, or OSCP are preferred.
  • The candidate must have at least 3 years of experience assessing or operating within Operational Technology, Industrial Control Systems, or SCADA environments.
  • The candidate must understand the operational constraints that make OT testing distinct from IT testing.
  • The candidate must communicate risk clearly to technical and non-technical audiences.
  • The candidate must demonstrate continuous learning in a rapidly evolving field.
  • The candidate must have strong analytical and problem-solving skills and be able to work independently in unfamiliar or highly specialized environments.
Responsibilities
  • Perform holistic tabletop reviews covering technical and non-technical risk across OT environments without engaging in high-risk manual or automated activity.
  • Analyze sensitive, legacy networks for negative impact, high risk, and single points of failure.
  • Apply structured judgment to identify concentrated risk and missing controls.
  • Adapt review depth and approach to each client environment's operational realities.
  • Identify vulnerabilities and weaknesses across OT environments, including Industrial Control Systems, SCADA, and field devices.
  • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk.
  • Distinguish theoretical risk from operationally relevant risk so findings remain actionable.
  • Prove impact where appropriate while exercising restraint when the environment requires it.
  • Support OT clients with security program improvements and identify critical controls.
  • Refine testing scope collaboratively as engagements proceed and the environment becomes clearer.
  • Translate technical findings into actionable guidance for technical and leadership audiences.
  • Build client confidence through credibility, clear communication, and operational awareness.
  • Contribute to the maturity of Packetlabs' OT testing methodology and practice.
  • Stay current on OT threats, attack techniques, and defensive controls.
  • Share knowledge with the broader team to minimize blind spots and strengthen collective capability.
  • Help raise the standard of OT security work across the firm.
Desired Qualifications
  • GICSP, GRID, GCIP, CSSA, CACE, CISSP, or OSCP professional qualifications.

Packetlabs provides IT consulting focused on expert penetration testing for organizations across government, technology, media, retail, healthcare, and finance. It conducts hands-on assessments including infrastructure, web and mobile application testing, social engineering, red team exercises, source-code reviews, and exploit development to simulate attacker techniques and identify weaknesses. It differentiates itself through outside-the-box thinking, ongoing learning, and a broad suite of services that goes beyond standard vulnerability scans. Its goal is to strengthen clients' security posture by delivering actionable findings and tailored remediation guidance that go beyond a basic VA scan.

Company Size

1-10

Company Stage

N/A

Total Funding

N/A

Headquarters

Mississauga, Canada

Founded

2011

Get referred to Packetlabs

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Packetlabs updated its site in July 2026, signaling active marketing and service expansion.
  • Its 2026 content targets Canada, Australia, healthcare, and critical-infrastructure buyers.
  • SOC 2 renewal in December 2025 strengthens trust with government and financial clients.

What critics are saying

  • NetSPI, Intruder, and Prescient launched AI pentesting in 2026, compressing pricing.
  • Manual consulting revenue faces margin pressure as customers demand continuous, automated testing.
  • If AI platforms replace episodic pentests, Packetlabs becomes a niche boutique by 2027.

What makes Packetlabs unique

  • Packetlabs focuses on expert-led penetration testing, not commodity vulnerability scanning.
  • SOC 2 Type II attestation supports regulated clients handling sensitive security data.
  • Its service mix spans infrastructure, web, mobile, social engineering, red team, source-code reviews.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Training Programs

Professional Development Budget

Company News

Decrypt
Mar 13th, 2025
Elon Musk’S X Ddos Accusation Ignores Basics Of Cyber Attacks, Expert Says

Decrypt’s Art, Fashion, and Entertainment Hub. Discover SCENEElon Musk’s claim that the DDoS attack on X (formerly Twitter) originated from Ukraine drew skepticism from cybersecurity experts, who argue that attributing attacks based on IP addresses is unreliable.Attackers frequently use virtual private networks (VPNs) and other methods to obfuscate their origins, making pinpointing a specific geographic source difficult.On Monday, X was the target of a distributed denial-of-service attack that intermittently shut down the popular social media site for users worldwide. The X DDoS attack was linked to Dark Storm Team, a notorious hackivist group known for launching similar large-scale cyber disruptions.Hours after the attack, Musk claimed during an interview with Fox Business that the IP addresses associated with the attack originated in the Ukraine area.Tech-savvy users on X quickly pointed out that IP addresses can be masked or spoofed, making them appear to originate from one region when they actually originate from another.Dear Elon:You can't attribute an attack to any geographic location by IP address alone.See: VPN, location spoofing, etc.Also See: How botnets are controlled remotelyAlso Also See: Ask a cybersecurity person to help you. — MikeTalonNYC (@MikeTalonNYC) March 10, 2025Cybersecurity professionals also cautioned against drawing conclusions based solely on IP address data.“If one were conducting a DDoS attack you wouldn't necessarily see each connection originating from an IP address from a specific nation or netblock,” Scott Renna, Senior Solutions Architect with blockchain security firm Halborn, told Decrypt. “By definition, the attack would have to come from multiple IP addresses.”Renna pointed out that attackers distribute their traffic across numerous locations to avoid detection and mitigation efforts.“From an optics perspective and a blocking and prevention standpoint, it's just not how it's typically done,” he said.While the origins of the X attack remain a mystery, DDoS-as-a-Service websites are popping up to facilitate the launch of large-scale attacks. These websites let customers pay to launch DDoS attacks.There are two main types of DaaS."Stresser" services, which are legitimate tools companies use to test and strengthen their IT infrastructure

Canadian Underwriter
Oct 25th, 2024
Nova Scotia health data at risk due to ineffective cybersecurity: report

The auditor said her office hired Toronto-based independent experts from Packetlabs to run cybersecurity tests between April 2021 and June 2023, which revealed a "pervasive tolerance" for accepting risk and a failure to manage ongoing risks.

The Paypers
Sep 20th, 2022
How To Strike A Balance Between Fraud Mitigation And Customer Experience

Milena Babayev, Ekata, explains how merchants overcome one of the greatest challenges: preventing fraud while providing a seamless customer experience. . . By striking the right balance between security and user experience, merchants can stay one step ahead of the competition. With cybercrime expected to cost the global economy USD 10.5 trillion by 2025, implementing friction to protect your business from fraud, chargebacks, and a wide variety of revenue killing activities is necessary. This is because, while the nature of fraud-related challenges stayed fairly consistent over the past year, the severity that each presents to merchants has increased.

VentureBeat
Jun 21st, 2022
Cyberint Delivers Focus To Cybersecurity Teams

We are excited to bring Transform 2022 back in-person July 19 and virtually July 20 - 28. Join AI and data leaders for insightful talks and exciting networking opportunities. Register today!. Cyberint, a cyber threat intelligence company known for attack surface reconnaissance, has announced a $40 million funding round focused at providing organizations with extensive integrated visibility into their external risk exposure