Fortinet OT Security Engineer

India
Full Time
Experienced
Fortinet OT Security Engineer
Zappsec Technologies Inc.
 
About the role
Zappsec secures operational technology environments for clients in manufacturing, energy, utilities, and process industries. OT means the control systems that run physical processes, as distinct from corporate IT.
You will segment plant networks with Fortinet, build policy from observed industrial traffic, and give clients visibility into assets they currently cannot see. You will do it without stopping production.
This is a hands-on engineering role. Availability comes first in these environments. You will monitor before you block and alert before you enforce.
Certification requirement
Fortinet certification at NSE 5 level or above is mandatory for this role. This is a hard requirement, not a preference.
Fortinet has renamed its program twice in recent years, so read this before you rule yourself out.
  • Certifications issued between October 2023 and July 2026 used the FCP, FCSS, and FCX names. FCP covered the NSE 4 to NSE 6 band. FCSS mapped to NSE 7. FCX mapped to NSE 8.
  • Fortinet returned to NSE 1 through NSE 8 numbering in July 2026.
  • If your certification sits at NSE 5 or higher under either naming, you meet the requirement.
What you will own
Segmentation and architecture
  • Map the client estate against the Purdue model and agree the zone and conduit design under IEC 62443.
  • Design and build the industrial demilitarised zone between the plant network and corporate IT.
  • Place FortiGate at cell and area boundaries, including ruggedised models on the plant floor.
  • Use transparent mode and virtual domains where the client cannot accept routing changes.
  • Segment legacy assets that cannot be patched, upgraded, or taken offline.
Industrial protocol control
  • Write policy for industrial protocols including Modbus TCP, DNP3, IEC 60870-5-104, IEC 61850, EtherNet/IP, PROFINET, S7comm, BACnet, and OPC UA.
  • Apply the Fortinet industrial security service for protocol-aware application control and intrusion prevention.
  • Use virtual patching to protect assets that cannot take a vendor patch.
  • Baseline real traffic first, then write policy from what the plant actually does rather than from a document.
Asset visibility
  • Deploy FortiNAC for asset discovery, device profiling, and port level enforcement.
  • Build passive discovery using SPAN ports and network taps where active scanning is unsafe.
  • Integrate with OT visibility platforms already in the client estate, such as Nozomi, Claroty, or Dragos.
  • Feed OT telemetry into FortiAnalyzer or FortiSIEM where monitoring is in scope.
Secure remote access
  • Replace shared vendor VPN accounts with identity-based access for maintenance and support staff.
  • Build ZTNA, which stands for Zero Trust Network Access, for engineers and third party vendors.
  • Configure multi-factor authentication and privileged session control, including session recording where the client requires it.
  • Design jump host and broker patterns that satisfy both plant operations and the security team.
Change control and safety
  • Work inside plant change windows and planned maintenance outages, not around them.
  • Complete site safety induction and follow plant rules on the floor. Expect site work during commissioning and cutover.
  • Coordinate directly with control engineers, maintenance teams, and operations leads.
  • Validate that a change had no process impact before you close the window.
Compliance and documentation
  • Document zones, conduits, and data flows to a standard an auditor will accept.
  • Support client obligations under IEC 62443, NERC CIP, or the framework their regulator applies.
  • Produce high level designs, low level designs, runbooks, and as-built records.
  • Run knowledge transfer so plant and IT teams can operate what you built.
Requirements
  • Fortinet certification at NSE 5 level or above, as set out in the certification section.
  • Five or more years in network security with production FortiGate and FortiOS experience.
  • Direct hands-on work inside OT or industrial control system environments, on site rather than from a design document.
  • Working knowledge of the Purdue model and of IEC 62443 zone and conduit principles.
  • Familiarity with industrial protocols and how they behave on a live network.
  • Segmentation experience where availability constraints ruled out the obvious design.
  • Strong fundamentals across routing, switching, VLANs, IPsec, and firewall policy.
  • Ability to write client-facing documentation that does not need an editor to rewrite it.
  • Credibility with control engineers. You can explain a security control in terms of process risk.
Preferred
  • NSE 7 level certification, or the FCSS equivalent in Secure Networking.
  • Fortinet OT security certification, either current or previously held under the retired FCSS OT Security track.
  • ISA or IEC 62443 certification, or GICSP.
  • FortiNAC deployment experience in a production OT environment.
  • Exposure to FortiSIEM, FortiDeceptor, or FortiPAM.
  • Working knowledge of Rockwell, Siemens, or Schneider control platforms.
  • Experience in energy, utilities, mining, water, or discrete and process manufacturing.
Tools you will work with
CategoryTools
PlatformFortiGate, FortiGate Rugged, FortiOS, FortiSwitch Rugged
OT securityFortinet industrial security service, protocol application control, virtual patching
VisibilityFortiNAC, FortiAnalyzer, FortiSIEM, third party OT monitoring platforms
AccessZTNA, FortiClient, FortiAuthenticator, FortiToken, FortiPAM
ManagementFortiManager
AnalysisPacket capture, SPAN and tap collection, protocol analysis

 
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*