ICS Platform Engineer
Xander Talent
This is a hands‑on engineering role solving a specific and technically demanding problem: how do you give ICS engineers the flexibility they need to work with legacy plant tooling, vendor‑specific PLC and plant build environments, without creating an uncontrolled path onto operational networks or plant assets?
The answer is a carefully designed platform: a hardened laptop host for modernised sites running strategic tooling natively, and one or more locked‑down VMware Workstation images for untransformed sites where legacy PLC and plant tools still have to run locally. Your job is to design, build, harden and iteratively test both, working side by side with engineers and Security until the platform is something the ICS community will actually use and the assurance team can stand behind.
This is not a ticket‑handling or deployment role. Images and builds will go through multiple test‑and‑fix cycles before they are right. You will hold the tension between engineer usability and security constraints, take findings from each cycle, and produce the next build.
Accountability
- Own the technical lifecycle of the gold laptop image and of the Workstation image set: design, package, lock‑down, test, release, refresh.
- Work side by side with engineering teams to develop and test builds against real engineering workflows.
- Work with domain specialists to package or tune applications and security configurations so tools remain usable and remain inside the agreed envelope.
- Run iterative test cycles with Security so that cyber risk vectors — particularly data transfer between host, VM, removable media and plant LAN — are identified, treated and formally assured.
- Support controlled rollout of new laptops to the ICS engineering community and the subsequent sustainment of images and overlays.
- Define a simple operating model for how engineers obtain updated Workstation images across a range of connectivity scenarios, from centrally managed refresh to site‑level distribution, without weakening the isolation model.
- Document the intended use of host versus image and the constraints engineers must work within, at a level that operations and Security can both live with.
Capabilities and skills
This is a practitioner role. The successful candidate will be comfortable moving between image engineering, application packaging, controlled virtualisation and a security conversation that is specific to ICS environments.
- Desktop and end‑user image engineering: gold images, driver baselines, layered or overlay software for distinct teams.
- VMware Workstation image design, hardening and lifecycle management, specifically building and locking down images for operational use, not server‑side virtualisation.
- Ability to design controls around high‑risk transfer paths, host‑to‑guest, USB and removable media, VM‑to‑plant LAN, without making the platform unusable for engineers who genuinely need those capabilities.
- Practical understanding of ICS and OT engineering tooling and why legacy plant environments cannot simply be replaced on a timetable.
- Working knowledge of enterprise host controls such as web proxy, EDR and VPN, and an understanding of what those controls do and do not cover inside a non‑domain‑joined guest environment.
- Comfort working with Security as a design partner through repeated test‑and‑adjust cycles, not a single gate at the end.
- Clear communication with engineers who need tools to work and with assurance teams who need evidence that risk is bounded.
Reference: WJ-766_22291970