1. Home
  2. Jobs
  3. United States
  4. Florida
  5. Miami
  6. Cloud Security
  7. Sr. Cybersecurity Engineer (OT & Cloud Infrastructure)
ON

Sr. Cybersecurity Engineer (OT & Cloud Infrastructure)

ON.energy
Posted onFeb 5, 2026
LocationMiami, Florida, United States (On-site)
Employment typeFull-time

ON.energy is building the power infrastructure that makes the AI era possible. As AI demand surges past what the grid and traditional data centers can support, ON.energy provides a new class of power technology proven at gigawatt scale and trusted by the world’s leading cloud and AI companies. Our systems are already deployed across 2.5 GW of hyper-scale campuses, validated by top U.S. national labs, and certified for grid-safe operation by major utilities. With real products in the field, we’re scaling faster than the grid can, transforming power from a bottleneck into a competitive advantage for the companies building the future.

We are looking for a Sr. Cybersecurity Engineer to architect and implement technical security controls for our grid-connected energy portfolio. As we scale our operations, we need a hands-on engineer to secure the entire data lifecycle - from the industrial control systems (OT) at the edge, through the cloud telemetry pipeline, to the corporate dashboards.
This is a builder role. You will be responsible for deploying and managing our core security infrastructure - specifically Wazuh and Authentik - to secure our AWS environments and operational field assets. You will work directly with control systems engineers and DevOps teams to build security into our backbone.

Responsibilities
Cloud & Infrastructure Security
Cloud Architecture: Secure the AWS infrastructure that hosts our energy management platforms. Implement hardening baselines and manage security groups for cloud resources.
SIEM & Observability (Wazuh): Architect a centralized and on-prem SIEM deployment to ingest logs from CloudTrail, VPC Flow Logs, and Linux servers. Configure custom decoders to detect threats across both cloud and on-prem environments.
Infrastructure as Code (IaC): Review and secure Terraform/CloudFormation scripts. Manage security configurations (including Wazuh agents and Authentik outposts) via Ansible or similar automation tools.
IoT/Edge Security: Secure the telemetry pipeline from the edge device (site controller) to the cloud, ensuring encryption (TLS 1.2/1.3) and proper certificate management (PKI) for edge.
Identity & Access Management (IAM)
Unified IAM (Authentik): Architect Authentik as the central Identity Provider (IdP), enforcing MFA and SSO across cloud consoles, internal engineering tools, and Grafana dashboards.
Least Privilege: Engineer granular IAM roles for cloud resources and service accounts, ensuring that automated services have only the permissions necessary to function.
Operational Technology (OT) Security
Network Segmentation: Design and implement IEC 62443-aligned network architectures (Purdue Model), strictly controlling traffic between the IT, Cloud, and OT zones.
Vulnerability & Integrity Monitoring: Deploy Wazuh agents on industrial PCs and HMIs to perform File Integrity Monitoring (FIM) and vulnerability scanning without disrupting critical real-time processes.
Industrial Protocols: Analyze and secure communications (Modbus, DNP3) to ensure integrity between field assets and control centers.

Requirements
5–8 years of technical cybersecurity experience, with a specific blend of Cloud/Linux Engineering and OT/Industrial exposure.
Technical Stack Proficiency:
Wazuh: Deep experience deploying managers/agents, writing custom rules/decoders, and tuning FIM/SCA modules for low-noise environments.
Authentik: Experience configuring Providers (OIDC, SAML), Outposts, and proxying legacy applications.
Cloud Platforms: Proficiency with AWS (GuardDuty, IoT Core, IAM) or Azure (Defender for IoT, Entra ID).
Required Background:
OT Security Experience: Proven experience working with industrial control systems (ICS), SCADA, or utility/energy infrastructure.
AND/OR
Cloud/DevSecOps Experience: Deep expertise in securing Linux-based cloud environments and managing infrastructure via code.
Core Traits:
Hands-on: You are comfortable debugging a failed Wazuh agent on a Linux server or tracing a dropped packet in a cloud VPC.
Open-Source Advocate: You prefer tailoring flexible open-source tools to fit specific architectural needs rather than relying solely on "black box" commercial vendors.
Preferred:
Experience with Docker/Kubernetes security in an edge computing context.
Knowledge of industrial protocols (Modbus TCP, DNP3, IEC 61850).
Certifications: GICSP, GRID, AWS Certified Security – Specialty.

For US-based roles - What you’ll get:

  • Competitive salary + annual performance-based bonus eligibility
  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and company holidays 

For Mexico-based roles - What you’ll get:

  • Competitive salary + annual performance bonus eligibility
  • Christmas Bonus (Aguinaldo): 30 days
  • Major medical expenses and life insurance
  • Paid time off and holidays (per local policy)

For all roles:

  • Professional development and growth opportunities
  • Opportunity to grow with a mission-driven team shaping the future of clean energy
  • Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
  • Accommodations: If you need an accommodation during the application process, email recruitment@onenergystorage.com
  • Benefits vary by role and location and are subject to change.

ON.energy builds hyperscale power systems for AI and critical infrastructure, delivering grid-safe energy storage with 99.9% uptime.

Similar jobs

You might also be interested in...

AL2w

Cybersecurity Platform Engineer

allstate-plumbing

USA - IL (Remote), United States of America or Remote (Illinois, United States)

$85.6k – $152.7k Yearly

WB5d

Cybersecurity Engineer

Warner Bros. Discovery

Atlanta, Georgia, United States (Hybrid)

$91k – $169k Yearly

SO1w

Cyber Security Engineer IV

SOSi

Reston, Virginia, United States (On-site)

BV7h

Cybersecurity Engineer

Bright Vision Technologies

Bridgewater, New Jersey, United States or Remote (United States)

LE1w

Senior Cybersecurity Manager

Leidos

Bedford, Massachusetts, United States (Hybrid)

$131.3k – $237.3k Yearly