Senior OT ICS Penetration Tester and Red Team Specialist
AtosMahape, Navi Mumbai, Maharashtra, India; Bengaluru or Mumbai (Hybrid)
Atos is seeking an experienced OT/ICS Penetration Tester and Red Team Specialist to conduct controlled security assessments, penetration testing, attack-path analysis and adversary-simulation exercises across industrial and critical-infrastructure environments.
The role focuses on identifying credible attack paths across OT networks, ICS/SCADA systems, engineering workstations, HMIs, historians, remote-access infrastructure, industrial DMZs and IT/OT boundaries. Testing must be formally authorised, risk-assessed and performed using production-safe techniques.
Key Responsibilities
- Plan and execute security assessments across OT and ICS environments spanning Purdue Levels 0–3.
- Assess OT network architecture, segmentation, firewalls, industrial DMZs, jump servers, remote-access solutions and vendor-access paths.
- Evaluate SCADA systems, HMIs, historians, engineering workstations, operator stations and supporting infrastructure.
- Review PLC communication paths and industrial protocols using passive, simulated, laboratory-based or explicitly approved techniques.
- Identify vulnerabilities, insecure configurations, weak authentication, excessive access, unsupported systems and insecure services.
- Assess IT-to-OT and OT-to-IT attack paths, including identity, network and remote-access exposure.
- Design controlled adversary-simulation exercises based on realistic industrial threat scenarios.
- Map attack techniques to MITRE ATT&CK for ICS and MITRE ATT&CK Enterprise.
- Support purple-team exercises and evaluate segmentation, identity controls, monitoring and incident-response procedures.
- Develop assessment plans, rules of engagement, risk assessments, testing boundaries and method-of-procedure documents.
- Define stop conditions, rollback procedures, escalation paths and emergency contacts before testing.
- Coordinate testing with plant operations, OT engineering, safety teams, SOC teams and customer stakeholders.
- Ensure testing does not disrupt process availability, safety systems, deterministic communications or production equipment.
- Prepare technical and executive reports covering scope, methodology, vulnerabilities, attack paths, evidence, impact, risk ratings and remediation recommendations.
- Present findings and facilitate remediation workshops.
Testing of sensitive industrial systems will primarily be conducted through passive assessment, configuration review, laboratory simulation, cyber ranges, digital twins or approved maintenance windows.