
Closed
Posted
I need an experienced cybersecurity engineer who knows how to secure manufacturing OT environments from the ground up. Our plant floor runs a mix of SCADA, PLC and DCS systems on VMware / ESXi virtual infrastructure, and I’m kicking off a project that tightens every layer—from the hypervisor to the operator workstation—while staying fully aligned with ISA/IEC 62443 and NIST guidelines. Scope of work • Assess the present security posture, map risks to ISA/IEC 62443 zones & conduits, and deliver a concise risk report. • Recommend and implement security improvements that will not disrupt production or existing integrations. • Verify every change through functional testing and validation before sign-off. Core technical tasks • Deploy and tune an endpoint detection & response (EDR) solution across 50 VMs. • Upgrade guest operating systems, apply the latest security patches, and document version baselines. • Configure and optimise an IDS that understands OT protocols. • Perform OS and service hardening following CIS benchmarks. • Secure remote access with a VPN architecture built for least privilege. • Strengthen privileged-access management (PAM) and roll out MFA to operators and maintenance teams. Acceptance criteria 1. EDR agents report healthy status on all 50 VMs. 2. Patch levels meet or exceed vendor recommendations. 3. IDS generates no false positives during a 48-hour production run. 4. Hardening checks pass an independent audit tool. 5. VPN and PAM workflows demonstrate MFA enforcement without downtime. 6. Final validation report confirms compliance to ISA/IEC 62443 relevant sections. If you bring solid OT cybersecurity experience, especially in manufacturing, and can speak fluently about SCADA, PLC and DCS nuances, I’d like to hear how you would approach this engagement and the tools you prefer.
Project ID: 40355283
18 proposals
Remote project
Active 8 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
18 freelancers are bidding on average $39 USD/hour for this job

Hi there, I will secure your manufacturing OT stack (SCADA/PLC/DCS) running on VMware ESXi by aligning controls to ISA/IEC 62443 and NIST; my combined OT and enterprise security experience ensures changes are production-safe and auditable. - Deliverable: full security posture assessment mapping risks to ISA/IEC 62443 zones & conduits plus concise risk report. - Deliverable: deploy and tune EDR across 50 VMs, apply OS patches, document baselines, and harden OS/services to CIS benchmarks. - Deliverable: configure OT-aware IDS, implement VPN least-privilege access, harden PAM and roll out MFA for operators. - Quality control: staged rollout with functional testing, rollback plan, 48-hour validation window and independent-audit-ready documentation. Skills: ✅ Internet Security ✅ VMware ✅ PLC ✅ VPN ✅ IDS/EDR deployment ✅ CIS benchmarks / OS hardening Certificates: ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m available to start immediately. Do you have preferred EDR/IDS vendors and any maintenance windows or change freeze periods I must accommodate? Best regards,
$100 USD in 3 days
6.4
6.4

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
$30 USD in 40 days
6.6
6.6

The professional with 16 years of experience in Industrial Automation. ^^Development,Commissioning of PLC Control System, HMI and SCADA^^ ◾PLC- Siemens [S7-1500F/H, S7-400, S7-400F/H/R, S7-300, S7-1200, S7-200, S5, TI PLC, LOGO!] Rockwell [(Allen Bradley)- SLC500,MicroLogix,CompactLogix.] Schneider [Zelio, M171/72] Automation Direct [DirectLogic Click PLC] Unitronic [V200-18-E3XB Controller] Delta [Delta DVP ES2] Click [C2 series] ◾HMI- Siemens ** Weintek ** Kinco ** Unitronics ** Hitachi ** Schneider ** Wecon ** DeepSeaElectronics** EZ Automation**Maple ◾SCADA - WinCC ** In-Touch Wonderware ** Citect ** Ignition ◾VFD- Siemens, Rockwell-AB, ABB, Telemechanique, SEW and Danfoss, Hitachi ◾ Industrial Networks- PPI-MPI ** Profibus ** AS-i ** Profinet ** Ethernet ** Modbus RTU/Modbus TCP ◾ OPC - PC Access ** OPC Scout ** OPCUA ** Metrikon ** Kepware ◾ Project Documentation- ISA88/95, GAMP, 21CFR Part11, VP, URS, FRS, DS, IQ, OQ, PQ, SOP. ◾ Programming Languages - C# ** VBA ** VB.net ** Javascript ** Python ◾ Arduino Uno ** RS485 ** Ethernet shield ** Data Logging ◾Raspberry pi ** Raspi Camera ? Networking Devices - Siemens ** Teltonika ◾OT Cybersecurity ? NIS2 Compliance **NO OFFSITE COMMUNICATIONS**
$38 USD in 40 days
4.5
4.5

Having worked extensively in industrial automation, including on projects involving SCADA, PLC, and DCS systems -- which are central to your manufacturing environment -- I understand the unique nuances and demands of such infrastructure. My expertise with Siemens TIA Portal and Simatic Manager, and my ability to write system software accordingly aligns perfectly with the requirement to secure your virtual infrastructure comprising VMware / ESXi. In addition to deploying and tuning endpoint detection & response (EDR) solutions across VMs, upgrading guest operating systems, and managing security patches, I have consistently adhered to industry guidelines like CIS benchmarks while hardening operating systems and services. Enforcing a secure remote access mechanism via VPN architecture is also part of my repertoire, which further extends to strengthening privileged-access management (PAM) and multifactor authentication (MFA). To assure a smooth transition of cybersecurity measures without disrupting your production or existing integrations, I emphasize functional testing and validation. Critical to implementing these transformative security changes would be a comprehensive assessment of your present security posture for which my experience mapping risks to ISA/IEC 62443 zones & conduits will be invaluable. With my capacity for attention-to-detail, all the acceptance criteria you've outlined will be thoroughly met and documented.
$38 USD in 40 days
4.2
4.2

With over a decade of experience in industrial cybersecurity and high-security systems, I understand your need for an experienced cybersecurity engineer to secure your manufacturing OT environments to the highest standards. Your project goal of tightening every layer of security while aligning with ISA/IEC 62443 and NIST guidelines aligns perfectly with my background in scaling high-security FinTech systems and deploying secure solutions for sensitive environments. For your project, a strategic high-level tip would be to implement a layered security approach, combining network segmentation, endpoint protection, and access control measures to create a robust defense system. I have successfully implemented similar strategies in the past, such as securing Telegram Mini Apps serving over 1 million users, proving my ability to handle complex security challenges at scale. I encourage you to take action and discuss how we can tackle your cybersecurity project together. Please feel free to reach out to me to discuss the roadmap and how we can ensure the success of your project within the allocated budget and timeframe.
$40 USD in 15 days
3.7
3.7

Hi, how are you doing? I have considerable experience securing OT environments in manufacturing, with hands-on work across SCADA, PLC, and DCS setups on VMware/ESXi. I’ve deployed end-to-end hardening, EDR on multiple hosts, OS patch baselines, OT-aware IDS tuning, CIS-compliant hardening, VPN with least-privilege access, and PAM with MFA rollout. I can draft a concise risk report, implement changes with minimal production impact, and validate through targeted testing. I can demo prior OT security work if needed; let me know the details to align on approach and tools.
$50 USD in 5 days
0.8
0.8

Hello, I am interested in your project, Industrial OT Cybersecurity Engineer. I've successfully completed projects involving Computer Security, Cisco, VMware before. Happy to discuss the details whenever works for you.
$25 USD in 7 days
0.0
0.0

Hi there! You are securing a manufacturing OT environment and the real challenge is hardening each layer—from hypervisor to operator workstation—without disrupting production, which is where many OT projects face delays. I recently led an OT cybersecurity project for a mid-size plant running SCADA and VMware, deploying EDR across 40+ VMs, hardening systems per CIS benchmarks, and achieving full ISA/IEC 62443 compliance while keeping production fully online. My expertise with SCADA, PLC, and VMware ensures both security and operational continuity. I will assess your current posture, implement endpoint protection, IDS tuning, OS hardening, VPN and PAM workflows, and validate all changes against ISA/IEC 62443 and NIST standards with zero downtime. Check our work: https://www.freelancer.com/u/ayesha86664 Do you already have preferred EDR and IDS tools, or should I recommend options optimized for OT environments? I am ready to start — just say the word. Best Regards, Ayesha
$35 USD in 40 days
0.0
0.0

I'd be delighted to help with your industrial OT cybersecurity project. With 15 years of experience in software engineering and a focus on practical solutions, I'm confident in my ability to secure your manufacturing OT environment while ensuring seamless production. I understand the importance of aligning with ISA/IEC 62443 and NIST guidelines, and I've worked with similar projects in the past. My approach would involve a thorough risk assessment, recommending and implementing security improvements that minimize disruption, and verifying each change through thorough testing and validation. Some of the technical tasks I'd focus on include deploying an EDR solution, upgrading guest operating systems, configuring an IDS that understands OT protocols, and securing remote access with a VPN architecture. I'd also work on hardening OS and services, implementing PAM, and rolling out MFA to operators and maintenance teams. My experience in working with various systems, including SCADA, PLC, and DCS, would be a significant asset in this project. I'd be happy to discuss my approach and preferred tools in more detail, ensuring that your project meets the acceptance criteria and adheres to the relevant ISA/IEC 62443 sections. Please feel free to initiate a conversation, and I'll be happy to answer any questions you may have.
$50 USD in 5 days
0.0
0.0

Hi there, I saw your post and it’s exactly what I’ve been doing for the last 8 years. I’m a Network Engineer and I’ve spent a lot of time maintaining WAN environments for large companies, making sure everything stays up and running without surprises. I totally get your point about documentation and change control. In my experience, a network only works well if you keep track of every single change, update, and patch. I’m the kind of guy who prefers to prevent a problem through proactive monitoring and firmware updates rather than fixing a crash in the middle of the night. Here’s a quick summary of what I can bring to your team: Stability: I’ve managed multi-site networks (Cisco, Aruba, HPE) where uptime was the #1 priority. No "surprises": I’m very disciplined with change logs and weekly status reports. You’ll always know what was touched and why. Proactive: I keep an eye on bandwidth and latency to catch issues before the users even feel them. I'm comfortable with VPNs, routing, and keeping production environments secure. If you're looking for someone reliable who takes documentation seriously and just gets the job done, we should talk. Let me know if you have a few minutes to chat about your current setup! Best, [Tu Nombre]
$25 USD in 40 days
0.0
0.0

Hello Brother, I have 6+ years of experience in cybersecurity with strong focus on OT and manufacturing environments, including SCADA, PLC, and DCS systems running on VMware ESXi. I follow ISA/IEC 62443, NIST SP 800-82, and CIS benchmarks to assess and secure plant networks. My approach starts with zone and conduit mapping, risk identification, and building a prioritized remediation plan aligned to production safety. I implement controls with zero disruption by validating each change in staging and production-safe windows. This includes EDR deployment across VMs, OS patching and baseline tracking, OT-aware IDS tuning, system hardening, and secure remote access using least privilege VPN. I also strengthen PAM and enforce MFA across operator and maintenance workflows. I validate all changes through functional testing and audit tools to meet acceptance criteria, including zero false positives and full compliance reporting. I can clearly explain OT-specific risks and controls and bring proven tools like CrowdStrike, Claroty, and Tenable.ot. Please reach out to discuss further. Thank you Venkatesan
$38 USD in 40 days
0.0
0.0

Drawing from my multifaceted background in technology, I am excited to take on this role as your Industrial OT Cybersecurity Engineer. Over the past five years, I have amassed extensive hands-on experience in various aspects of engineering that intersect perfectly with your project requirements. My fluency in languages of both hardware and software makes me uniquely positioned to tackle the intricacies of SCADA, PLC, and DCS systems while aligning them closely with ISA/IEC 62443 and NIST guidelines. In today's interconnected world, protecting critical infrastructure is more important than ever. My proficiency in employing VPN architectures for least privilege access management and rolling out multi-factor authentication (MFA) will provide you with the peace of mind you need to protect against cyber threats. Moreover, I am well-versed with VMware / ESXi virtual infrastructure, making me a suitable candidate for deploying and tuning an endpoint detection & response (EDR) solution across your 50 VMs while ensuring uninterrupted production. Ultimately, I understand the paramount importance of functional testing, validation, and robust documentation in securing OT environments without disrupting operations. This approach aligns perfectly with your scope of work and will ensure acceptance criteria such as healthy EDR agents across all VMs and adherence to vendor recommended patch levels are met and exceeded.
$38 USD in 40 days
0.0
0.0

I am a Certified Siemens Industrial Cybersecurity SOP Expert with practical experience in ICS Penetration Testing and assessing/protecting industrial control systems.
$35 USD in 40 days
0.0
0.0

I am an OT cybersecurity engineer with experience securing SCADA, PLC, and DCS environments on VMware/ESXi infrastructure. I specialize in implementing ISA/IEC 62443 and NIST-aligned security without disrupting production. I will: Assess your OT environment and map risks to 62443 zones/conduits Deploy and tune EDR across 50 VMs Apply OS patching and CIS-based hardening Configure OT-aware IDS with minimal false positives Secure remote access using VPN + MFA with least privilege Implement PAM for operators and engineers All changes will be tested in a controlled manner to ensure zero production downtime, followed by a validation report confirming compliance and system stability.
$25 USD in 40 days
0.0
0.0

I’m an experienced OT cybersecurity engineer with a strong track record in securing manufacturing environments from the ground up. I have hands-on expertise with SCADA, PLC, and DCS systems running on virtualized infrastructures like VMware/ESXi, and I fully understand the need to balance security with uninterrupted operations. I can assess your current environment, map risks to ISA/IEC 62443 zones and conduits, and implement practical, non-disruptive security enhancements. My approach includes EDR deployment, IDS tuning for OT protocols, system hardening based on CIS benchmarks, and securing remote access with VPN, PAM, and MFA. I ensure all changes are validated in real conditions, with full documentation and compliance alignment.
$35 USD in 40 days
0.0
0.0

This is exactly the kind of OT security engagement I handle—balancing strict security with zero production disruption. I’ve worked on SCADA/PLC/DCS environments on VMware/ESXi, aligning controls with ISA/IEC 62443 and NIST while maintaining operational continuity. Approach: • Assess current state → map zones/conduits → risk report with prioritized fixes • Phased hardening to avoid downtime (test → validate → deploy) • Implement EDR across all VMs with health monitoring • Patch + baseline OS versions with rollback strategy • Deploy OT-aware IDS (low false positives, protocol-aware tuning) • Enforce CIS hardening, secure VPN (least privilege), and PAM + MFA rollout Key focus: • No disruption to production systems • OT-safe configurations (protocol sensitivity, legacy constraints) • Audit-ready documentation and validation Deliverables: • Risk + compliance report (ISA/IEC 62443 aligned) • Hardened, monitored environment • Final validation + audit-ready documentation I take a practical, plant-safe approach to OT security. Ready to discuss tools, timeline, and phased rollout.
$38 USD in 40 days
0.0
0.0

Al Mansurah, Egypt
Member since Mar 4, 2026
$250-750 USD
£18-36 GBP / hour
$25-50 USD / hour
$15-25 USD / hour
₹37500-75000 INR
£20-250 GBP
$3000-5000 USD
£20-250 GBP
$500-2000 USD
$30-50 USD / hour
$30-250 AUD
$250-750 USD
₹150000-250000 INR
$25-50 USD / hour
$30-250 USD
$250-750 USD
$10-30 CAD
$250-750 USD
₹1500-12500 INR
$3000-5000 USD