OT career guidance
How to describe OT cybersecurity experience on your resume
A hiring manager needs to understand what you've done in an operating environment. A list of tools or standards rarely answers that question. Explain the work you owned, the people you worked with and the constraints that shaped your decisions.
This guide helps OT security engineers, architects, consultants and leaders make that experience easier to assess. It can also help someone moving from controls engineering or IT security identify which parts of their background are relevant.
Give the reader enough context to understand the work
Describe the type of environment before the technical detail. A manufacturing plant, electric utility and building automation environment can involve different systems, responsibilities and access restrictions. Name the sector and system types when you're allowed to share them. You don't need to identify a confidential client or disclose network diagrams.
Useful context includes whether you supported a live production site or a lab, how closely you worked with operations, and whether your responsibility covered one site or several. Distinguish design work from implementation and ongoing support.
Separate your contribution from the team's result
Words such as “supported,” “implemented,” “designed” and “approved” describe different responsibilities. Choose the verb that matches your part. If you contributed to a larger program, explain what you delivered and who made the final decision.
An example of useful detail
Too little context: Responsible for OT network security and firewalls.
More useful: Reviewed industrial firewall rules with plant engineering, documented required communications and prepared a staged rule change for an approved maintenance window. Tested the rollback procedure with the site team before implementation.
This is a fictional example, not a template to copy as your own experience. Its value is the connection between the technical task and the operating conditions.
Explain how operating constraints affected the decision
NIST's Guide to Operational Technology Security addresses OT's performance, reliability and safety requirements. In a resume or interview, show what those considerations meant in your work.
For example, did a production schedule change your rollout plan? Did a vendor dependency affect the patching approach? Who needed to approve a containment action? Describe a decision you actually made rather than adding “safety” or “uptime” to a skills list.
Connect technologies and standards to a task
Include recognizable technology names where they're relevant, but explain what you did with them. Configuring an asset discovery platform, reviewing its findings and owning the inventory process are different experiences. A reader should be able to tell which one you have.
The same applies to standards. If you worked with IEC 62443 or NERC CIP requirements, describe the part of the work you performed. Don't imply that familiarity with a standard makes you responsible for an organization's compliance. Keep certifications separate from practical experience and use their correct names.
Use results you can support
A measured result is useful when you know how it was calculated. Include the scope and time period so someone can interpret it. If you don't have a defensible number, describe the completed work: a reviewed inventory, a tested recovery procedure or an approved segmentation design.
Don't invent percentages or imply that an absence of incidents proves a control was effective. A specific, explainable outcome is more useful than an impressive number you can't substantiate.
Make the practical details easy to find
State your location at the level you're comfortable sharing, the work arrangements you'll consider and your travel availability. A metropolitan area is still useful location information. If you're moving into OT from another discipline, identify your relevant experience and distinguish production work from training or lab practice.
Before sharing your resume, remove client secrets, sensitive site details, credentials and contact information you don't have permission to distribute. You can describe a project clearly without exposing its infrastructure.
Prepare for the conversation your resume starts
For each significant project, be ready to explain the starting problem, your responsibility, a decision you made and what happened afterward. It's reasonable to identify what you would do differently. Employers need enough detail to ask useful follow-up questions.
Our fictional candidate dossier shows one way to organize experience and the questions that still need discussion. To see the other side of that conversation, read our guide to defining an OT cybersecurity role.
