New

Senior IT Data Security & OT Risk Engineer

Boulder, Colorado, United States

Who we are:  

We're transforming one of the world’s oldest industries with cutting-edge technology and an innovative approach. Backed by top-tier investors and recognized by Time as one of the "best Inventions of 2024" and Fast Company as one of 2024's "Next Big Things in Tech", Electra is scaling rapidly and we're looking for bold, driven individuals to help us reshape the future of iron production. If you're ready to make a real impact in a company that's redefining heavy industry for a cleaner, smarter world, we want to hear from you.

What you will do:  

The Senior IT Data Security & OT Risk Engineer is a senior-level individual contributor responsible for safeguarding Electra’s information and operational technology assets worldwide. This role leads security engineering initiatives, risk management programs, and compliance adoption across IT and OT environments. 
 
Beyond technical execution, this position also plays a critical role in the development of IT security policies, standards, and guidelines in partnership with leadership. Acting as a subject matter expert, the engineer helps shape Electra’s security strategy, ensuring policies are practical, compliant with international regulations, and aligned with business objectives. 

Responsibilities include:

 

  • Lead the design, implementation, and governance of IT/OT security frameworks across enterprise and industrial systems
  • Collaborate with the Director of IT and leadership team to develop, update, and enforce IT security policies, standards, and procedures
  • Ensure that policies align with NIST CSF 2.0, ISO/IEC 27001, IEC 62443, and global regulatory frameworks (e.g., GDPR, NIS Directive, CCPA)
  • Partner with the Staff Network Administrator to embed policy-driven controls into network segmentation, access, and firewall strategies
  • Conduct risk assessments, threat modeling, and penetration testing, translating findings into updated policy and governance requirements
  • Develop incident response and escalation policies; ensure playbooks are current and aligned with business continuity goals
  • Monitor compliance with policies across global teams; recommend corrective actions when gaps are identified
  • Mentor IT staff on both technical and governance aspects of data security and risk
  • Communicate policy changes and risk posture updates to leadership, ensuring executive alignment and informed decision-making
  • Stay current with emerging threats, regulations, and industry standards; proactively recommend policy adjustments to maintain Electra’s resilience

 

What we need you to bring to the team:   

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field
  • Professional certifications such as CISSP, CISM, CISA, CCSP, or IEC 62443 are strongly preferred
  • 8+ years of experience in IT security with at least 3 years in OT or ICS environments (excluding internships, co-ops, and other school projects)
  • Proven experience developing and implementing security policies, governance frameworks, and risk management strategies in collaboration with IT leadership
  • Expertise in ISO 27001, NIST CSF, IEC 62443, and regulatory compliance requirements, including GDPR, NIS Directive, and SOC 2
  • Strong technical background with hands-on expertise in SIEM, EDR, IAM, DLP, firewalls, IDS/IPS, and cloud security platforms
  • Ability to translate complex risk findings into actionable policies and standards understood by both technical and business stakeholders
  • Excellent communication, collaboration, and influence skills with the ability to work closely with senior leadership and cross-functional teams
  • Applies advanced professional knowledge, business acumen, and company objectives to develop and resolve complex technical and governance challenges
  • Provides creative and effective solutions to highly complex issues requiring in-depth evaluation of multiple variables
  • Directs the application of established security principles while guiding the development of new policies, standards, and practices
  • Understands interrelationships across disciplines and works effectively on complex, cross-functional initiatives
  • Exercises judgment in selecting and adapting methods, techniques, and evaluation criteria to achieve departmental and organizational objectives
  • Builds and maintains networks with key contacts outside of direct expertise and leverages influence across the business
  • Adapts communication style and uses persuasion to deliver messages that align with enterprise-wide security and business goals
  • Frequently advises others on complex cybersecurity and governance matters and may lead teams accountable for delivering tactical business targets

 

What we want you to bring to the team:   

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field
  • 10+ years of experience in IT security with at least 3 years in OT or ICS environments
  • Experience in international manufacturing or energy sectors with multi-country compliance requirements
  • Familiarity with Microsoft security stack, including Sentinel, Defender, Entra, and Purview
  • Exposure to policy-driven OT risk governance and industrial cybersecurity maturity models
  • Ability to work on significant and unique issues requiring evaluation of complex or intangible factors
  • Strong conceptual thinking skills to understand advanced issues and implications in cybersecurity and compliance
  • Exercises independent judgment in determining methods, techniques, and evaluation criteria to achieve results
  • Accountable for results that may impact the entire IT security function and business operations

Compensation:   

  • The anticipated starting pay range for this position is $100,000-$127,000 and may be more or less depending upon skills, experience, and education.  

 

Benefits For You:  

  • 100% paid premiums across all medical, dental, vision, telemedicine, short-term disability, long-term disability, and basic life insurance plans 
  • Reasonable use PTO 
  • $1,800 in annual employer HSA contributions (health savings account) 

Benefits For Your Family:  

  • 100% paid premiums across all medical, dental, vision, and telemedicine plans 
  • 12 weeks of paid parental leave 

Benefits For Your Future:  

  • 401k with up to 5% matching contributions which vest 100% on day one  
  • Eligibility for incentive stock options 

 

If you need an accommodation during the application or interview process, reach out to us at careers@electra.com—we’re here to help.

 

Create a Job Alert

Interested in building your career at Electra? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Electra’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.