Operational Technology Controls and Automation Engineer

Posted 17 Days Ago
Be an Early Applicant
Wyoming, MI, USA
In-Office
Entry level
Food
The Role
Leads the security, reliability, and modernization of operational technology across warehouse distribution sites. Responsibilities include securing OT networks, implementing segmentation and zero-trust access, managing detection and response platforms, validating PLC and SCADA backups, troubleshooting industrial networks, optimizing WCS/WES execution, governing control-system changes, and developing standards. The role partners with security, IT, maintenance, and vendors while mentoring site teams and supporting automation, refrigeration, building systems, and facility safety infrastructure.
Summary Generated by Built In

Welcome to Gordon Food Service! We are excited that you are thinking about opportunities with us, and we have an amazing story to share. See below for a quick glance of who we are and the impact you could have on the food service industry. There's a seat at our table for you...

Position Summary:

The Operational Technology Controls and Automation Engineer serves as the key technical lead  bridging physical warehouse automation, industrial cybersecurity, and operational execution across the distribution network.

This role is responsible for driving the continuous improvement, stability, and security posture of all on-site Operational Technology (OT) - including Material Handling Equipment (MHE/conveyors/sorters/ASRS), Cold Chain/Refrigeration controls, Building Management Systems (BMS), and facility safety infrastructure.

Functioning as a technical owner and influencer, this role collaborates directly with Divisional DC Maintenance, Enterprise IT/GTS, Security Operations, and external OEM vendors to enforce OT network segmentation, optimize real-time WCS/WES execution logic, and guarantee high availability without compromising floor throughput or physical safety.

What you will do:

OT Security Posture & Network Governance

  • Zero-Trust Floor Architecture & Segmentation: Partners with Enterprise Security to design, deploy, and enforce Layer 7 network segmentation (e.g., Palo Alto / Prisma Access) between OT subnets and enterprise VLANs, protecting OT/ICS environments from enterprise threats without impacting operational continuity.

  • Secure Vendor Remote Access (SASE/ZTNA): Leads the leads the deployment and execution of technical migration from legacy VPNs to modern Zero Trust Network Access (ZTNA) and SASE jump-box portals, establishing strict access governance for third-party automation and refrigeration providers.

  • OT Visibility, Telemetry & NDR: Manages Network Detection and Response and OT visibility platforms (e.g., Armis, Cisco CyberVision, Vectra), maintaining real-time asset inventories and threat detection across cloud and floor environments.

  • Automated Incident Containment ("Red Button"): Operationalizes and executes  pre-approved "break-glass" containment playbooks with SecOps to isolate compromised warehouse segments or malicious vendor tunnels at machine speed during cyber threats without causing self-inflicted plant outages.

Network Security Architecture & Enterprise Governance

  • Zero Trust Reference Architectures: Partners with GTS teams to develop  and maintain network security design patterns, engineering standards, and implementation roadmaps supporting Zero Trust, SASE, cloud migration, and business objectives.

  • Unified Segmentation Strategy: Partners with other GTS and Security teams  and oversees a global segmentation model utilizing Next-Gen Firewalls (NGFWs), micro-segmentation, and cloud-native security controls across cloud, data center, partner networks, and site locations.

  • Cross-Functional Infrastructure Alignment: Partners with Cloud, On-Prem Network, and IAM teams to integrate identity attributes, device posture, and directory services into dynamic access policies across SD-WAN and enterprise transit layers.

  • Infrastructure as Code (IaC) & Policy Automation: Implements IaC and policy-as-code solutions to automatically deploy, validate, and audit network security controls across hybrid environments.

System Health, Resiliency & Disaster Recovery

  • High Availability & Virtual Patching: Establishes edge firewall virtual patching and threat prevention profiles (IPS/App-ID) to mitigate vulnerabilities on legacy PLCs and controllers that cannot accept direct firmware patches.

  • Local HA/DR Verification: Owns point-in-time backup integrity and disaster recovery protocols for PLC ladder logic, SCADA configurations, and local execution databases to satisfy corporate Recovery Point (RPO) and Recovery Time (RTO) objectives.

  • Complex Root-Cause Triage: Serves as senior technical escalation support during complex automation stoppages and cybersecurity incidents, troubleshooting fieldbus communications (Profinet, EtherNet/IP) and network-based threat activity.

Continuous Improvement & Operational Leadership

  • Informal Technical Leadership & Mentorship: Serves as a trusted advisor to Divisional DC Maintenance, Site Leadership, and GTS teams, mentoring technicians and driving network-wide adoption of OT best practices, SOPs, and engineering standards.

  • WCS/WES & Control Logic Optimization: Oversees the integration and real-time execution performance of Warehouse Control Systems (WCS) and Warehouse Execution Systems (WES), ensuring wave-balancing algorithms and routing logic maintain peak case-per-hour throughput.

  • Operational Change Gatekeeper: Controls PLC firmware updates, SCADA updates, and control logic patches, ensuring all updates undergo offline validation in pre-production environments prior to scheduled maintenance windows.

Strategic Technology Modernization

  • Architecture Advisory & Committee Participation: Participates in the Cross-Functional Architecture Group to influence the secure design of enterprise technology initiatives, cloud transit, and data-in-transit encryption standards.

  • Metrics & Roadmap Evaluation: Evaluates emerging network security technologies and defines key security engineering metrics related to network visibility, policy compliance, and Zero Trust maturity.

  • Performs other duties as assigned.

  • Control Platform Standards: Develops and maintains Control Platform Standards that are maintained in the GFS Standards used for existing and new implementations

  • Infrastructure  Support: Provides and specifies server OT needs for IT to provide the appropriate solution for the OT application or Control System.  This includes supporting provisioning of support contractors and required roles to support GFS systems.

  • Device Approvals and Certification:  Collaborate with Enterprise security in review of devices that will exist on GFS networks.  This includes hardware devices, software used to control devices, and other OT specific applications and devices.

When you will work:

  • Monday to Friday, 8am to 5pm

What you’ll bring to the table:

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field or equivalent combination of education and experience required.

  • GICSP (Global Industrial Cyber Security Professional), CISSP, ISA/IEC 62443 Cybersecurity Expert, or Palo Alto PCNSA/PCNSE certifications preferred.

  • Deep expertise in Industrial Control Systems (ICS), Programmable Logic Controllers (PLCs - Rockwell/Allen-Bradley, Siemens), HMIs, variable frequency drives (VFDs), and fixed barcode scan tunnels.

  • Advanced knowledge of industrial networking protocols (Profinet, EtherNet/IP, Modbus TCP) and industrial network security frameworks (ISA/IEC 62443, NIST SP 800-82, Purdue Model).

  • Hands-on proficiency with Layer 7 Next-Gen Firewalls (Palo Alto Networks, App-ID, Threat Prevention) and SASE/Zero-Trust Access (Prisma Access).

  • Knowledge of Automated Material Handling Systems (AMHS), AS/RS stacker cranes, robotics, and their operational relationships to cold chain refrigeration and facility utilities.

  • Strong ability to influence without direct authority, build trust with floor maintenance teams, and translate complex technical requirements into actionable site guidance.

  • Strong troubleshooting and analytical skills related to interpreting trend logs, packet captures, and network flow data.

  • Excellent written and verbal communication skills; ability to author procedures, business proposals, and technical incident reports for executive leadership.

  • Strong Electrical / Controls background 

  • Strong Industrial control system trouble shooting experience with ability to assist in system trouble events both remotely and on site dispatched if needed.

BE PART OF AN AMAZING CULTURE WHERE WHAT MATTERS TO YOU, MATTERS TO US!

Gordon Food Service values our customers and understands that their success is largely dependent upon their workforce. To demonstrate our commitment to our partnership, we will require any candidate who works for a Gordon Food Service customer to provide a letter of support from their management if they are selected for the interview process.

Equal Employment Opportunity is a matter of policy at Gordon Food Service, Inc. and we are committed to a work environment in which all individuals are treated with respect and dignity.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, status as a protected veteran, or status as a qualified individual with disability.  If you require reasonable accommodation for any part of the application or hiring process due to a disability, please submit your request to [email protected] and use the words “Accommodation Request” in your subject line. 

All Gordon Food Service locations are tobacco-free.

Gordon Food Service is a drug-free workplace and conducts pre-employment drug tests.

Skills Required

  • Bachelor’s degree in Information Security, Computer Science, Engineering, Information Technology, or a related field, or equivalent education and experience
  • Deep expertise in ICS, PLCs including Rockwell/Allen-Bradley and Siemens, HMIs, VFDs, and fixed barcode scan tunnels
  • Advanced knowledge of Profinet, EtherNet/IP, Modbus TCP, ISA/IEC 62443, NIST SP 800-82, and the Purdue Model
  • Hands-on proficiency with Palo Alto Networks next-generation firewalls, App-ID, Threat Prevention, SASE, and Prisma Access
  • Knowledge of automated material handling systems, AS/RS stacker cranes, robotics, cold-chain refrigeration, and facility utilities
  • Strong electrical and controls background
  • Industrial control system troubleshooting experience, including remote and on-site support
  • Strong troubleshooting and analytical skills using trend logs, packet captures, and network-flow data
  • Ability to influence without direct authority and translate technical requirements into site guidance
  • Excellent written and verbal communication skills, including technical procedures, proposals, and incident reports
  • GICSP, CISSP, ISA/IEC 62443 Cybersecurity Expert, Palo Alto PCNSA, or PCNSE certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Wyoming, Michigan
20,000 Employees
Year Founded: 1897

What We Do

We’ve grown to become the largest family-operated broadline food service distributor in North America by upholding the same business approach since 1897—being passionately committed to the people we serve. We believe in the power of good food—to bring people together and make moments special. Every product, every order, and every decision we make is inspired by the people on the other side of the plate. We distribute to foodservice operators throughout the Midwest, Northeast, Southeast and Southwest regions of the U.S. and coast to coast in Canada. Our company also operates more than 170 Gordon Food Service Stores, which are open to the public and provide the benefits of restaurant-quality products and friendly, knowledgeable service. Gordon Food Service Stores do not charge a membership fee. Gordon Food Service Stores are the primary supplier for many small foodservice operators, including: restaurants, churches, daycare providers, caterers, event planners, and other small businesses. We offer a broad range of employment opportunities throughout our corporate offices, distribution centers, and retail stores. We have a strong commitment to our employees and foster an environment that promotes internal growth, training, and career development opportunities. Gordon Food Service is an Equal Opportunity Employer and does not discriminate against any person on the basis of age, sex, race, religion, national origin, disability, or veteran status.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Support Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Byron Center, MI, USA
16000 Employees
15-20 Hourly

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
91K-203K Annually

IDeaS Logo IDeaS

Sr Manager Accounting

Software • Analytics • Hospitality
Remote or Hybrid
MI, USA
747 Employees

MetLife Logo MetLife

Site Reliability Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
111K-180K Annually

Similar Companies Hiring

Munchkin, Inc. Thumbnail
Consumer Web • eCommerce • Food • Kids + Family • Design • Manufacturing
Milton, Ontario
325 Employees
Tastewise Thumbnail
Artificial Intelligence • Big Data • Food • Retail • Software • Generative AI • Big Data Analytics
NYC, NYC
120 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account