bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesAppgateSenior/Staff/Principal SWE - OT Security Engineering

Senior/Staff/Principal SWE - OT Security Engineering

Appgate · New York, United States (Remote) · Remote · Active · Workable

Job facts

FieldValue
CompanyAppgate
TitleSenior/Staff/Principal SWE - OT Security Engineering
Normalized title-
Department / teamOther
LocationNew York, United States
Work modelRemote / Remote
Employment typeFull Time
SalaryUSD 180,000–275,000
Statusactive
ATS providerWorkable
Posted / first seen2026-05-11 / 2026-05-31
Changed / last seen2026-05-31 / 2026-06-19

Related slices

PageWhat it containsOpen
Company jobsActive postings from Appgate.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Workable.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Department jobsActive postings in Other.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyAppgate
Sourceca2fcda2-376a-406a-a735-8d66e91e7d45
ATS providerWorkable

Description

Salary: USD 180,000–275,000 Description About AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate is the only direct routed ZTNA solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards Fortune 500 enterprises worldwide. Learn more at appgate.com. About the Role We're looking for an OT Security Engineer (Senior / Staff / Principal) who will design, build, and evolve the secure remote access capabilities at the heart of AppGate's OT platform. You'll work directly with the CTO and OT Technical Product Manager to take secure remote access for OT from concept to production deployment in real industrial environments electric utilities navigating NERC CIP requirements, manufacturers managing third party vendor access, and defense programs requiring CMMC compliant remote access controls. We are open to candidates at the Senior level (hands on engineer with deep OT remote access experience) and Staff / Principal level (hands on technical leader who can own architecture and mentor as the team scales to 5–7 engineers). Key Responsibilities Your engineering work will directly enable next generation OT capabilities, including: •      Secure Remote Access Platform: Identity bound, MFA protected access, with session brokering, just in time privilege, and policy enforcement designed for industrial environments. •      Protocol Aware Policy Authoring: A Protocol Registry that maps OT protocol names to port and transport defaults, making policy authoring OT aware without changing the underlying enforcement model. •      Evidence and Audit Baseline: Structured access logs capturing user identity, target, session start/end, and outcome forwardable to Splunk, Kinesis, Datadog etc. •      Session Governance: Enforced session recording, keystroke logging, step up authentication, and dual authorization approval workflows for regulated and defense environments. •      Asset Context Ingestion : API based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy ready attributes, without blocking access in the critical path. •      Design and implement backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT safe deployment patterns. •      Build and maintain REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT specific system integrations. •      Apply Zero Trust principles to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments. •      Own features end to end, from architecture through production deployment in real customer environments. •      (Staff / Principal) Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales. Required Qualifications •     Experience: Hands on background building or operating secure remote access systems — VPN, ZTNA, jump servers, privileged access, session brokers, or equivalent. •     OT Domain Knowledge: Direct experience in or with OT / ICS environments — manufacturing, energy, utilities, oil and gas, water, transportation, or defense. •     Technical Fundamentals: •     Strong Java backend experience and systems programming in Go, Rust or a comparable language •     Solid networking (TCP/IP, TLS, firewalls) and identity (SAML, OIDC, PKI) fundamentals •     Familiarity with the Purdue Model and IT/OT DMZ design patterns •     Mindset: High ownership, end to end accountability, comfortable in a small team where you solve problems before they become fires. Preferred Qualifications Experience with OT/SRA/PAM platforms: Claroty, Dragos, Nozomi, Xona, Cyolo, Dispel, SSH PrivX OT, CyberArk, or BeyondTrust Background in safety critical, regulated, or compliance driven environments (Staff / Principal) Track record owning platform architecture and mentoring engineering teams Comfortable and fluent working in Linux environments This is your chance to build the secure access layer that protects the world's most critical industrial systems. If you're a Senior/ Staff/ Principal level engineer with deep OT and secure remote access experience, we want to hear from you. AppGate is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.

Full job record

Job IDd4efc5ddd8b3a6b1c4be5f31ec57936ab77fc7cd
Org IDa69c6489-41d6-4af2-9aca-7303faf40ed3
Source IDca2fcda2-376a-406a-a735-8d66e91e7d45
Board IDca2fcda2-376a-406a-a735-8d66e91e7d45
Providerworkable
Provider Job KeyA7AAC013E0
TitleSenior/Staff/Principal SWE - OT Security Engineering
Normalized Title
Statusactive
Activeyes
Location TextNew York, United States (Remote)
DepartmentOther
Team
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
CityNew York
Salary RawUSD 180,000–275,000
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://apply.workable.com/appgate/jobs/view/A7AAC013E0
Apply URLhttps://apply.workable.com/appgate/j/A7AAC013E0/apply
First Seen At2026-05-31 17:47:51Z
Last Seen At2026-06-19 13:53:20Z
Last Checked At2026-06-19 13:53:20Z
Last Changed At2026-05-31 17:47:51Z
Inactive At
Source Posted At2026-05-11 00:00:00Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=workable/board=appgate/date=2026-06-19/2026-06-19T13-53-19-433Z-fa2f9634b6209dc6c188b128cb10bfb1587f39151112b0bbda0de3b1ab9f0513.json
Event Fields
{
  "content_hash": "73767c621e5e796e6a5a2b9eff62cf99b21f786a9a5032b4a35781ca48ad4e57",
  "source_hash": "abd3a313df863180122abb01bc9472b3c5d295c782b98cecfd50ff9252273c31",
  "last_changed_at": "2026-05-31T17:47:51.132Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "New York, United States (Remote)",
    "city": "New York",
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.95
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-19T13:53:19.980Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York, United States (Remote)",
      "city": "New York",
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.95
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "detail": {
    "type": "Full-time",
    "title": "Senior/Staff/Principal SWE - OT Security Engineering",
    "posted": "2026-05-11",
    "company": "AppGate Cybersecurity, Inc.",
    "applyUrl": "https://apply.workable.com/appgate/j/A7AAC013E0/apply",
    "location": "New York, United States (Remote)",
    "workplace": "remote",
    "department": null,
    "descriptionText": "Salary: USD 180,000–275,000\n\n Description\n\n About AppGate \n\nAppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate is the only direct routed ZTNA solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards Fortune 500 enterprises worldwide. Learn more at appgate.com. \n\n About the Role \n\nWe're looking for an OT Security Engineer (Senior / Staff / Principal) who will design, build, and evolve the secure remote access capabilities at the heart of AppGate's OT platform.\n\nYou'll work directly with the CTO and OT Technical Product Manager to take secure remote access for OT from concept to production deployment in real industrial environments electric utilities navigating NERC CIP requirements, manufacturers managing third party vendor access, and defense programs requiring CMMC compliant remote access controls.\n\nWe are open to candidates at the Senior level (hands on engineer with deep OT remote access experience) and Staff / Principal level (hands on technical leader who can own architecture and mentor as the team scales to 5–7 engineers).\n\n Key Responsibilities \n\nYour engineering work will directly enable next generation OT capabilities, including:\n\n•      Secure Remote Access Platform: Identity bound, MFA protected access, with session brokering, just in time privilege, and policy enforcement designed for industrial environments.\n\n•      Protocol Aware Policy Authoring: A Protocol Registry that maps OT protocol names to port and transport defaults, making policy authoring OT aware without changing the underlying enforcement model.\n\n•      Evidence and Audit Baseline: Structured access logs capturing user identity, target, session start/end, and outcome forwardable to Splunk, Kinesis, Datadog etc.  \n\n•      Session Governance: Enforced session recording, keystroke logging, step up authentication, and dual authorization approval workflows for regulated and defense environments.\n\n•      Asset Context Ingestion : API based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy ready attributes, without blocking access in the critical path.\n\n•      Design and implement backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT safe deployment patterns.\n\n•      Build and maintain REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT specific system integrations.\n\n•      Apply Zero Trust principles to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments.\n\n•      Own features end to end, from architecture through production deployment in real customer environments.\n\n•      (Staff / Principal) Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.\n\n Required Qualifications \n\n•     Experience: Hands on background building or operating secure remote access systems — VPN, ZTNA, jump servers, privileged access, session brokers, or equivalent.\n\n•     OT Domain Knowledge: Direct experience in or with OT / ICS environments — manufacturing, energy, utilities, oil and gas, water, transportation, or defense.\n\n•     Technical Fundamentals: \n\n•     Strong Java backend experience and systems programming in Go, Rust or a comparable language\n\n•     Solid networking (TCP/IP, TLS, firewalls) and identity (SAML, OIDC, PKI) fundamentals\n\n•     Familiarity with the Purdue Model and IT/OT DMZ design patterns\n\n•     Mindset: High ownership, end to end accountability, comfortable in a small team where you solve problems before they become fires.\n\n Preferred Qualifications \n\n Experience with OT/SRA/PAM platforms: Claroty, Dragos, Nozomi, Xona, Cyolo, Dispel, SSH PrivX OT, CyberArk, or BeyondTrust\n Background in safety critical, regulated, or compliance driven environments\n (Staff / Principal) Track record owning platform architecture and mentoring engineering teams\n Comfortable and fluent working in Linux environments\n\nThis is your chance to build the secure access layer that protects the world's most critical industrial systems.\n\nIf you're a Senior/ Staff/ Principal level engineer with deep OT and secure remote access experience, we want to hear from you.\n\n AppGate is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator."
  },
  "list_job": {
    "id": "A7AAC013E0",
    "type": "Full-time",
    "title": "Senior/Staff/Principal SWE - OT Security Engineering",
    "posted": "2026-05-11",
    "salary": "USD 180,000–275,000",
    "location": "New York, United States (Remote)",
    "detailUrl": "https://apply.workable.com/appgate/jobs/view/A7AAC013E0.md",
    "department": "Other"
  },
  "detail_meta": {
    "url": "https://apply.workable.com/appgate/jobs/view/A7AAC013E0.md",
    "http_status": 200,
    "content_type": "text/markdown; charset=utf-8",
    "response_bytes": 5588
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/d4efc5ddd8b3a6b1c4be5f31ec57936ab77fc7cd?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/a69c6489-41d6-4af2-9aca-7303faf40ed3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/ca2fcda2-376a-406a-a735-8d66e91e7d45JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/d4efc5ddd8b3a6b1c4be5f31ec57936ab77fc7cd/eventsJSON