How to Hire Veterans for SCADA and OT Security Roles
Hire veterans who are ready for the job
We turn real military records into clear, civilian resumes so your hiring team can see what each veteran actually did.
You have an OT security req open. It has been open a while. The resumes come in two piles.
One pile knows firewalls, SIEM, and endpoint tools. Those people have never stood on a plant floor. The other pile knows the plant floor cold. Those people have never drawn a network diagram.
That split is the whole problem. SCADA and industrial control system security needs someone who speaks both languages. On the open market, that person is rare and expensive. In the veteran pool, that person is a lot more common than most hiring teams think.
This guide covers one role family. The security seat that sits between your IT team and your control system. It does not cover plant operators. It does not cover automation engineers. For those, start with our guide on hiring veterans into water and wastewater utilities. Or the one on hiring veterans for industrial automation and robotics.
Below you get the military backgrounds that map. How to read them on a resume. What to ask in the interview. And what to change in your posting.
Why do strong IT security hires fail on the plant floor?
Most IT security people are trained to protect data first. Keep it secret. Keep it accurate. Keep it available, in that order.
OT flips that order. On a plant floor, availability and safety come first. A process that stops can hurt someone. It can also ruin a batch, trip a unit, or shut down a treatment train serving a city.
So a good IT habit becomes a bad OT habit fast. A few examples of where it breaks:
- You cannot just patch: many vendors only support one tested firmware build. Patching outside that build can void support.
- You cannot just reboot: the window to restart a controller may only come during a planned outage.
- You cannot just scan: an aggressive active scan can knock over an older PLC. That is not a theory. It is a known risk in the field.
- The protocols are old: a lot of control traffic was built for a closed network. Some of it has no real authentication at all.
- The assets live a long time: a controller installed twenty years ago may still be running your process today.
A new hire who does not respect those limits will lose the plant team in week one. After that, they get shut out of every change window and the seat stops producing value. NIST wrote a whole publication about this tension. It is NIST SP 800-82 Revision 3, Guide to Operational Technology (OT) Security, published in September 2023. The whole guide is built on one idea. OT has performance, reliability, and safety needs that standard IT guidance does not cover.
What is the IT and OT convergence gap?
Your control network used to be an island. Now it is not. Remote vendor access, historians, cloud dashboards, and plant data feeds all cross the line.
That created a seam. IT owns one side. Engineering and maintenance own the other. Very often nobody owns the middle.
The two groups also run on different clocks. IT may push changes every two weeks. The plant may take changes once a year. Both teams are right inside their own world. Neither one is staffed to translate.
The person who closes that seam has to do two things at once. Read a packet capture. Then read a piping and instrumentation diagram. Sit in a change board and know which change will trip a unit.
Veterans are unusually good candidates for that seat. In a lot of military units, the network and the machinery sit under one chain of command. The same watch team that ran a plant also ran the monitoring and the comms that fed it. Many of these veterans have already done the translating job because there was nobody else to do it.
Which military backgrounds map to SCADA and OT security roles?
Two very different talent streams feed this role. Hiring teams often look at only one of them. Look at both.
The cyber stream
These are the cyberspace operations and network defense jobs. Army 17C cyber operations specialists and 25D cyber network defenders. Navy CWTs, or cyber warfare technicians. That rating absorbed the old CTN rating in 2023, so older resumes still say CTN. Air Force 1D7X5 cybersecurity. Air Force 1D7X1 information technology systems, renamed from cyber defense operations in 2025. Marine Corps 1721 cyberspace warfare operators.
What they bring: network monitoring, incident handling, log analysis, and hunting. Just as useful, they are used to working inside heavy change control and strict authorization rules. They do not touch a system because they feel like it.
What they usually lack: hands on a real process. That is the part you train.
The control systems stream
Security teams often skip this stream entirely. It is often the better half of the hire. Army 12P prime power production specialists and 91D tactical power generation specialists. Navy ETs, or electronics technicians, plus EMs, GSEs, and the nuclear machinist's mates. Air Force 3E0X2 electrical power production.
What they bring: most of them ran instrumented power or propulsion plants. Sensors, relays, switchgear, alarm panels, and operator screens are not new to them. They know why you do not reboot a running system. Many of them worked under formal tag-out and configuration control, so the discipline is already burned in.
What they usually lack: the security vocabulary. That is also trainable, and it is trainable faster than plant instinct.
- •Network monitoring and traffic analysis
- •Incident handling under pressure
- •Working inside strict authorization rules
- •Log review and reporting habits
- •Often an active clearance
- •Real time on live process equipment
- •Instinct for what must never go down
- •Tag-out and configuration control habits
- •Credibility with your plant team
- •Troubleshooting with the unit still running
The strongest hires often sit somewhere between the two. A cyber veteran who spent a tour supporting a base utility plant. A power production veteran who picked up Security+ before separating. Do not screen for a perfect blend. Screen for one strong half and real curiosity about the other.
How do you read a control systems resume for OT security potential?
The trap is scanning for keywords your ATS was told to find. Some teams search only for SCADA, OT, ICS, and Purdue. They miss much of the control systems stream. Those veterans wrote their resumes in military language.
Read the duties, not the job code. In practice that looks like this.
"Maintained shipboard electronic and monitoring systems. Performed casualty control. Kept configuration records current per tag-out procedures. Trained 6 junior technicians."
Ran networked instrumentation on a live plant. Troubleshot faults without shutting the plant down. Worked a formal change and lockout process daily. Already teaches. That is an OT security analyst in training.
Signals worth flagging on any resume in this pool:
- Named equipment: switchgear, relays, HMIs, sensors, generators, distributed control. Brand names are a bonus, not a must.
- Watch or duty language: anything that shows they held a live plant under their control.
- Formal process words: tag-out, lockout, configuration control, technical manual compliance, quality assurance.
- Any network exposure at all: comms, remote monitoring, data systems, radio, satellite.
- Baseline certs: Security+ is common because military cyber roles often call for it. CCNA and vendor training show up too.
Our guide on how to evaluate a veteran resume walks through the same translation work in more detail. Does the role touch classified sites? Our guide on reading a security clearance on a resume covers what those lines mean.
Which standards should you ask about, and which should you skip?
Ask about the frameworks your site actually answers to. Skip the rest. A candidate who can name every standard but has never worked one is not the hire.
The ones worth a real conversation:
- NIST SP 800-82: the federal guide to securing operational technology. Broad, practical, and free to read. A good baseline question for any candidate.
- ISA and IEC 62443: a series of standards for the security of industrial automation and control systems. It uses ideas like zones and conduits to segment a plant. Ask how they would apply it, not whether they memorized it.
- The Purdue model: a reference architecture that describes plant networks in layers. It is a shared vocabulary more than a rulebook. If a candidate can sketch your plant on it, that is a strong sign.
- NERC CIP: only relevant if you touch the bulk power system. Under the Energy Policy Act of 2005, FERC certified NERC as the Electric Reliability Organization. NERC writes the Critical Infrastructure Protection standards and FERC approves them. You can read more on the FERC cyber and grid security page.
- CISA ICS advisories: ask if they track them. CISA publishes advisories on vulnerabilities in control system products at its industrial control systems hub. A candidate who reads them already thinks in OT terms.
Do not stack the cert wall
Postings that demand CISSP plus GICSP plus a 62443 credential plus named-vendor SCADA years get very few applicants. That candidate exists. That candidate is already employed. Ask what the person holds, then sponsor the gap. Cert prep runs weeks. Your req has been open for months.
What interview questions separate real OT exposure from IT-only experience?
Generic security questions will not sort this pool. You need questions where the OT answer and the IT answer look different.
Five screening questions that actually sort
"Tell me about securing something you were not allowed to reboot."
IT-only answers stall here. OT answers go straight to compensating controls.
"How do you inventory a control network without an active scan?"
Look for passive monitoring, span ports, drawings, and asking the techs.
"The vendor will not support the patched build. Now what?"
Tests whether they can hold risk without breaking the support contract.
"Describe a change process you worked inside. Who signed it?"
Veterans from both streams tend to answer this one very well.
"When does safety outrank security, and what do you do?"
There is a right answer. Safety wins, and you document the accepted risk.
One more thing to watch. Ask a control systems candidate to explain a fault they chased with the plant still running. The story will tell you more about their judgment than any cert on the page.
What should your OT security job posting say?
Most postings for this role are written by an IT team. They read that way, and the control systems half of the pool skips right past them.
Four changes that usually help:
- Describe the environment, not just the tools: say what you run. A water treatment plant reads differently from a refinery or a substation.
- Name duties in plain words: "keep the control network segmented and monitored" beats a list of product names.
- Say what you will train: put it in writing. Tell them if you will teach the security side to a plant person. That one line often widens your applicant pool.
- Be honest about the clearance: if the site needs one, say so and say whether you sponsor.
On clearances: some OT security work at defense sites, national labs, and certain utilities does need one. A veteran who separated with an active clearance can save you real time. The background investigation is already done. Confirm it is still current before you plan around it. Clearances can lapse after separation. Our guide on writing a job description that attracts veterans covers the wording in more depth. Hiring for program security rather than control system security? The facility security officer hiring guide is the better fit.
Where do you find veterans with both halves?
Demand for security talent is not cooling off. The Bureau of Labor Statistics projects information security analyst jobs to grow 29 percent from 2024 to 2034. That is about 16,000 openings a year, on average, over the decade.
You are competing for that talent against everyone. The advantage in the veteran pool is that you can reach people before the open market does. Timing matters more than budget here.
Three practical channels:
- Separating service members: reach them in the months before they leave, not after. A strong control systems veteran does not sit on a job board long. Several firms are already talking to them.
- Veteran talent databases: search by what a person did, not by job code. The Department of Labor VETS employer resources are a good starting map of the public options.
- Your current veteran employees: if you already have veterans in maintenance or IT, ask them. They know who else is looking.
Best Military Resume sits in that first window. It adds over 1,000 new profiles every month. The platform has built 65,000 resumes so far. Many of them wrote up plant work and power production in plain civilian language. Shipboard electronics and cyber duty show up the same way. They did it before they ever posted a resume publicly. You can reach out to access BMR's veteran talent pool and search it directly.
Key Takeaway
You will rarely find a finished OT security analyst. You will find a strong cyber half or a strong plant half. Hire the half that is harder to teach, which is usually plant instinct, and train the rest.
What should you do this week?
Start small. This does not need a formal veteran hiring program to work.
Pull your OT security posting and cut any cert you would waive for the right person. Add one line saying you will train the security side for a candidate with real control systems time. Then run a search that ignores job codes and looks for duties. Power production. Shipboard electronics. Network defense. Prime power. Electrical distribution.
Our related guides go deeper on the roles around this seat. See hiring veterans for energy and utilities roles and power grid and transmission roles. Also see nuclear power operations. Want to turn one good hire into a repeatable motion? The guide on building a cybersecurity veteran hiring pipeline lays out the system.
The OT security seat is hard to fill because the market treats it as one job. It is really two skill sets stapled together. Veterans are one of the few groups that regularly arrive with both stapled already. Go find them before your competitor does.
Ready to look at real candidates? Get access to BMR's veteran talent pool and tell us what the role needs.
Frequently Asked Questions
QWhat is the difference between IT security and OT security?
QWhich military jobs map best to SCADA and OT security roles?
QDo I need to require a GICSP or CISSP for an OT security role?
QHow do I tell if a candidate has real OT exposure?
QWhich standards should an OT security hire know?
QDoes an OT security role need a security clearance?
QWhere can I find veteran candidates for SCADA and OT security roles?
About the Author
Brad Tachi is the CEO and founder of Best Military Resume and a 2025 Military Friendly Vetrepreneur of the Year award recipient for overseas excellence. A former U.S. Navy Diver with over 20 years of combined military, private sector, and federal government experience, Brad brings unparalleled expertise to help veterans and military service members successfully transition to rewarding civilian careers. Having personally navigated the military-to-civilian transition, Brad deeply understands the challenges veterans face and specializes in translating military experience into compelling resumes that capture the attention of civilian employers. Through Best Military Resume, Brad has helped thousands of service members land their dream jobs by providing expert resume writing, career coaching, and job search strategies tailored specifically for the veteran community.
Found this helpful? Share it: