§What You'll Do
- Build AI-driven systems that discover vulnerabilities in SCADA/ICS environments (PLCs, RTUs, HMIs) and gain access autonomously.
- Reverse engineer proprietary industrial protocols and control system firmware to feed the models that find the next entry point.
- Develop the AI tooling that bridges IT/OT boundaries at scale, not one target at a time, but across entire classes of industrial systems.
- Turn your deep ICS knowledge into training data, heuristics, and system understanding that makes machines as good at finding access as you are.
§Requirements
- Strong experience with SCADA/ICS vulnerability research and exploit development focused on gaining access.
- Familiarity with industrial protocols: Modbus, DNP3, OPC-UA, EtherNet/IP, IEC 61850.
- Experience reverse engineering PLC firmware (Siemens, Allen-Bradley, Schneider, ABB).
- Understanding of OT network architectures, Purdue model segmentation, and IT/OT boundary weaknesses.
- Strong C/C++ or Python skills for tooling and exploit development.
§Nice to Have
- Published CVEs or advisories against ICS/SCADA products.
- Experience with HMI exploitation (WinCC, FactoryTalk, Ignition).
- Familiarity with safety instrumented systems (SIS) and their attack surfaces.
- Experience with ICS-specific fuzzing and protocol analysis tools.
- Experience building with LLMs and AI agents.
- Background in red team operations against critical infrastructure.
§You Are
- Motivated by the challenge of breaking into the systems that run critical infrastructure.
- Clearly interested in stepping away from purely manual research and moving toward the development of AI systems.
- Building something massive matters more to you than comfort, titles, or predictability.
- You want to be early at a company that will change an industry, and you're ready to do what that actually takes.
For Recruiters
Note to recruiting firms: SCADA/ICS vulnerability research focused on gaining access is the core requirement. This role is about finding and exploiting entry points, not effects delivery. Industrial protocol and PLC reversing experience are essential.
Ready?
Apply for SCADA / ICS Exploitation Engineer
Email team@zealotlabs.com with a resume and a paragraph on what you want to build with us.
Apply now