429,851open jobs
14,548companies
65,110added this week
Browse all
Salary
$77k – $170k per year (Estimated)
Location
In office (Wyoming)
Employment
Full-Time
Overview
Company
Impact
Profile match
Gordon Food Service is a foodservice distributor headquartered in Wyoming, Michigan, and founded in 1897. The company supplies food, beverages, equipment, and disposables to restaurants, schools, hospitals, and other institutional kitchens, and also runs its own cash-and-carry store network. It is one of the largest family owned distributors in North America, operating distribution centres across the United States and Canada.

Welcome to Gordon Food Service! We are excited that you are thinking about opportunities with us, and we have an amazing story to share. See below for a quick glance of who we are and the impact you could have on the food service industry. There's a seat at our table for you...

Position Summary:

The Operational Technology Controls and Automation Engineer serves as the key technical lead bridging physical warehouse automation, industrial cybersecurity, and operational execution across the distribution network.

This role is responsible for driving the continuous improvement, stability, and security posture of all on-site Operational Technology (OT) - including Material Handling Equipment (MHE/conveyors/sorters/ASRS), Cold Chain/Refrigeration controls, Building Management Systems (BMS), and facility safety infrastructure.

Functioning as a technical owner and influencer, this role collaborates directly with Divisional DC Maintenance, Enterprise IT/GTS, Security Operations, and external OEM vendors to enforce OT network segmentation, optimize real-time WCS/WES execution logic, and guarantee high availability without compromising floor throughput or physical safety.

What you will do:

OT Security Posture & Network Governance

  • Zero-Trust Floor Architecture & Segmentation: Partners with Enterprise Security to design, deploy, and enforce Layer 7 network segmentation (e.g., Palo Alto / Prisma Access) between OT subnets and enterprise VLANs, protecting OT/ICS environments from enterprise threats without impacting operational continuity.

  • Secure Vendor Remote Access (SASE/ZTNA): Leads the leads the deployment and execution of technical migration from legacy VPNs to modern Zero Trust Network Access (ZTNA) and SASE jump-box portals, establishing strict access governance for third-party automation and refrigeration providers.

  • OT Visibility, Telemetry & NDR: Manages Network Detection and Response and OT visibility platforms (e.g., Armis, Cisco CyberVision, Vectra), maintaining real-time asset inventories and threat detection across cloud and floor environments.

  • Automated Incident Containment ("Red Button"): Operationalizes and executes pre-approved "break-glass" containment playbooks with SecOps to isolate compromised warehouse segments or malicious vendor tunnels at machine speed during cyber threats without causing self-inflicted plant outages.

Network Security Architecture & Enterprise Governance

  • Zero Trust Reference Architectures: Partners with GTS teams to develop and maintain network security design patterns, engineering standards, and implementation roadmaps supporting Zero Trust, SASE, cloud migration, and business objectives.

  • Unified Segmentation Strategy: Partners with other GTS and Security teams and oversees a global segmentation model utilizing Next-Gen Firewalls (NGFWs), micro-segmentation, and cloud-native security controls across cloud, data center, partner networks, and site locations.

  • Cross-Functional Infrastructure Alignment: Partners with Cloud, On-Prem Network, and IAM teams to integrate identity attributes, device posture, and directory services into dynamic access policies across SD-WAN and enterprise transit layers.

  • Infrastructure as Code (IaC) & Policy Automation: Implements IaC and policy-as-code solutions to automatically deploy, validate, and audit network security controls across hybrid environments.

System Health, Resiliency & Disaster Recovery

  • High Availability & Virtual Patching: Establishes edge firewall virtual patching and threat prevention profiles (IPS/App-ID) to mitigate vulnerabilities on legacy PLCs and controllers that cannot accept direct firmware patches.

  • Local HA/DR Verification: Owns point-in-time backup integrity and disaster recovery protocols for PLC ladder logic, SCADA configurations, and local execution databases to satisfy corporate Recovery Point (RPO) and Recovery Time (RTO) objectives.

  • Complex Root-Cause Triage: Serves as senior technical escalation support during complex automation stoppages and cybersecurity incidents, troubleshooting fieldbus communications (Profinet, EtherNet/IP) and network-based threat activity.

Continuous Improvement & Operational Leadership

  • Informal Technical Leadership & Mentorship: Serves as a trusted advisor to Divisional DC Maintenance, Site Leadership, and GTS teams, mentoring technicians and driving network-wide adoption of OT best practices, SOPs, and engineering standards.

  • WCS/WES & Control Logic Optimization: Oversees the integration and real-time execution performance of Warehouse Control Systems (WCS) and Warehouse Execution Systems (WES), ensuring wave-balancing algorithms and routing logic maintain peak case-per-hour throughput.

  • Operational Change Gatekeeper: Controls PLC firmware updates, SCADA updates, and control logic patches, ensuring all updates undergo offline validation in pre-production environments prior to scheduled maintenance windows.

Strategic Technology Modernization

  • Architecture Advisory & Committee Participation: Participates in the Cross-Functional Architecture Group to influence the secure design of enterprise technology initiatives, cloud transit, and data-in-transit encryption standards.

  • Metrics & Roadmap Evaluation: Evaluates emerging network security technologies and defines key security engineering metrics related to network visibility, policy compliance, and Zero Trust maturity.

  • Performs other duties as assigned.

  • Control Platform Standards: Develops and maintains Control Platform Standards that are maintained in the GFS Standards used for existing and new implementations

  • Infrastructure Support: Provides and specifies server OT needs for IT to provide the appropriate solution for the OT application or Control System. This includes supporting provisioning of support contractors and required roles to support GFS systems.

  • Device Approvals and Certification: Collaborate with Enterprise security in review of devices that will exist on GFS networks. This includes hardware devices, software used to control devices, and other OT specific applications and devices.

When you will work:

  • Monday to Friday, 8am to 5pm

What you’ll bring to the table:

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field or equivalent combination of education and experience required.

  • GICSP (Global Industrial Cyber Security Professional), CISSP, ISA/IEC 62443 Cybersecurity Expert, or Palo Alto PCNSA/PCNSE certifications preferred.

  • Deep expertise in Industrial Control Systems (ICS), Programmable Logic Controllers (PLCs - Rockwell/Allen-Bradley, Siemens), HMIs, variable frequency drives (VFDs), and fixed barcode scan tunnels.

  • Advanced knowledge of industrial networking protocols (Profinet, EtherNet/IP, Modbus TCP) and industrial network security frameworks (ISA/IEC 62443, NIST SP 800-82, Purdue Model).

  • Hands-on proficiency with Layer 7 Next-Gen Firewalls (Palo Alto Networks, App-ID, Threat Prevention) and SASE/Zero-Trust Access (Prisma Access).

  • Knowledge of Automated Material Handling Systems (AMHS), AS/RS stacker cranes, robotics, and their operational relationships to cold chain refrigeration and facility utilities.

  • Strong ability to influence without direct authority, build trust with floor maintenance teams, and translate complex technical requirements into actionable site guidance.

  • Strong troubleshooting and analytical skills related to interpreting trend logs, packet captures, and network flow data.

  • Excellent written and verbal communication skills; ability to author procedures, business proposals, and technical incident reports for executive leadership.

  • Strong Electrical / Controls background

  • Strong Industrial control system trouble shooting experience with ability to assist in system trouble events both remotely and on site dispatched if needed.

BE PART OF AN AMAZING CULTURE WHERE WHAT MATTERS TO YOU, MATTERS TO US!

Gordon Food Service values our customers and understands that their success is largely dependent upon their workforce. To demonstrate our commitment to our partnership, we will require any candidate who works for a Gordon Food Service customer to provide a letter of support from their management if they are selected for the interview process.

Equal Employment Opportunity is a matter of policy at Gordon Food Service, Inc. and we are committed to a work environment in which all individuals are treated with respect and dignity.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, status as a protected veteran, or status as a qualified individual with disability. If you require reasonable accommodation for any part of the application or hiring process due to a disability, please submit your request to [email protected] and use the words “Accommodation Request” in your subject line.

All Gordon Food Service locations are tobacco-free.

Gordon Food Service is a drug-free workplace and conducts pre-employment drug tests.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
429,851 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Wyoming
$73k – $165k per year (Estimated) • Remote • Full-Time • 2+ years exp • United States
Python
JavaScript
TypeScript
Node JS
Frontend
Vue.js
GraphQL
Angular
React.js
DevOps
Terraform
GitHub Actions
GitLab CI
CI/CD
Jenkins
AWS
Docker
Kubernetes
AWS Lambda
GitHub
GitLab
IAM
Cybersecurity
Zero Trust
Microsoft Entra ID
Apply
$69k – $178k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Panama
DevOps
Azure
IAM
Cybersecurity
Microsoft Entra ID
Management
ServiceNow
Apply
In office • Full-Time • Bengaluru
Databases
Databricks
DevOps
Terraform
Azure
CI/CD
AWS
Amazon S3
IAM
Apply
$210k – $225k per year • Remote/Hybrid
JavaScript
Node JS
Node JS
Commander.js
AI/ML
AI Agents
LLM
Agentic Workflows
DevOps
Terraform
AWS
Kubernetes
IAM
Cybersecurity
Crowdstrike
Wiz
Defense in Depth
Apply
$22k – $52k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
Java
TypeScript
SQL
C#
Node JS
Bash
Java
Flyway
C#
.NET
Databases
PostgreSQL
DynamoDB
DevOps
Terraform
GitHub Actions
New Relic
Datadog
CI/CD
Git
AWS
Docker
Kubernetes
Opsgenie
JFrog Artifactory
AWS Fargate
AWS Lambda
GitHub
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Cybersecurity
Keycloak
Crowdstrike
SonarQube
Apply
$62k – $137k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • Houston
Apply
Shorts Runner 7 hours ago
$42k per year • In office • Full-Time • Imperial
Apply
$34k per year • In office • Full-Time • 1+ year exp • PhD • Florence
Apply
$33k – $66k per year (Estimated) • In office • Full-Time • Brighton
Marketing
YouTube
Apply
Retail Team Leader 2 days ago
$36k per year • In office • Full-Time • 1+ year exp • High School Diploma • Madison
Apply
$30k – $72k per year (Estimated) • In office • Full-Time • Wyoming
Apply
$28k – $68k per year (Estimated) • In office • Full-Time • Wyoming
Apply
$61k – $131k per year (Estimated) • In office • Full-Time • Wyoming
Apply
$70k – $142k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Wyoming
Management
Google Sheets
Apply
$42k per year • In office • Full-Time • Wyoming
Apply
See all jobs
This is one of many
429,851 more open roles from verified company boards, updated every day.