Infrastructure/Networking/Systems Engineer to deploy a secure remote industrial monitoring system
Worldwide
About the work We are building an industrial monitoring system to be installed on offshore vessels and rigs. Each installation is a small edge platform: a hypervisor host running Linux service containers and a Windows analytics VM, pulling PLC data into a VM service. It is deployed and running today (in a lab setup) — but deployment is still manual, the infrastructure-as-code is unproven, and credential handling needs to move to a properly designed rotation model. We have a draft target architecture. We want an experienced engineer to finish it with us, prove it, and make it repeatable across installations. Installations live on customer vessels. Support is remote, links are constrained, and the people on board are not IT specialists. What you'll own: - Review the target architecture with our team, then finish the IaC and prove it. - Take us from manual deployment to proven, repeatable Terraform + Ansible — one codebase, per-site config, no hand edits - Design and build credential rotation protocols. Currently credentials live in a 1Password vault. You will be given a service token with read/write access to vaults. - Network design and hardening: segmentation, default-deny firewalling, TLS/PKI and trust distribution, secure remote access - Work directly with vessel and facility IT departments — prepare and defend the network and firewall requests needed to get an installation approved - Advise us on which industrial cyber security standards and class requirements apply to our installations, identify the gaps, and help assemble what a certification or audit needs - Write the internal specifications and procedures: architecture specs for our engineers, install and recovery procedures for field techs, security documentation for client IT and auditors Required - Experience with zero trust networks e.g: Twingate - Strong hands-on networking: routing, VLANs, segmentation, firewalling, DNS/NTP — and the habit of verifying reachability rather than trusting configuration - Production Terraform and Ansible; Debian-family Linux; Proxmox VE ; containers - Familiarity with industrial/OT security standards (IEC 62443 and related), and the judgment to say what applies to a given installation - Clear written English and the confidence to represent us on a technical call with a client's IT department - Comfortable holding production credentials under NDA Nice to have: - Marine, offshore or rig experience; class society cyber requirements - MQTT or other industrial protocols; PostgreSQL operations; CI/CD; Windows in a mixed fleet
- Not SureHourly
- 3-6 monthsDuration
- ExpertExperience Level
$31.00
-
$60.00
Hourly- Remote Job
- Complex projectProject Type
Skills and Expertise
Activity on this job
- Proposals:10 to 15
- Last viewed by client:8 hours ago
- Hires:1
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- MalaysiaHouston7:53 AM
- $48K total spent27 hires, 5 active
- 1,158 hours
- Mid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by