Per-MW pricing, regional variance, and cost drivers for owners scoping hyperscale & AI builds.
Salary benchmarks across the 14 mission-critical disciplines.
If you hire the wrong BAS cybersecurity person for a data center, the cost can hit fast. A BAS failure can affect cooling, power support, access control, and alarms, and data center downtime can cost millions of dollars per hour.
If I were hiring for this role, I’d keep the process simple:
A few numbers shape the hiring plan:
What matters most is simple: not every BAS engineer owns security, and not every cybersecurity candidate understands OT risk in a live facility.
Here’s the short version of what I’d look for:
Bottom line: I’d use a tight hiring framework so I can cut rework, protect schedule dates, and lower cyber risk in a live data center.
BAS Cybersecurity Hiring Framework for Data Centers
Before you write the job description, get clear on which role you’re hiring for. That sounds basic, but it’s where a lot of teams go wrong. In BAS staffing for mission-critical work, mixing roles is one of the most expensive mistakes you can make. Each role owns a different part of the system, and the skills don’t move neatly from one to another.
The BAS/BMS Engineer with security scope owns the building automation platform itself. That includes secure BAS setup, access control, password policy, controller hardening, and BACnet/SC. The BAS Integration or Controls Engineer connects BAS with DCIM, EPMS, CMMS, and vendor portals. That role also needs to enforce secure integration patterns such as DMZs, API gateways, and one-way data flows. The OT/ICS Cybersecurity Engineer owns OT security architecture across facility systems, including network segmentation, firewall policy, remote access design, logging, and incident response, with NIST SP 800-82 and ISA/IEC 62443 as the main frameworks.
The facility’s risk profile should shape how deep each role goes. In other words, role depth needs to fit the site type.
Owner-operator enterprise data centers usually need BAS roles that work closely with corporate IT security standards, change management processes, and audit requirements. In that setup, the OT/ICS Cybersecurity Engineer isn’t just running OT on its own island. They need to connect facility OT with the enterprise SOC.
Colocation sites push the risk even higher. One BAS compromise can hit multiple tenants’ critical loads at the same time, which puts major SLA pressure on the operation. In that setting, vendor access control, change isolation, and hard segmentation between tenant networks and facility OT move to the top of the list.
Hyperscale projects change the focus again. At that size, the OT/ICS Cybersecurity Engineer needs to build repeatable security patterns that teams can roll out again and again across many projects and regions. That usually means standardized VLANs, pre-defined firewall rules, and approved vendor access workflows.
A simple way to think about it:
This is where most hiring mistakes happen.
Someone can spend years programming Metasys graphics, tuning PID loops in EcoStruxure, or building Niagara N4 station logic and still have little or no experience designing a VLAN structure, writing firewall policy, or handling a BAS security incident. Those are not the same job.
You can often spot the difference in the resume language. Phrases like "programmed Metasys" or "commissioned EcoStruxure" point to platform operation. Phrases like "designed BAS network segmentation", "implemented BACnet/SC", "defined role-based access control for BAS", "led remediation of BAS cyber vulnerability", or "aligned BAS design to NIST SP 800-82/ISA/IEC 62443" point to actual security ownership.[2][3]
That distinction matters fast in live environments. Tier IV assessments have found default credentials and legacy devices that allowed unauthorized access to critical BMS components within minutes.[4]
Spell out the owned layer in the job description, KPIs, and reporting line. That line of ownership becomes your filter for screening and technical testing.
Once the role is clear, set up a screening process that separates BAS security owners from broader cybersecurity candidates. For live data center BAS roles, that means drawing a clean line between people who owned security decisions and people who mainly worked around general controls.
A simple workflow works well:
This screening step should make one thing clear: who has earned a technical interview.
In OT and BAS security, availability and safety come before confidentiality. That's a big shift from standard IT security. If a candidate can't explain that difference in the context of a live BAS decision, they haven't cleared the minimum bar.
A strong early screen question is: How would you secure a BAS network supporting a live data center without causing downtime?
Good candidates usually go straight to things like maintenance windows, risk-based segmentation, and coordination with commissioning teams. For mission-critical projects, give extra weight to people who talk about operational fallout, such as loss of cooling, broken alarms, disabled schedules, or bad trending data, instead of leaning on broad cyber buzzwords. You're listening for operational judgment, not a polished glossary.
The screening rubric below maps the core skills to the signals you should look for and the minimum passing level.
The gap between someone who owned BAS security work and someone who simply watched it from the sidelines usually shows up in the verbs.
Words like designed, implemented, validated, coordinated, and led suggest ownership. Phrases like supported cybersecurity initiatives or assisted with network security - without saying what was secured or how it was checked - usually point to exposure, not decision-making.
Strong resumes also show work across the full project arc: design, construction, turnover, and operations. If the experience stays stuck at policy or documentation, that's a warning sign.
If a candidate can't clearly explain what they owned, what they decided, and what they verified, they likely observed the work rather than ran it. Look for experience in data centers, hospitals, manufacturing, laboratories, or campus settings where uptime-aware security calls mattered day to day.
Certifications like GICSP, CISSP, and GIAC ICS/OT training are useful signals, but they show study discipline more than delivery. Treat them as supporting evidence, then test for actual project execution through interviews and specific examples.
Vendor credentials such as Metasys, Desigo CC, or Niagara N4 can help as baseline filters for platform fluency. Still, they don't prove security ownership. Use those screens to decide who should move forward into live scenario testing.
A standard interview can show what someone knows. A technical exercise shows how they think when a BAS is live and the room for error is small.
Once screening confirms ownership, use technical scenarios to test how candidates work under uptime, access, and commissioning limits. The point is simple: put them in situations that look like first-week decisions, not classroom trivia.
A 2026 OT/ICS report found that 96% of OT security incidents originated from IT-level compromises, and 60% of organizations experienced incidents in 2025[9]. That should shape how you build these exercises. The risks aren't abstract. They're the same ones teams deal with on active sites.
Use one scenario for each project phase so you can test design, remediation, and operations on their own. These three scenarios cover the full delivery arc and surface different strengths.
Scenario 1 - Securing a BAS network during build-out: Ask the candidate to explain the BAS network and security architecture they would set up for the commissioning phase of a new hyperscale data center, and how they would move that design into a segmented turnover state. This tests how they handle initial architecture, commissioning access controls, and the handoff plan at turnover.
Scenario 2 - Reviewing a flat controls network before turnover: Give the candidate a simplified but flawed architecture diagram: one large BAS VLAN, BAS servers dual-homed into both the BAS and corporate IT networks, a vendor remote access appliance with broad rules, and no DMZ. Then give them 30–40 minutes to spot the risks and lay out concrete remediation steps within tight change windows during active commissioning. You want people who can rank issues, especially as data center commissioning talent by criticality. Chilled water control and power room ventilation should come first. You also want someone who suggests low-disruption segmentation, not a massive redesign that slows the project to a crawl.
Scenario 3 - Correcting exposed vendor remote access in an operating facility: Present a case where a BAS vendor has a permanent VPN tunnel with shared credentials and no MFA. Ask how the candidate would reduce the risk without disrupting critical systems. A strong answer includes replacing shared credentials right away, enforcing time-bound sessions through a locked-down remote access gateway, and using closer monitoring as a compensating control while the new setup is rolled out during defined change windows.
For a configuration critique, provide sanitized but realistic artifacts: a BAS server user and role configuration with shared accounts, a firewall ruleset showing permissive any-to-any rules from corporate IT into the BAS VLAN, and a sample BACnet/IP setup with broadcast traffic crossing subnets. Ask candidates to find at least five high-risk issues and recommend specific fixes. This looks a lot like actual BAS design reviews, site assessments, and turnover audits[1].
Score responses based on risk ranking, implementation order, and outage avoidance - not terminology. For written or whiteboard responses, check whether the candidate links their recommendations to NIST SP 800-82 guidance on defense-in-depth and OT network architecture. For encryption-related questions, strong candidates should connect their recommendations to encryption standards, certificate management, and migration risk, including the security impact of mixed protocol deployments.
The clearest signal isn't fancy vocabulary. It's operational judgment. Candidates who tie every recommendation to uptime, commissioning schedules, and vendor coordination show that they understand what is on the line in a mission-critical setting. A repeatable rubric makes the interview easier to defend as a hiring decision.
Even when role ownership is clear, phase fit still matters. Once a candidate clears the fundamentals test, the next step is simple: match that person to the project phase where they can do the most good.
In early design, hire for architecture decisions. You want someone who has written or shaped basis of design documents, drafted BAS cybersecurity specs, or led OT threat modeling during the design stage. Put extra weight on experience with ISA/IEC 62443 zones and on writing specs that contractors can actually follow without guessing.
Here’s the big test: can the candidate spot a flat, unauthenticated BACnet/IP network on paper and fix it before it gets built?
The right person can. They’ll redesign it with segmented VLANs, BACnet/SC for critical systems, and MFA-enforced remote access. That kind of call, made early, can save a project from expensive rework later.
During construction and turnover, hire for verification. This person needs to work on-site with MEP trades, controls integrators, and commissioning agents to confirm that the installed system matches the design intent.
This is the phase where the rubber meets the road. Account structures get checked. Firewall rules get tested. Remote access settings get confirmed before handoff.
Strong candidates won’t speak in vague terms. They should point to specific field tasks and be fluent in L1–L5 commissioning. They also need to know where cyber checks belong inside functional testing (L4) and integrated systems testing (L5).
After turnover, hire for lifecycle control. The operations-phase hire owns the day-to-day work that keeps risk in check over time:
The clearest sign of a strong operations candidate is a history of owning metrics. That means tracking time to remediate vulnerabilities, privileged account counts, and compliance with access review schedules, then reporting risk status to facility leadership in plain terms.
A candidate who has managed a critical firmware patch in a live 24/7 data center without setting off false alarms or causing downtime is the kind of person worth chasing.
Once you’ve matched talent to the right project phase, the last step is a structured hiring process. Define the role in plain terms, screen for OT basics, test hands-on skills, confirm standards and platform experience, and place the person where they can do the most good for that phase of the project.
In mission-critical facilities, BAS cyber mistakes don’t stay hidden for long. They show up as downtime, rework, and turnover risk. A structured process helps you move with more confidence when qualified OT talent is hard to find.
With the right hire in place, the results are concrete: fewer clashes between IT, facilities, and construction teams; commissioning and handover that stay on schedule; and lower lifecycle risk after turnover. Disciplined BAS cyber hiring does more than fill a seat - it cuts rework, protects uptime, and lowers lifecycle risk.
Focus on the project’s domain and architecture. Bring in a Systems Integration Manager when you need building-wide control, vendor-neutral integration, and OT network segmentation. Bring in a Controls & Automation Engineer when the job hinges on day-to-day reliability and clear sequence-of-operations authorship across a multi-platform setup.
If network governance and remote access security sit at the top of the list, look for an OT Cybersecurity Engineer. iRecruit.co can help scope these needs based on your platform mix and project phase.
Beyond certifications, check how candidates use their skills on the job and how they think through system-level problems. Have them walk you through a PLC control sequence, a Revit MEP model, or a calculation from a past project.
Scenario-based questions work well here. A failed commissioning script or a black-start L5 test can show how someone thinks under pressure, handles load issues, explains technical choices, and works through cross-discipline conflicts without throwing the schedule off track.
Start the search 6 to 12 months before project mobilization. These roles call for specialized expertise across mechanical, electrical, and network layers, so treat them as long-lead hires.
Bring recruiters in early during the design phase so the right people are on board before complex stages like Integrated Systems Testing (IST). If you wait until commissioning, schedule delays and expensive last-minute fixes can hit fast.