August 4, 2026

Cybersecurity for BAS: Hiring Manager Guide

By:
Dallas Bond

If you hire the wrong BAS cybersecurity person for a data center, the cost can hit fast. A BAS failure can affect cooling, power support, access control, and alarms, and data center downtime can cost millions of dollars per hour.

If I were hiring for this role, I’d keep the process simple:

  • Define the role before opening the search
  • Separate BAS platform work from OT security ownership
  • Screen for uptime-first thinking
  • Test candidates with live-site scenarios
  • Match the hire to the project phase: design, turnover, or operations

A few numbers shape the hiring plan:

  • About 225,200 U.S. cybersecurity jobs were unfilled in Q2 2024
  • Around 55% of senior cybersecurity roles take 6 months or more to fill
  • Researchers found 20,000+ exposed DCIM systems tied to HVAC and power
  • One OT/ICS report said 96% of OT incidents started from IT-side compromise

What matters most is simple: not every BAS engineer owns security, and not every cybersecurity candidate understands OT risk in a live facility.

Here’s the short version of what I’d look for:

  • Someone who can explain why uptime and safety come first
  • Someone who has designed or enforced segmentation, remote access control, and account hardening
  • Someone who can rank risk during commissioning and live operations
  • Someone whose experience fits the phase of the project, not just the title on the resume
Hiring focus What I’d check
Role clarity BAS engineer, integration engineer, or OT/ICS security engineer
Resume proof Verbs like designed, implemented, validated, led
Screen questions Segmentation, vendor access, patching without downtime
Technical test Architecture review, written scenario, or config critique
Phase fit Design, construction/turnover, or facility operations

Bottom line: I’d use a tight hiring framework so I can cut rework, protect schedule dates, and lower cyber risk in a live data center.

BAS Cybersecurity Hiring Framework for Data Centers

BAS Cybersecurity Hiring Framework for Data Centers

Webinar: Securing Your Buildings Most Critical Assets

Before you write the job description, get clear on which role you’re hiring for. That sounds basic, but it’s where a lot of teams go wrong. In BAS staffing for mission-critical work, mixing roles is one of the most expensive mistakes you can make. Each role owns a different part of the system, and the skills don’t move neatly from one to another.

The BAS/BMS Engineer with security scope owns the building automation platform itself. That includes secure BAS setup, access control, password policy, controller hardening, and BACnet/SC. The BAS Integration or Controls Engineer connects BAS with DCIM, EPMS, CMMS, and vendor portals. That role also needs to enforce secure integration patterns such as DMZs, API gateways, and one-way data flows. The OT/ICS Cybersecurity Engineer owns OT security architecture across facility systems, including network segmentation, firewall policy, remote access design, logging, and incident response, with NIST SP 800-82 and ISA/IEC 62443 as the main frameworks.

Role Primary Cyber Responsibilities Common Platforms Key Standards
BAS/BMS Engineer (Security Scope) Platform hardening, role-based access, credential management, BAS-side logging, vendor access workflows Metasys, Desigo CC, EcoStruxure Building, Niagara N4 NIST SP 800-82, ISA/IEC 62443, BACnet/SC
BAS Integration/Controls Engineer Secure integrations (EPMS, DCIM, CMMS, cloud), gateway hardening, TLS/OPC UA, integration activity logging Niagara-based integration frameworks, protocol gateways, EPMS/SCADA products NIST SP 800-82, ISA/IEC 62443, BACnet/SC
OT/ICS Cybersecurity Engineer OT security architecture, segmentation, remote access design, SIEM integration, vulnerability management, incident response Firewalls, VPNs, SIEM tools, cross-vendor BAS/ICS systems NIST SP 800-82, ISA/IEC 62443, internal security policies

Map Responsibilities to the Facility Risk Profile

The facility’s risk profile should shape how deep each role goes. In other words, role depth needs to fit the site type.

Owner-operator enterprise data centers usually need BAS roles that work closely with corporate IT security standards, change management processes, and audit requirements. In that setup, the OT/ICS Cybersecurity Engineer isn’t just running OT on its own island. They need to connect facility OT with the enterprise SOC.

Colocation sites push the risk even higher. One BAS compromise can hit multiple tenants’ critical loads at the same time, which puts major SLA pressure on the operation. In that setting, vendor access control, change isolation, and hard segmentation between tenant networks and facility OT move to the top of the list.

Hyperscale projects change the focus again. At that size, the OT/ICS Cybersecurity Engineer needs to build repeatable security patterns that teams can roll out again and again across many projects and regions. That usually means standardized VLANs, pre-defined firewall rules, and approved vendor access workflows.

A simple way to think about it:

  • Owner-operators often get more from BAS Engineers who can work through long-term operational alignment with corporate IT.
  • Colocation and hyperscale programs usually need heavier weighting on the OT/ICS Cybersecurity Engineer role.

Separate BAS Platform Skill from OT Security Ownership

This is where most hiring mistakes happen.

Someone can spend years programming Metasys graphics, tuning PID loops in EcoStruxure, or building Niagara N4 station logic and still have little or no experience designing a VLAN structure, writing firewall policy, or handling a BAS security incident. Those are not the same job.

You can often spot the difference in the resume language. Phrases like "programmed Metasys" or "commissioned EcoStruxure" point to platform operation. Phrases like "designed BAS network segmentation", "implemented BACnet/SC", "defined role-based access control for BAS", "led remediation of BAS cyber vulnerability", or "aligned BAS design to NIST SP 800-82/ISA/IEC 62443" point to actual security ownership.[2][3]

That distinction matters fast in live environments. Tier IV assessments have found default credentials and legacy devices that allowed unauthorized access to critical BMS components within minutes.[4]

Spell out the owned layer in the job description, KPIs, and reporting line. That line of ownership becomes your filter for screening and technical testing.

Build a Screening Process for BAS Cybersecurity Fundamentals

Once the role is clear, set up a screening process that separates BAS security owners from broader cybersecurity candidates. For live data center BAS roles, that means drawing a clean line between people who owned security decisions and people who mainly worked around general controls.

A simple workflow works well:

  • Start with a resume review for direct BAS or OT ownership
  • Follow with a short phone screen centered on safety and uptime thinking
  • Use a structured technical interview to check how the person handles access, segmentation, and remote support during commissioning or live operations

This screening step should make one thing clear: who has earned a technical interview.

In OT and BAS security, availability and safety come before confidentiality. That's a big shift from standard IT security. If a candidate can't explain that difference in the context of a live BAS decision, they haven't cleared the minimum bar.

A strong early screen question is: How would you secure a BAS network supporting a live data center without causing downtime?

Good candidates usually go straight to things like maintenance windows, risk-based segmentation, and coordination with commissioning teams. For mission-critical projects, give extra weight to people who talk about operational fallout, such as loss of cooling, broken alarms, disabled schedules, or bad trending data, instead of leaning on broad cyber buzzwords. You're listening for operational judgment, not a polished glossary.

The screening rubric below maps the core skills to the signals you should look for and the minimum passing level.

Competency Evidence to Look For (Resume/Interview) Minimum Acceptable Depth
IT vs. OT Security Explains uptime priority over confidentiality; references ISA/IEC 62443 vs. standard IT frameworks Must explain how a BAS compromise can disrupt cooling or equipment control
BAS Operational Risk Describes real impacts: loss of HVAC control, disabled alarms, incorrect setpoints, failed startup sequences Can walk through what happens operationally - not just technically - if a BAS server is compromised in a live data center
Zones, Conduits, and Segmentation Mentions Purdue Model, OT DMZ design, VLAN structure, firewall rules between IT and OT Can describe BAS controller separation from the corporate LAN and the OT DMZ [5][8]
Firewalls and DMZs References hardware firewalls, DMZ placement between IT and OT, minimal single-connection design Understands that direct network traffic between corporate IT and BAS is a documented risk per NIST SP 800-82 [7][8]
MFA and Privileged Vendor Access Experience with jump hosts, time-limited vendor credentials, session logging, least-privilege accounts Can explain MFA as part of a larger remote-access model - not just use MFA - including how to handle legacy devices that don't support it [6][8]
Protocol Security Fluency in BACnet/SC, Modbus over secure tunnels, OPC-UA Knows that standard BACnet is unencrypted and requires network-level protection; can explain why that matters for segmentation design
Patch and Lifecycle Management Examples of patch planning during live operations, firmware update coordination Can describe a method for updating controller firmware while maintaining redundant cooling or power continuity

Resume Signals That Point to Real Project Ownership

The gap between someone who owned BAS security work and someone who simply watched it from the sidelines usually shows up in the verbs.

Words like designed, implemented, validated, coordinated, and led suggest ownership. Phrases like supported cybersecurity initiatives or assisted with network security - without saying what was secured or how it was checked - usually point to exposure, not decision-making.

Strong resumes also show work across the full project arc: design, construction, turnover, and operations. If the experience stays stuck at policy or documentation, that's a warning sign.

If a candidate can't clearly explain what they owned, what they decided, and what they verified, they likely observed the work rather than ran it. Look for experience in data centers, hospitals, manufacturing, laboratories, or campus settings where uptime-aware security calls mattered day to day.

Check Credentials Without Overvaluing Acronyms

Certifications like GICSP, CISSP, and GIAC ICS/OT training are useful signals, but they show study discipline more than delivery. Treat them as supporting evidence, then test for actual project execution through interviews and specific examples.

Vendor credentials such as Metasys, Desigo CC, or Niagara N4 can help as baseline filters for platform fluency. Still, they don't prove security ownership. Use those screens to decide who should move forward into live scenario testing.

Run Technical Assessments That Reflect Live BAS Environments

A standard interview can show what someone knows. A technical exercise shows how they think when a BAS is live and the room for error is small.

Once screening confirms ownership, use technical scenarios to test how candidates work under uptime, access, and commissioning limits. The point is simple: put them in situations that look like first-week decisions, not classroom trivia.

A 2026 OT/ICS report found that 96% of OT security incidents originated from IT-level compromises, and 60% of organizations experienced incidents in 2025[9]. That should shape how you build these exercises. The risks aren't abstract. They're the same ones teams deal with on active sites.

Use Scenario-Based Exercises Tied to Data Center Delivery

Use one scenario for each project phase so you can test design, remediation, and operations on their own. These three scenarios cover the full delivery arc and surface different strengths.

Scenario 1 - Securing a BAS network during build-out: Ask the candidate to explain the BAS network and security architecture they would set up for the commissioning phase of a new hyperscale data center, and how they would move that design into a segmented turnover state. This tests how they handle initial architecture, commissioning access controls, and the handoff plan at turnover.

Scenario 2 - Reviewing a flat controls network before turnover: Give the candidate a simplified but flawed architecture diagram: one large BAS VLAN, BAS servers dual-homed into both the BAS and corporate IT networks, a vendor remote access appliance with broad rules, and no DMZ. Then give them 30–40 minutes to spot the risks and lay out concrete remediation steps within tight change windows during active commissioning. You want people who can rank issues, especially as data center commissioning talent by criticality. Chilled water control and power room ventilation should come first. You also want someone who suggests low-disruption segmentation, not a massive redesign that slows the project to a crawl.

Scenario 3 - Correcting exposed vendor remote access in an operating facility: Present a case where a BAS vendor has a permanent VPN tunnel with shared credentials and no MFA. Ask how the candidate would reduce the risk without disrupting critical systems. A strong answer includes replacing shared credentials right away, enforcing time-bound sessions through a locked-down remote access gateway, and using closer monitoring as a compensating control while the new setup is rolled out during defined change windows.

For a configuration critique, provide sanitized but realistic artifacts: a BAS server user and role configuration with shared accounts, a firewall ruleset showing permissive any-to-any rules from corporate IT into the BAS VLAN, and a sample BACnet/IP setup with broadcast traffic crossing subnets. Ask candidates to find at least five high-risk issues and recommend specific fixes. This looks a lot like actual BAS design reviews, site assessments, and turnover audits[1].

Assessment Format Realism Time Required Scoring Consistency Best Use Case
Whiteboard Architecture Review High 45–60 minutes Medium Final-round interviews for roles owning BAS architecture and cross-team alignment
Written Scenario Response Medium–High 30–45 minutes High Standardized screening across multiple candidates; tests judgment under defined constraints
Configuration Critique Very High 45–60 minutes High Technical roles requiring platform-specific hardening (e.g., Niagara N4, Metasys, Desigo CC)

Score Answers Against Standards and Project Constraints

Score responses based on risk ranking, implementation order, and outage avoidance - not terminology. For written or whiteboard responses, check whether the candidate links their recommendations to NIST SP 800-82 guidance on defense-in-depth and OT network architecture. For encryption-related questions, strong candidates should connect their recommendations to encryption standards, certificate management, and migration risk, including the security impact of mixed protocol deployments.

The clearest signal isn't fancy vocabulary. It's operational judgment. Candidates who tie every recommendation to uptime, commissioning schedules, and vendor coordination show that they understand what is on the line in a mission-critical setting. A repeatable rubric makes the interview easier to defend as a hiring decision.

Match BAS Cybersecurity Talent to the Project Delivery Phase

Even when role ownership is clear, phase fit still matters. Once a candidate clears the fundamentals test, the next step is simple: match that person to the project phase where they can do the most good.

Project Phase Primary Cyber Responsibilities Ideal Role Profile Typical Tools & Standards
Design & Preconstruction Secure BAS architecture, OT/IT segmentation, protocol selection, specification language OT Cybersecurity Engineer / Controls Design Manager ISA/IEC 62443, NIST SP 800-82, Purdue Model, BACnet/SC
Construction and Turnover Implementation oversight, account hardening, remote access validation, commissioning verification Systems Integration Manager / Controls CxA BACnet/IP, integrated systems testing, commissioning checklists, L1–L5 commissioning
Operations Vulnerability management, patch baselines, access reviews, change control, incident response BMS/Controls Manager or MEP Director NIST SP 800-82, ISA/IEC 62443, vendor patch procedures and OT change control

Design and Preconstruction: Hire for Architecture and Standards

In early design, hire for architecture decisions. You want someone who has written or shaped basis of design documents, drafted BAS cybersecurity specs, or led OT threat modeling during the design stage. Put extra weight on experience with ISA/IEC 62443 zones and on writing specs that contractors can actually follow without guessing.

Here’s the big test: can the candidate spot a flat, unauthenticated BACnet/IP network on paper and fix it before it gets built?

The right person can. They’ll redesign it with segmented VLANs, BACnet/SC for critical systems, and MFA-enforced remote access. That kind of call, made early, can save a project from expensive rework later.

Construction and Turnover: Hire for Implementation and Verification

During construction and turnover, hire for verification. This person needs to work on-site with MEP trades, controls integrators, and commissioning agents to confirm that the installed system matches the design intent.

This is the phase where the rubber meets the road. Account structures get checked. Firewall rules get tested. Remote access settings get confirmed before handoff.

Strong candidates won’t speak in vague terms. They should point to specific field tasks and be fluent in L1–L5 commissioning. They also need to know where cyber checks belong inside functional testing (L4) and integrated systems testing (L5).

Operations: Hire for Lifecycle Risk Management

After turnover, hire for lifecycle control. The operations-phase hire owns the day-to-day work that keeps risk in check over time:

  • Quarterly access reviews
  • OT-appropriate vulnerability scanning
  • Patch scheduling around maintenance windows
  • Change control for sequence and configuration updates
  • Incident response coordination with corporate security

The clearest sign of a strong operations candidate is a history of owning metrics. That means tracking time to remediate vulnerabilities, privileged account counts, and compliance with access review schedules, then reporting risk status to facility leadership in plain terms.

A candidate who has managed a critical firmware patch in a live 24/7 data center without setting off false alarms or causing downtime is the kind of person worth chasing.

Conclusion: Use a Structured Hiring Framework to Reduce BAS Cyber Risk

Once you’ve matched talent to the right project phase, the last step is a structured hiring process. Define the role in plain terms, screen for OT basics, test hands-on skills, confirm standards and platform experience, and place the person where they can do the most good for that phase of the project.

In mission-critical facilities, BAS cyber mistakes don’t stay hidden for long. They show up as downtime, rework, and turnover risk. A structured process helps you move with more confidence when qualified OT talent is hard to find.

With the right hire in place, the results are concrete: fewer clashes between IT, facilities, and construction teams; commissioning and handover that stay on schedule; and lower lifecycle risk after turnover. Disciplined BAS cyber hiring does more than fill a seat - it cuts rework, protects uptime, and lowers lifecycle risk.

FAQs

How do I know which BAS cybersecurity role I need?

Focus on the project’s domain and architecture. Bring in a Systems Integration Manager when you need building-wide control, vendor-neutral integration, and OT network segmentation. Bring in a Controls & Automation Engineer when the job hinges on day-to-day reliability and clear sequence-of-operations authorship across a multi-platform setup.

If network governance and remote access security sit at the top of the list, look for an OT Cybersecurity Engineer. iRecruit.co can help scope these needs based on your platform mix and project phase.

What should I test in an interview besides certifications?

Beyond certifications, check how candidates use their skills on the job and how they think through system-level problems. Have them walk you through a PLC control sequence, a Revit MEP model, or a calculation from a past project.

Scenario-based questions work well here. A failed commissioning script or a black-start L5 test can show how someone thinks under pressure, handles load issues, explains technical choices, and works through cross-discipline conflicts without throwing the schedule off track.

When should I hire for BAS cybersecurity during a data center project?

Start the search 6 to 12 months before project mobilization. These roles call for specialized expertise across mechanical, electrical, and network layers, so treat them as long-lead hires.

Bring recruiters in early during the design phase so the right people are on board before complex stages like Integrated Systems Testing (IST). If you wait until commissioning, schedule delays and expensive last-minute fixes can hit fast.

Related Blog Posts

Keywords:
BAS cybersecurity, building automation security, OT cybersecurity hiring, data center BAS, BAS hiring guide, OT/ICS security, vendor remote access
Free Download

Data Center Construction Labor Trends in 2026

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

More mission critical construction news

AI Hiring Guide for Mission-Critical Builders
August 4, 2026

AI Hiring Guide for Mission-Critical Builders

Staff mission-critical AI builds early: hire PMs, superintendents, MEP leads, commissioning and schedulers tied to design freeze and equipment release.
Construction Recruiting Benchmarks: Ultimate Guide
August 4, 2026

Construction Recruiting Benchmarks: Ultimate Guide

Benchmarks must be role-, region-, and funnel-specific so hiring meets project milestones and avoids schedule risk.
Cost Estimator Pay Guide for Mission-Critical Hiring
August 4, 2026

Cost Estimator Pay Guide for Mission-Critical Hiring

Set 2026 estimator base bands, bonus structures, and travel/relocation policies to hire and retain mission‑critical talent.
Owner's Rep Salary by Market 2026: Mission-Critical Pay Guide
August 4, 2026

Owner's Rep Salary by Market 2026: Mission-Critical Pay Guide

2026 owner's rep pay by market and asset class — data centers pay most; total compensation includes bonuses, overtime, and travel premiums.