ICS/OT Security Architect

Charles A. Penn Jr.

Building order out of complexity

I design and operationalize secure industrial architectures across energy, manufacturing, and regulated environments. My work sits at the intersection of infrastructure, OT cybersecurity, and governance—turning complex systems into predictable, measurable, and resilient operations.

Systems Thinker
25+ years across infrastructure, OT, and regulated operations—aligning people, process, and technology into coherent, secure architectures.
ICS / OT
Dragos
Governance
Exec Reporting

Professional Identity

I am an ICS/OT Security Architect who builds order out of complexity. I combine deep infrastructure experience with modern OT security, documentation, and governance to reduce risk and improve operational integrity across multi‑site enterprises.

Flagship Achievements

A selection of work that best represents how I think, design, and deliver in high‑stakes industrial environments.

DTE ICS Security Architect Master Plan

DTE Energy
Enterprise OT security blueprint • 14 sites • Nuclear, generation, distribution, gas

Authored a four‑section, Day‑1 actionable master plan covering governance, Dragos rollout, SIEM/SOAR integration, OT Zero Trust pilot, AI/ML strategy, and a conversion‑ready evidence portfolio for executive oversight.

MTTD < 24h MTTC < 12h Asset Visibility ≥ 95% Sensor Uptime ≥ 99.5%

Dragos Operationalization Across 10 Sites

Cordia
OT security operations • Vulnerability management • Governance

Led Dragos deployment and remediation across 10 plants, coordinated sensor placement and relocation, delivered monthly vulnerability reports, and aligned segmentation and incident response with enterprise standards.

10 sites Monthly reporting CSIRP tabletop exercises

Ford BlueOval Hybrid AD & VMware Architecture

Ford Motor Company
Commissioning support • Hybrid AD • vSphere • OpenShift

Administered hybrid Active Directory, VMware vSphere, Windows Server roles, and Red Hat OpenShift in a high‑pressure greenfield battery plant, ensuring secure, stable infrastructure aligned with enterprise security and change management.

Hybrid AD vSphere / ESXi OpenShift

North American Server & Storage Leadership

Denso Manufacturing
VDI • SAN • Backup • 24/7 manufacturing

Served as primary server administrator for Denso Manufacturing Michigan and a key member of the North American server/storage team, managing VMware Horizon VDI, ESXi hosts, Nimble SAN, Veeam backups, and multi‑site AD/GPO.

24/7 support VDI at scale Nimble + Veeam

Identity & Access Governance

Cordia
SSO • MFA • Privileged access

Implemented Duo SSO for 18+ applications, performed MFA assessments for OT systems, and integrated CyberArk with SIEM for privileged access auditing—tightening identity governance across plant and enterprise services.

18+ apps SSO MFA assessments CyberArk + SIEM

Regulated Environment Foundations

Lilly, Covance & Others
GxP • GLP/GMP • FDA • SOX/JSOX

Built early‑career depth in FDA‑regulated and GxP environments, authoring SOPs, IVIs, and change‑controlled documentation while supporting scientific instruments, Windows/HP3000 servers, and large‑scale backup operations.

GxP / GLP / GMP SOP & IVI authoring 650+ servers (backups)

Career Timeline

A condensed view of how my roles evolved from hands‑on infrastructure and lab systems to enterprise ICS/OT security architecture and governance.

ICS Security Architect – DTE Energy (via Optomi)
2026 – Present • Detroit, MI (Remote + On‑Site)

Lead ICS/OT security architecture across nuclear, generation, distribution, and gas sites; design segmentation, secure remote access, and executive‑grade governance for critical infrastructure.

Systems Administrator – Ford BlueOval Battery Park
2026 • Marshall, MI

Delivered hybrid AD, VMware, and OpenShift administration in a greenfield battery plant, supporting commissioning and alignment with Ford enterprise security standards.

Sr. IT/OT Operations & Cybersecurity – Cordia
2024 – 2025 • Remote

Operationalized Dragos, improved segmentation, strengthened identity and access controls, and led governance and incident response enhancements across multiple plants.

Server & Storage / Sys Admin – Denso Manufacturing
2013 – 2024 • Battle Creek, MI

Managed VMware, SAN, backups, and VDI for North American manufacturing environments, providing 24/7 support and driving vulnerability remediation and lifecycle improvements.

Infrastructure & Lab Systems – Lilly, Covance & Others
1997 – 2012 • Indianapolis & Fort Wayne, IN

Supported scientific instruments, Windows/HP3000 servers, backups, and application testing in FDA‑regulated environments, building a strong foundation in compliance and documentation.

Skills Matrix

The capabilities I rely on most when designing and operationalizing secure industrial environments.

ICS / OT Security
Purdue Model Dragos OT Segmentation Vendor Remote Access OT Zero Trust (Pilot)
Infrastructure & Virtualization
Windows Server / AD VMware vSphere / ESXi Horizon VDI Nimble SAN Veeam / NetBackup
Security & Governance
NIST CSF CIS 18 NERC CIP (Context) GxP / GLP / GMP / FDA SOX / JSOX
Identity & Access
Duo SSO / MFA CyberArk Privileged Access Auditing Change Management
Monitoring & Integration
SIEM / SOAR Integration OT Telemetry KPI Design Tabletop Exercises
Documentation & Communication
SOPs & IVIs Architecture Diagrams Executive Reporting Training Content

Values & Contact

The principles that guide how I design, lead, and communicate—and how to reach me if you’d like to talk about ICS/OT security, infrastructure, or governance.

Professional Values

These are the anchors I return to when making decisions in complex, high‑stakes environments.

Integrity & Accountability
Stewardship & Resilience
Operational Excellence
Human‑Centered Technology
Clear Communication
Collaboration & Community
```