Glen Combe — IT/OT Cybersecurity, Fortinet
I build security systems that watch the boundary between IT and OT -- turning raw network, endpoint, and industrial-protocol traffic into findings a SOC/NOC analyst can actually act on at Fortinet. Most recently, in my free time, I developed Foundry -- a ground-up applied intelligence platform covering syslog, Zeek passive capture, and OT protocol decoding in one pipeline.
Background
Certifications
- ISC2 ZTNA
- CISSP
- CCSP
- Fortinet NSE 7 — OT Security
- Fortinet NSE 4 — Network Security
- GICSP
- Security+
With 27 years of experience in IT and OT operations with a focus on cybersecurity, I've dedicated my career to architecting and implementing secure cybersecurity solutions for information technology, with a focused emphasis the last 11 years on operational technology (OT) environments. My passion lies in building and optimizing cybersecurity frameworks that align with business objectives while securing critical infrastructure.
I specialize in evaluating existing IT/OT systems, identifying vulnerabilities, and applying tailored security controls to mitigate risk. My deep technical expertise enables me to make informed security decisions that not only protect process networks but also support operational efficiency and compliance requirements.
Beyond the technical scope, I excel in communicating cybersecurity strategies with key stakeholders and leadership teams. Bridging the gap between technical execution and executive vision, I ensure security initiatives align seamlessly with organizational goals, enabling resilient, future-proofed infrastructure.
At Fortinet, I bring my expertise in industrial cybersecurity, IT/OT convergence, and risk management to drive innovative security solutions that protect critical systems and enhance business resilience.
- 27 years in IT/OT operations and cybersecurity — 11+ focused specifically on OT/ICS environments
- Driving industrial cybersecurity and IT/OT convergence strategy at Fortinet
- Builder of Foundry, a ground-up applied intelligence platform for IT/OT security monitoring
- Certified across ISC2 ZTNA, CISSP, CCSP, and Fortinet's OT/network security tracks
What I work on
Grounded in what's actually been built and accomplished.
OT / ICS Security
- Modbus, DNP3, CIP/EtherNet-IP, S7comm protocol decoding
- Purdue-model zone/level-aware asset classification
- PLC program-change & state-change detection
- Passive capture (Zeek) with ICSNPP protocol parsers
Detection Engineering
- MITRE ATT&CK-mapped behavior/pattern libraries
- Windows/Sysmon event classification (process, registry, DNS, named-pipe, WMI persistence)
- Credential-access detection: Kerberoasting, password spraying, golden-ticket heuristics
- Pcap-based protocol classification (Kerberos, SMB, TLS, LDAP, DNS, HTTP/FTP/SMTP)
Platform & Data Architecture
- Python backend design, event-driven ingestion pipelines
- PostgreSQL + Redis at the core of a durable, queryable registry
- Dual-path ingestion: live syslog and passive network capture
- Systemd/Linux service architecture, install/deploy tooling
Fortinet OT Security Fabric
- FortiGate — NGFW segmentation and policy enforcement at the IT/OT boundary and between Purdue zones
- FortiSwitch — secure, fabric-connected access-layer switching for OT network segmentation
- FortiNAC — network access control, device profiling, and automated response for IT/OT endpoints
- FortiPAM — privileged access management for secure vendor/engineer remote access into control systems
- FortiDeceptor — deception technology for early-stage OT/ICS intrusion detection
- FortiAnalyzer — centralized logging, correlation, and fabric-wide analytics
- FortiSOAR — playbook-driven orchestration and response tying the fabric together
Tools & Stack
- Python, PostgreSQL, Redis, systemd, nginx
- Zeek, tshark/Wireshark, Sysmon, NXLog
- FortiGate, FortiNAC, FortiAnalyzer-adjacent workflows
- Micro-segmentation and zone/conduit network design
- Virtual patching for legacy/unpatchable OT assets
Foundry
An applied intelligence platform for OT/IT security monitoring -- built end to end, from ingestion to analyst review.
Every event becomes a labeled fact, not a log line
Raw traffic is normalized into one of 178 canonical behaviors -- spanning authentication, credential access, lateral movement, defense evasion, and OT/ICS-specific activity -- each carrying a MITRE ATT&CK tactic, technique, and risk tier out of the box. Repeat occurrences of the same underlying flow feed a noise-reduction loop instead of re-flagging forever: an analyst's "expected" judgment on one recurring pattern is remembered and honored on every future match.
Findings that carry their own evidence
57+ patterns run continuously against live behavior. When one matches, a hypothesis is raised carrying the exact observation IDs that triggered it -- never a vague alert, always traceable back to specific evidence. Confirmed hypotheses get explicitly promoted to durable Doctrine, so a judgment call made once becomes standing organizational knowledge instead of getting re-litigated the next time the same pattern shows up.
Let's talk
Open to OT/ICS security engineering work, consulting, and interesting problems in general.