Functional safety is the part of safety that depends on control systems doing what they are specified to do: safety instrumented systems that trip a process to a safe state, emergency shutdown systems on plants, and safety interlocks on machines. IEC 61508 frames the discipline with safety integrity levels, four discrete levels where SIL 4 carries the highest risk reduction, allocated per safety function rather than per device . The craft's evidence base is what makes hiring distinct: competence is demonstrated through safety requirements specifications, verification reports and proof-test records, and employers buy that documentation along with the engineer.
Challenges in Functional Safety Recruiting
Hazard risk assessment decides the SIL before any vendor does
The first act of any safety project is a hazard risk assessment, and everything downstream hangs on it. IEC 61508 takes a risk-based approach: the tolerable risk determines the safety integrity required of the function, and the SIL is the claim that the function will achieve its risk reduction . The standard is explicit about what it will not do: it does not specify which SIL any given function needs, which means the practitioner decides, and the decision is defensible or it is not . In the process sector, IEC 61511 puts the same duty in the operator's hands, requiring a process hazard and risk assessment to derive the specification of each safety instrumented function . The scarce profile is the engineer who has run those studies and stood behind the allocation in front of an assessor. Far more common is the engineer who received a SIL target from a study someone else ran and implemented it competently, which is useful but not the same seat.
IEC 61508 lifecycles split the machinery bench from IEC 61511 process work
Functional safety fragments along the lifecycle standards. IEC 61508 is the generic framework, adopted in Europe as EN 61508, and its role has been to seed the sector implementations . IEC 61511 is the process sector implementation: it governs how a safety instrumented system is specified, designed, installed, operated and maintained so it can be entrusted with the safe state of the process . Machinery safety runs a different branch entirely, through ISO 13849 and IEC 62061. The practitioners sit in different populations. A process safety engineer thinks in demand mode, shutdown valves and proof-test intervals; a machinery safety engineer thinks in performance levels, categories and monitored outputs. Both call themselves functional safety engineers, and a plant hiring for a SIS role against that generic title will interview half its shortlist from the wrong branch.
Safety integrity levels fragment between demand and continuous modes
Safety integrity levels are not one scale but two. IEC 61508-1 sets target failure measures per SIL: in low demand mode, the average probability of dangerous failure on demand, down to 10 to the minus 5 for SIL 4; in high demand or continuous mode, the average frequency of dangerous failure per hour, down to 10 to the minus 9 . The distinction is not bookkeeping. A demand-mode function sits idle until an emergency; a continuous-mode function is the control itself, and the two have different architectures, different diagnostic expectations and different proof-test mathematics. The IEC overview makes the point bluntly: SIL is a property of a safety function, not of a device . A candidate who has sized demand-mode SIF loops may never have touched continuous-mode failure rates, and the interview needs to know which arithmetic the role requires before the candidate can be judged.
Emergency shutdown systems live on SIF loops and proof-test intervals
Emergency shutdown systems are where the discipline meets the plant floor. A safety instrumented system runs one or more safety instrumented functions, and each SIF loop runs from sensor through logic solver to final element, shutdown valves included . What keeps the loop honest is the proof test: IOGP's supplementary specification to IEC 61511 requires written procedures per SIF, testing the entire loop including process connections, and documenting as-found and as-left conditions, and it layers owner practices on top such as de-energise-to-trip wiring and bypass logging . The engineer who has owned those loops carries proof-test records, failure mode data and the arguments about test coverage that decide the assumed probability of failure on demand. This population is small because the evidence is only generated on operating plants, and operators guard it closely.
Safety interlocks multiply at the machine builders
Safety interlocks are the machinery branch's daily work: guard monitoring, two-hand controls, electro-sensitive protective devices and the enabling switches that make operator access safe. ISO 13849-1 is the governing standard, defining safety-related parts of control systems and the performance levels they must carry for high demand and continuous mode, across electrical, hydraulic, pneumatic and mechanical technologies . The 2023 edition structures the work around categories B, 1, 2, 3 and 4, each with its own behavior under fault conditions, diagnostic coverage and channel reliability requirements, and lists interlocking devices among the classic applications . Machine builders absorb this volume, and they hire differently from process operators: they need design-side engineers who can select a category, score common cause failures and defend a validation. The two populations meet only at the standards shelf.
ISO 13849 PLd routes machinery safety through MTTFd arithmetic
PLd is the workhorse claim of machinery safety, and it is earned by arithmetic. The performance level of a safety function comes out of the combination of category architecture, mean time to dangerous failure of each channel, average diagnostic coverage and the common cause failure score . PLd itself is typically reached through Category 3: redundant channels, a single fault must not lose the safety function, diagnostic coverage at least low, and measures against common cause failures in place . The interview that separates the field asks the candidate to defend a PLd claim from its inputs: which MTTFd band, which DC value, what the CCF scoring sheet said, and what happens to the claim when a component changes supplier. A candidate who can run that arithmetic owns the role; a candidate who copies PLd from a competitor's declaration owns the vocabulary.
SFF and proof-test records expose inflated SIL claims
Verification in this discipline is an audit, not a quiz. Ask which safety requirements specification the candidate wrote and how it was verified. Ask for the SIF loop they carried from hazard study through design to proof test, and what the as-found condition was at the last test . Ask which safety integrity level the function carried and how the target failure measure was met . On the machinery side, ask for the PLd calculation and the validation record behind it . A strong candidate answers with documents; a weak one answers with standards numbers, and the difference is visible in five minutes. The cost of a miss is unlike any other seat in industrial control: a proof-test gap quietly erodes the risk reduction the plant is operating under, an audit finding can shut work down, and the rework lands on the safety requirements specification that everything else was built from. False negatives are equally serious. A machinery safety engineer who has never touched a shutdown valve may still be the right hire for the interlocks backlog, and screening on "SIS" keywords alone would throw that person out.
References
- Overview of IEC 61508 and Functional Safety — International Electrotechnical Commission (IEC). (accessed 2026-09-28)
- IEC 61508-1:2010, General Requirements (Preview) — International Electrotechnical Commission (IEC). (accessed 2026-09-28)
- What is IEC 61508? — The 61508 Association. (accessed 2026-09-28)
- S-636: Supplementary Specification to IEC 61511-1, Safety Instrumented Systems — International Association of Oil and Gas Producers (IOGP). (accessed 2026-09-28)
- ISO 13849-1:2015, Safety of machinery — International Organization for Standardization (ISO). (accessed 2026-09-28)
- ISO 13849-1:2023, Safety of machinery (Sample) — International Organization for Standardization (ISO). (accessed 2026-09-28)
