Job Summary
Operational Technology Network
Security Architect L4 OT Security Architect
Role Summary
We are seeking a skilled and experienced OT Security Architect with strong hands-on expertise in Operational Technology security, OT network architecture, secure remote access, Zero Trust access models, and industrial cybersecurity frameworks.
The role will be responsible for designing, implementing, and managing secure OT access and segmentation architectures across industrial environments. The candidate should have practical experience with OT/ICS environments such as SCADA, DCS, PLC systems, and the ability to translate business, operational, and security requirements into scalable OT security architecture designs.
This position requires a strong understanding of industrial network zones and conduits, Purdue Model architecture, OT/IT segmentation, vendor remote access, identity integration, firewall/security policy design, and compliance with IEC 62443, NIST, and internal cybersecurity policies.
Key Responsibilities
Operational Technology / Cyolo Architecture
Key Responsibilities
OT Architecture & Network Security Design
• Design and review secure OT network architectures aligned with the Purdue Model and industrial security best practices.
• Define and implement OT security zones and conduits, including segmentation between IT, OT, DMZ, production, engineering, and vendor access zones.
• Develop reference architectures for secure remote access, OT firewall placement, jump server access, identity-based access, and secure vendor connectivity.
• Review existing OT environments and recommend architecture improvements to reduce risk and improve security posture.
• Support the design of OT DMZ, industrial firewall rules, secure routing paths, access control flows, and network isolation models.
• Work with network, firewall, platform, and plant teams to ensure OT architecture designs are practical, resilient, and operationally supportable.
• Validate architecture designs against security principles such as least privilege, defense-in-depth, Zero Trust, secure-by-design, and asset criticality.
Secure Remote Access & Zero Trust Implementation
• Lead the design, deployment, and management of Cyolo Secure Remote Access solution across OT environments.
• Implement Zero Trust access controls for vendors, third-party users, internal support teams, and privileged users.
• Integrate Cyolo with Active Directory, Identity Providers, SSO, and MFA solutions.
• Configure and manage secure remote sessions, policy enforcement, access workflows, approval processes, and session monitoring.
• Monitor, review, and audit remote access activity to ensure compliance with IEC 62443, NIST, and company security policies.
OT/ICS Security Operations & Risk Management
• Conduct OT risk assessments, vulnerability analysis, exposure reviews, and remediation planning for industrial systems.
• Identify insecure communication paths between OT, IT, vendor networks, and internet-facing services.
• Support secure onboarding of OT assets, remote users, vendors, applications, and industrial systems.
• Participate in incident response and forensic investigations related to OT remote access, unauthorized access, segmentation gaps, and abnormal industrial network activity.
• Collaborate with SOC/SIEM teams to improve monitoring, alerting, and threat detection for OT remote access and industrial network events.
• Support continuous improvement of OT security controls, including firewall rule reviews, access recertification, and architecture compliance checks.
Governance, Documentation & Stakeholder Support
• Develop and maintain OT security architecture documents, SOPs, low-level designs, high-level designs, connectivity diagrams, and operational runbooks.
• Assist in customer demonstrations, deployment planning, architecture workshops, and post-implementation support.
• Provide technical guidance to operations teams during complex troubleshooting, implementation, and escalation scenarios.
• Support compliance mapping and evidence collection for IEC 62443, NIST, internal cybersecurity standards, and industrial control security requirements.
Skill Requirements
Network Security, Cyolo
Required Skills
Experience
• 14+ years of experience, with strong focus on OT/ICS security, OT network security, or industrial cybersecurity.
• Strong hands-on experience in OT/ICS environments including SCADA, DCS, PLC systems, engineering workstations, HMIs, historians, and industrial control networks.
• Experience in designing or supporting OT security architectures for large industrial or manufacturing environments.
• Experience with secure remote access solutions such as Cyolo, Secomea, Claroty, BeyondTrust, or similar OT access platforms.
• Experience working with network security technologies such as firewalls, VPN, segmentation, routing, switching, NAT, IDS/IPS, and secure access gateways.
• Exposure to SIEM, SOC operations, OT threat detection, log analysis, and incident response processes.
OT Architecture Skills
• Strong understanding of Purdue Model architecture and OT/IT security segmentation principles.
• Ability to design zones and conduits for industrial environments.
• Knowledge of OT DMZ design, secure vendor access models, jump server architecture, and controlled access paths.
• Ability to create and review HLD, LLD, network diagrams, data flow diagrams, and security architecture documents.
• Understanding of industrial network communication patterns and how to secure OT-to-IT, OT-to-OT, and OT-to-vendor connectivity.
• Ability to assess architecture risks and recommend compensating security controls.
• Knowledge of secure firewall rule design, least privilege access, and rule lifecycle governance in OT environments.
• Understanding of high availability, resilience, operational continuity, and fail-safe design considerations in OT networks.
Identity, Access & Zero Trust Skills
• Familiarity with Identity and Access Management, Active Directory, SSO, MFA, privileged access management, and role-based access control.
• Ability to implement identity-driven access controls for OT remote access users.
• Understanding of approval workflows, session recording, just-in-time access, and access recertification processes.
• Knowledge of vendor access governance and third-party access risk management.
Industrial Protocol & Security Knowledge
• Knowledge of industrial protocols such as Modbus, OPC, Profinet, EtherNet/IP, BACnet, DNP3, IEC 60870-5-104, and related OT communication protocols.
• Understanding of how industrial protocols operate and the security risks associated with insecure or unsegmented communication.
• Knowledge of OT asset discovery, vulnerability management, and exposure assessment concepts.
Compliance & Framework Knowledge
• Good understanding of industrial cybersecurity frameworks and standards such as:
IEC 62443
NIST Cybersecurity Framework
NIST SP 800-82
ISO 27001
Internal OT security policies and governance requirements
• Ability to map technical controls to compliance requirements and support audit evidence preparation.
Qualifications
• Bachelor’s degree in Engineering, Cybersecurity, Computer Science, Information Technology, or related field.
• Preferred certifications:
GICSP
IEC 62443 Cybersecurity Certification
CISSP
CISM
PCNSE
CCNP Security
Cyolo / Secure Remote Access platform training or equivalent
Other relevant OT, network security, or industrial cybersecurity certifications
Other Requirements
Cyolo