Jobs · Engineering · California

Cyber SDC - OT - Security Architect

EY · San Mateo, CA · 4 wk ago
HybridEngineering$105k–$192k/yrFull-time

About the role

Organizations operating industrial and operational technology environments require consistent application of cybersecurity standards, secure connectivity patterns, network segmentation practices, and operational support requirements across diverse site environments. The Security Architect – OT role provides architecture guidance, design validation, and technical advisory support to help ensure OT environments are implemented and operated in alignment with established security requirements and approved design patterns.

Key responsibilities

  • Apply established OT cybersecurity standards and approved design patterns to site-level implementations.
  • Review proposed OT network, firewall, secure access, monitoring, and infrastructure designs for alignment with approved standards.
  • Identify gaps between proposed implementations and established architecture requirements.
  • Recommend practical remediation options for design constraints, exceptions, or operational support concerns.
  • Support architecture reviews for site implementations, modernization activities, and operational changes.
  • Validate alignment with segmentation, zoning, firewall, remote access, monitoring, and operational support expectations.
  • Participate in design discussions for complex, high-risk, or non-standard OT implementations.
  • Partner with engineering and operations teams to support transition of approved designs into steady-state support.
  • Support technical risk assessments and impact analysis for non-standard architecture decisions.
  • Provide technical input for exception reviews, risk acceptance discussions, and remediation planning.
  • Escalate material design risks, control gaps, or operational concerns through appropriate governance channels.
  • Ensure architecture decisions and risk outcomes are documented and supportable.
  • Review secure connectivity patterns involving firewalls, remote access, segmentation controls, monitoring platforms, and related infrastructure.
  • Support alignment of applicable Zero Trust principles to OT users, devices, applications, and remote access use cases.
  • Advise on technical dependencies that may affect implementation, operations, lifecycle management, or supportability.
  • Validate that designs include monitoring, alerting, documentation, support records, and escalation considerations.
  • Support operational readiness discussions and post-implementation improvement activities.
  • Provide senior technical advisory support for complex OT security architecture decisions.
  • Develop reusable guidance, lessons learned, and implementation patterns based on site delivery experience.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, or related field preferred.
  • 8–10+ years of experience in cybersecurity, infrastructure, networking, industrial technology, or security architecture roles.
  • 5+ years supporting OT, manufacturing, industrial, engineering, laboratory, or critical infrastructure environments.
  • Strong understanding of network security, firewalls, segmentation, secure connectivity, remote access, and infrastructure support concepts.
  • Experience reviewing technical designs against established architecture standards and operational requirements.
  • Strong communication, documentation, stakeholder management, and risk-based decision-making skills.

Preferred qualifications

  • Experience supporting manufacturing or industrial site environments.
  • Knowledge of ICS and OT architectures, Purdue Model concepts, NIST CSF, and IEC 62443 concepts.
  • Experience with firewall policy review, network segmentation, secure remote access, OT asset visibility, or security monitoring platforms.
  • Relevant certifications such as CISSP, GICSP, GIAC, IEC 62443, Security+, Network+, or comparable security/network credentials.

Technical skills

  • OT security architecture
  • Network segmentation
  • Firewall policy architecture
  • Secure remote access
  • Zero Trust principles
  • Industrial networking
  • Security monitoring concepts
  • Routing and switching
  • Operational readiness
  • Risk assessment
  • Documentation and handoff
  • Stakeholder coordination

Similar jobs