Cyber SDC - OT - Security Architect
About the role
This role provides architecture guidance and technical oversight for industrial, manufacturing, laboratory, and operational technology environments. The architect supports site-level design reviews, network segmentation validation, secure connectivity planning, exception analysis, operational readiness, and risk-based technical decision-making. This role applies and interprets established architecture standards rather than defining enterprise standards or performing routine day-to-day governance queue execution.
Responsibilities
- Apply established OT cybersecurity standards and approved design patterns to site-level implementations
- Review proposed OT network, firewall, secure access, monitoring, and infrastructure designs for alignment with approved standards
- Identify gaps between proposed implementations and established architecture requirements
- Recommend practical remediation options for design constraints, exceptions, or operational support concerns
- Support architecture reviews for site implementations, modernization activities, and operational changes
- Validate alignment with segmentation, zoning, firewall, remote access, monitoring, and operational support expectations
- Participate in design discussions for complex, high-risk, or non-standard OT implementations
- Partner with engineering and operations teams to support transition of approved designs into steady-state support
- Support technical risk assessments and impact analysis for non-standard architecture decisions
- Provide technical input for exception reviews, risk acceptance discussions, and remediation planning
- Escalate material design risks, control gaps, or operational concerns through appropriate governance channels
- Ensure architecture decisions and risk outcomes are documented and supportable
- Review secure connectivity patterns involving firewalls, remote access, segmentation controls, monitoring platforms, and related infrastructure
- Support alignment of applicable Zero Trust principles to OT users, devices, applications, and remote access use cases
- Advise on technical dependencies that may affect implementation, operations, lifecycle management, or supportability
- Validate that designs include monitoring, alerting, documentation, support records, and escalation considerations
- Support operational readiness discussions and post-implementation improvement activities
- Provide senior technical advisory support for complex OT security architecture decisions
- Develop reusable guidance, lessons learned, and implementation patterns based on site delivery experience
Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, or related field preferred
- 8–10+ years of experience in cybersecurity, infrastructure, networking, industrial technology, or security architecture roles
- 5+ years supporting OT, manufacturing, industrial, engineering, laboratory, or critical infrastructure environments
- Strong understanding of network security, firewalls, segmentation, secure connectivity, remote access, and infrastructure support concepts
- Experience reviewing technical designs against established architecture standards and operational requirements
- Strong communication, documentation, stakeholder management, and risk-based decision-making skills
Preferred qualifications
- Experience supporting manufacturing or industrial site environments
- Knowledge of ICS and OT architectures, Purdue Model concepts, NIST CSF, and IEC 62443 concepts
- Experience with firewall policy review, network segmentation, secure remote access, OT asset visibility, or security monitoring platforms
- Relevant certifications such as CISSP, GICSP, GIAC, IEC 62443, Security+, Network+, or comparable security/network credentials
Technical skills
- OT security architecture
- Network segmentation
- Firewall policy architecture
- Secure remote access
- Zero Trust principles
- Industrial networking
- Security monitoring concepts
- Routing and switching
- Operational readiness
- Risk assessment
- Documentation and handoff
- Stakeholder coordination
Pay
Base salary range: $104,800 to $192,200 (all geographic locations in the US); $125,800 to $218,500 (New York City Metro Area, Washington State, and California excluding Sacramento). Individual salaries determined by education, experience, knowledge, skills, and geography.
Schedule
Team-led and leader-enabled hybrid model: most people in external, client-serving roles work together in person 40-60% of the time over the course of an engagement, project, or year.
Benefits
- Medical and dental coverage
- Pension and 401(k) plans
- Flexible vacation policy (determine vacation time based on personal circumstances)
- Designated EY Paid Holidays
- Winter/Summer breaks
- Personal/Family Care leave
- Other leaves of absence to support physical, financial, and emotional well-being