Cyber SDC - OT - Security Architect
EY · Chicago, IL · 4 wk ago
HybridEngineering$105k–$192k/yrFull-time
About the role
This senior-level role provides architecture guidance and technical oversight for industrial, manufacturing, laboratory, and operational technology environments. The architect supports site-level design reviews, network segmentation validation, secure connectivity planning, exception analysis, operational readiness, and risk-based technical decision-making. This position applies and interprets established architecture standards rather than defining enterprise standards or performing routine day-to-day governance queue execution. The architect works across cybersecurity, infrastructure, engineering, operations, and site teams to help ensure OT solutions are secure, supportable, and aligned to established standards.
Key responsibilities
- Apply established OT cybersecurity standards and approved design patterns to site-level implementations.
- Review proposed OT network, firewall, secure access, monitoring, and infrastructure designs for alignment with approved standards.
- Identify gaps between proposed implementations and established architecture requirements.
- Recommend practical remediation options for design constraints, exceptions, or operational support concerns.
- Support architecture reviews for site implementations, modernization activities, and operational changes.
- Validate alignment with segmentation, zoning, firewall, remote access, monitoring, and operational support expectations.
- Participate in design discussions for complex, high-risk, or non-standard OT implementations.
- Partner with engineering and operations teams to support transition of approved designs into steady-state support.
- Support technical risk assessments and impact analysis for non-standard architecture decisions.
- Provide technical input for exception reviews, risk acceptance discussions, and remediation planning.
- Escalate material design risks, control gaps, or operational concerns through appropriate governance channels.
- Ensure architecture decisions and risk outcomes are documented and supportable.
- Review secure connectivity patterns involving firewalls, remote access, segmentation controls, monitoring platforms, and related infrastructure.
- Support alignment of applicable Zero Trust principles to OT users, devices, applications, and remote access use cases.
- Advise on technical dependencies that may affect implementation, operations, lifecycle management, or supportability.
- Validate that designs include monitoring, alerting, documentation, support records, and escalation considerations.
- Support operational readiness discussions and post-implementation improvement activities.
- Provide senior technical advisory support for complex OT security architecture decisions.
- Develop reusable guidance, lessons learned, and implementation patterns based on site delivery experience.
Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, or related field preferred.
- 8–10+ years of experience in cybersecurity, infrastructure, networking, industrial technology, or security architecture roles.
- 5+ years supporting OT, manufacturing, industrial, engineering, laboratory, or critical infrastructure environments.
- Strong understanding of network security, firewalls, segmentation, secure connectivity, remote access, and infrastructure support concepts.
- Experience reviewing technical designs against established architecture standards and operational requirements.
- Strong communication, documentation, stakeholder management, and risk-based decision-making skills.
Preferred qualifications
- Experience supporting manufacturing or industrial site environments.
- Knowledge of ICS and OT architectures, Purdue Model concepts, NIST CSF, and IEC 62443 concepts.
- Experience with firewall policy review, network segmentation, secure remote access, OT asset visibility, or security monitoring platforms.
- Relevant certifications such as CISSP, GICSP, GIAC, IEC 62443, Security+, Network+, or comparable security/network credentials.
Technical skills
- OT security architecture
- Network segmentation
- Firewall policy architecture
- Secure remote access
- Risk assessment
- Zero Trust principles
- Industrial networking
- Security monitoring concepts
- Routing and switching
- Operational readiness
- Documentation and handoff
- Stakeholder coordination
Benefits and pay
- Comprehensive compensation and benefits package with rewards based on performance.
- Base salary range for all US geographic locations: $104,800 to $192,200.
- Base salary range for New York City Metro Area, Washington State, and California (excluding Sacramento): $125,800 to $218,500.
- Medical and dental coverage.
- Pension and 401(k) plans.
- Wide range of paid time off options.
- Flexible vacation policy allowing you to decide how much time you need based on personal circumstances.
- Designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence.
Schedule and work model
- Team-led and leader-enabled hybrid model.
- For most people in external, client-serving roles: work together in person 40-60% of the time over the course of an engagement, project, or year.