> Markdown version of [/jobs/ext/1885798-cyber-sdc-ot-security-architect](https://www.wearedevelopers.com/jobs/ext/1885798-cyber-sdc-ot-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber SDC - OT - Security Architect - **Company:** Ernst & Young LLP - **Location:** Grandview Heights, OH, United States (Remote available) - **Experience:** Expert - **Salary:** $104,800.0 - $192,200.0 - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Cyber Security, Software Design Patterns, Network Security, Routing, Network Segmentation, Remote Access Technology, Material Design, Zero Trust Network Access, IT Architecture, Firewalls (Computer Science), Information Technology, Operational Systems - **Published:** August 2, 2026 - **Apply:** https://dejobs.org/x/x/F4C8D1ADC0554F3488623A5E8AE7AC0F/job/ ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, or related field preferred. * 8-10+ years of experience in cybersecurity, infrastructure, networking, industrial technology, or security architecture roles. * 5+ years supporting OT, manufacturing, industrial, engineering, laboratory, or critical infrastructure environments. * Strong understanding of network security, firewalls, segmentation, secure connectivity, remote access, and infrastructure support concepts. * Experience reviewing technical designs against established architecture standards and operational requirements. * Strong communication, documentation, stakeholder management, and risk-based decision-making skills., * Experience supporting manufacturing or industrial site environments. * Knowledge of ICS and OT architectures, Purdue Model concepts, NIST CSF, and IEC 62443 concepts. * Experience with firewall policy review, network segmentation, secure remote access, OT asset visibility, or security monitoring platforms. * Relevant certifications such as CISSP, GICSP, GIAC, IEC 62443, Security+, Network+, or comparable security/network credentials. TECHNICAL SKILLS Architecture Infrastructure Operations OT security architecture Network segmentation Operational readiness Firewall policy architecture Secure remote access Risk assessment Zero Trust principles Industrial networking Documentation and handoff Security monitoring concepts Routing and switching ## Description Site-level architecture guidance, standards adherence, design validation, and technical risk advisory, Senior OT security architecture advisor supporting secure and supportable industrial environments, The Security Architect - OT role provides architecture guidance, design validation, and technical advisory support to help ensure OT environments are implemented and operated in alignment with established security requirements and approved design patterns., We are seeking an experienced Security Architect - Operational Technology (OT) to provide architecture guidance and technical oversight for industrial, manufacturing, laboratory, and operational technology environments. This role supports site-level design reviews, network segmentation validation, secure connectivity planning, exception analysis, operational readiness, and risk-based technical decision-making. The architect works across cybersecurity, infrastructure, engineering, operations, and site teams to help ensure OT solutions are secure, supportable, and aligned to established standards. Role positioning: This role applies and interprets established architecture standards rather than defining enterprise standards or performing routine day-to-day governance queue execution., Architecture Standards Adherence * Apply established OT cybersecurity standards and approved design patterns to site-level implementations. * Review proposed OT network, firewall, secure access, monitoring, and infrastructure designs for alignment with approved standards. * Identify gaps between proposed implementations and established architecture requirements. * Recommend practical remediation options for design constraints, exceptions, or operational support concerns. Site-Level Design Review and Validation * Support architecture reviews for site implementations, modernization activities, and operational changes. * Validate alignment with segmentation, zoning, firewall, remote access, monitoring, and operational support expectations. * Participate in design discussions for complex, high-risk, or non-standard OT implementations. * Partner with engineering and operations teams to support transition of approved designs into steady-state support. Risk and Exception Support * Support technical risk assessments and impact analysis for non-standard architecture decisions. * Provide technical input for exception reviews, risk acceptance discussions, and remediation planning. * Escalate material design risks, control gaps, or operational concerns through appropriate governance channels. * Ensure architecture decisions and risk outcomes are documented and supportable. Secure Connectivity and Infrastructure Alignment * Review secure connectivity patterns involving firewalls, remote access, segmentation controls, monitoring platforms, and related infrastructure. * Support alignment of applicable Zero Trust principles to OT users, devices, applications, and remote access use cases. * Advise on technical dependencies that may affect implementation, operations, lifecycle management, or supportability. Operational Readiness and Technical Advisory * Validate that designs include monitoring, alerting, documentation, support records, and escalation considerations. * Support operational readiness discussions and post-implementation improvement activities. * Provide senior technical advisory support for complex OT security architecture decisions. * Develop reusable guidance, lessons learned, and implementation patterns based on site delivery experience., Security Architect - OT: Provides architecture guidance and technical oversight for operational technology environments, ensuring site-level implementations adhere to established cybersecurity standards, approved design patterns, network segmentation requirements, secure connectivity practices, monitoring expectations, and operational support needs. Supports design reviews, exception analysis, risk assessments, operational readiness, and transition into steady-state operations. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)