OT Cyber Security Architect

Chalmette, La
Brentwood, TN, United States
13 days ago
Apply on ptsadvance.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Computer-Aided Design Google AdWords User Authentication Cloud Engineering Communications Protocols Cyber Security Information Systems Multi-Factor Authentication Google Analytics Health Information Management Human-Computer Interaction
+27 more
Supervisory Control and Data Acquisition (SCADA) Identity and Access Management Intrusion Detection Systems Information Systems Security Architecture Professional JavaScript Libraries Network Security Network Layer Network Architecture Network Monitoring Network Segmentation Role-Based Access Control Remote Access Technology Zero Trust Network Access Security Information and Event Management Software Engineering Software Vulnerability Management Wireless Networks Enterprise Software Applications Process Control Systems Enterprise Integration Operational Systems Fortinet Multiaccess Edge Computing Industrial Software Network Server Cisco Security Orchestration, Automation & Response

Job description

The Operational Technology (OT) Cybersecurity Architect is responsible for defining, designing, and governing the cybersecurity architecture that protects Delek Logistics’ (DKL) operational technology environments, including pipeline, terminal, storage, and industrial control systems (ICS). This role establishes the strategic direction for OT cybersecurity while ensuring industrial operations remain safe, reliable, resilient, and compliant with applicable regulatory and industry requirements.

The OT Security Architect partners with Operations Technology, Engineering, Pipeline Operations, Infrastructure, Network Engineering, Cloud Engineering, Security Operations, Enterprise Architecture, and third-party vendors to develop secure OT architectures that reduce cyber risk without impacting operational availability.

The successful candidate will possess deep expertise in industrial control systems (ICS), SCADA, industrial networking, Zero Trust for Operational Technology, and cybersecurity frameworks applicable to critical infrastructure., · Define secure reference architectures for pipeline, terminal, storage, and industrial environments.

· Establish OT cybersecurity standards and design principles.

· Develop long-term OT cybersecurity roadmaps aligned with business objectives.

· Lead architecture reviews for OT modernization and digital transformation initiatives.

· Ensure cybersecurity controls support operational safety, reliability, and availability.

· Develop secure architectures for SCADA systems, Distributed Control Systems (DCS), Programmable Logic Controllers (PLC), Remote Terminal Units (RTU), Human Machine Interfaces (HMI), Historian systems, Engineering workstations, Safety Instrumented Systems (SIS), Industrial IoT and Edge computing platforms.

· Ensure secure integration between industrial systems and enterprise technologies.

· Define architecture standards for Industrial firewalls, Network segmentation, Industrial DMZs, Secure remote access, Jump servers, Vendor remote access, Industrial wireless networks, Layer 2 and Layer 3 segmentation, Industrial network monitoring and Secure field communications.

· Develop strategies supporting Zero Trust principles within OT environments.

· Provide architectural guidance for Industrial Intrusion Detection Systems (IDS), Network Detection and Response (NDR), OT asset discovery platforms, Industrial vulnerability management, Secure remote access platforms, OT Security Information and Event Management (SIEM) integration, Security orchestration and response for OT environments, and Passive network monitoring technologies.

· Guide implementation teams responsible for deployment and administration.

· Develop secure architectures supporting Privileged access to OT systems, OT Multi-Factor Authentication (MFA), Role-based access control, least privilege administration, Secure engineering workstation access, Authentication for industrial systems, and Identity boundaries between IT and OT.

· Perform cybersecurity architecture risk assessments for operational technology initiatives.

· Identify architectural risks associated with industrial modernization.

· Develop compensating controls where operational constraints exist.

· Evaluate cybersecurity impacts on operational reliability and safety.

· Provide architectural guidance supporting OT threat detection.

· Collaborate with Security Operations during OT security incidents.

· Support forensic investigations involving industrial systems.

· Improve visibility into industrial cybersecurity events.

· Recommend architecture improvements following incident reviews.

· Evaluate emerging OT cybersecurity technologies.

· Lead proof-of-concept evaluations.

· Present architecture recommendations to executive leadership and engineering stakeholders.

· Ensure architectural alignment with:

o NIST Cybersecurity Framework (CSF)

o ISA/IEC 62443

o SOX

o CIS Critical Security Controls

· Partner closely with Enterprise Architecture, Infrastructure Services, Network Engineering, Cloud Engineering, Security Operations, Identity & Access Management, Operations Technology (OT), Refinery Engineering, Third- party vendors and Application Development.

SUCCESS MEASURES

· Highly available and resilient Operational Technology environments.

· Successful implementation of secure IT/OT architecture principles.

· Reduced cybersecurity risk across pipeline and terminal operations.

· Effective segmentation between enterprise and industrial networks.

· Increased visibility into OT assets and cybersecurity events.

· Successful completion of cybersecurity assessments and regulatory audits with minimal findings., Essential cookies enable basic functions and are necessary for the proper function of the website. Name, This cookie is used to identify a unique visitor to enhance the user experience by enabling personalized features and content based on the visitor’s preferences and browsing history. 4 weeks ipaddress This cookie is used to store the IP address of the visitor to facilitate website functionality by providing a more personalized experience. 1 day Cookie Preferences This cookie is used to store the user’s cookie consent preferences. 30 days Statistics

Statistics cookies collect information anonymously. This information helps us understand how visitors use our website. Google Analytics

Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.

Service URL: policies.google.com (opens in a new window) Name, Duration gali Used by Google Analytics to determine which links on a page are being clicked 30 seconds _ga ID used to identify users 2 years gid ID used to identify users for 24 hours after last activity 24 hours _gat Used to monitor number of Google Analytics server requests when using Google Tag Manager 1 minute _gac Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together. 90 days __utma ID used to identify users and sessions 2 years after last activity __utmt Used to monitor number of Google Analytics server requests 10 minutes __utmb Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server. 30 minutes after last activity __utmc Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session. End of session (browser) __utmz Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server 6 months after last activity __utmv Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server. 2 years after last activity __utmx Used to determine whether a user is included in an A / B or Multivariate test. 18 months _ga ID used to identify users 2 years Cookie Policy

Requirements

· Bachelor’s degree in Cybersecurity, Computer Science, Engineering, Information Systems, Industrial Engineering, Electrical Engineering, or a related field; or equivalent combination of education and experience.

· 8+ years of experience in Operational Technology (OT), Industrial Control Systems (ICS), or industrial cybersecurity.

· 3+ years designing enterprise or industrial cybersecurity architectures.

· Experience securing pipeline, terminal, refinery, manufacturing, or critical infrastructure environments.

· Experience with SCADA systems, PLCs, HMIs, RTUs, and industrial communication protocols.

· Experience designing secure industrial network architectures.

· Experience implementing network segmentation between IT and OT environments.

· Experience working with industrial control system vendors and engineering teams.

· Experience supporting highly available operational environments where uptime and safety are critical.

PREFERRED CERTIFICATIONS

· ISA/IEC 62443 Cybersecurity Certificate

· CISSP

· Certified Information Security Manager (CISM)

· Microsoft Certified: Cybersecurity Architect Expert (SC-100)

· Cisco Certified Network Professional (CCNP) Security

· Fortinet NSE Certification, · Develop and maintain the enterprise Operational Technology cybersecurity architecture.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ptsadvance.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:17 min

Applying authorization at the network versus application layers

Alex Olivier Alex Olivier · LIVE

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann +1 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:26 min

The convergence of IT and OT attacks

Kurt Eder · LIVE

1:50 min

Configuring gRPC bindings in the OpenSearch YAML

Sakshi Nasha Sakshi Nasha · Europe 2026 Virtual

Videos

See all

Related articles

See all