OT Cyber Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+27 more
Job description
The Operational Technology (OT) Cybersecurity Architect is responsible for defining, designing, and governing the cybersecurity architecture that protects Delek Logistics’ (DKL) operational technology environments, including pipeline, terminal, storage, and industrial control systems (ICS). This role establishes the strategic direction for OT cybersecurity while ensuring industrial operations remain safe, reliable, resilient, and compliant with applicable regulatory and industry requirements.
The OT Security Architect partners with Operations Technology, Engineering, Pipeline Operations, Infrastructure, Network Engineering, Cloud Engineering, Security Operations, Enterprise Architecture, and third-party vendors to develop secure OT architectures that reduce cyber risk without impacting operational availability.
The successful candidate will possess deep expertise in industrial control systems (ICS), SCADA, industrial networking, Zero Trust for Operational Technology, and cybersecurity frameworks applicable to critical infrastructure., · Define secure reference architectures for pipeline, terminal, storage, and industrial environments.
· Establish OT cybersecurity standards and design principles.
· Develop long-term OT cybersecurity roadmaps aligned with business objectives.
· Lead architecture reviews for OT modernization and digital transformation initiatives.
· Ensure cybersecurity controls support operational safety, reliability, and availability.
· Develop secure architectures for SCADA systems, Distributed Control Systems (DCS), Programmable Logic Controllers (PLC), Remote Terminal Units (RTU), Human Machine Interfaces (HMI), Historian systems, Engineering workstations, Safety Instrumented Systems (SIS), Industrial IoT and Edge computing platforms.
· Ensure secure integration between industrial systems and enterprise technologies.
· Define architecture standards for Industrial firewalls, Network segmentation, Industrial DMZs, Secure remote access, Jump servers, Vendor remote access, Industrial wireless networks, Layer 2 and Layer 3 segmentation, Industrial network monitoring and Secure field communications.
· Develop strategies supporting Zero Trust principles within OT environments.
· Provide architectural guidance for Industrial Intrusion Detection Systems (IDS), Network Detection and Response (NDR), OT asset discovery platforms, Industrial vulnerability management, Secure remote access platforms, OT Security Information and Event Management (SIEM) integration, Security orchestration and response for OT environments, and Passive network monitoring technologies.
· Guide implementation teams responsible for deployment and administration.
· Develop secure architectures supporting Privileged access to OT systems, OT Multi-Factor Authentication (MFA), Role-based access control, least privilege administration, Secure engineering workstation access, Authentication for industrial systems, and Identity boundaries between IT and OT.
· Perform cybersecurity architecture risk assessments for operational technology initiatives.
· Identify architectural risks associated with industrial modernization.
· Develop compensating controls where operational constraints exist.
· Evaluate cybersecurity impacts on operational reliability and safety.
· Provide architectural guidance supporting OT threat detection.
· Collaborate with Security Operations during OT security incidents.
· Support forensic investigations involving industrial systems.
· Improve visibility into industrial cybersecurity events.
· Recommend architecture improvements following incident reviews.
· Evaluate emerging OT cybersecurity technologies.
· Lead proof-of-concept evaluations.
· Present architecture recommendations to executive leadership and engineering stakeholders.
· Ensure architectural alignment with:
o NIST Cybersecurity Framework (CSF)
o ISA/IEC 62443
o SOX
o CIS Critical Security Controls
· Partner closely with Enterprise Architecture, Infrastructure Services, Network Engineering, Cloud Engineering, Security Operations, Identity & Access Management, Operations Technology (OT), Refinery Engineering, Third- party vendors and Application Development.
SUCCESS MEASURES
· Highly available and resilient Operational Technology environments.
· Successful implementation of secure IT/OT architecture principles.
· Reduced cybersecurity risk across pipeline and terminal operations.
· Effective segmentation between enterprise and industrial networks.
· Increased visibility into OT assets and cybersecurity events.
· Successful completion of cybersecurity assessments and regulatory audits with minimal findings., Essential cookies enable basic functions and are necessary for the proper function of the website. Name, This cookie is used to identify a unique visitor to enhance the user experience by enabling personalized features and content based on the visitor’s preferences and browsing history. 4 weeks ipaddress This cookie is used to store the IP address of the visitor to facilitate website functionality by providing a more personalized experience. 1 day Cookie Preferences This cookie is used to store the user’s cookie consent preferences. 30 days Statistics
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website. Google Analytics
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window) Name, Duration gali Used by Google Analytics to determine which links on a page are being clicked 30 seconds _ga ID used to identify users 2 years gid ID used to identify users for 24 hours after last activity 24 hours _gat Used to monitor number of Google Analytics server requests when using Google Tag Manager 1 minute _gac Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together. 90 days __utma ID used to identify users and sessions 2 years after last activity __utmt Used to monitor number of Google Analytics server requests 10 minutes __utmb Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server. 30 minutes after last activity __utmc Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session. End of session (browser) __utmz Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server 6 months after last activity __utmv Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server. 2 years after last activity __utmx Used to determine whether a user is included in an A / B or Multivariate test. 18 months _ga ID used to identify users 2 years Cookie Policy
Requirements
· Bachelor’s degree in Cybersecurity, Computer Science, Engineering, Information Systems, Industrial Engineering, Electrical Engineering, or a related field; or equivalent combination of education and experience.
· 8+ years of experience in Operational Technology (OT), Industrial Control Systems (ICS), or industrial cybersecurity.
· 3+ years designing enterprise or industrial cybersecurity architectures.
· Experience securing pipeline, terminal, refinery, manufacturing, or critical infrastructure environments.
· Experience with SCADA systems, PLCs, HMIs, RTUs, and industrial communication protocols.
· Experience designing secure industrial network architectures.
· Experience implementing network segmentation between IT and OT environments.
· Experience working with industrial control system vendors and engineering teams.
· Experience supporting highly available operational environments where uptime and safety are critical.
PREFERRED CERTIFICATIONS
· ISA/IEC 62443 Cybersecurity Certificate
· CISSP
· Certified Information Security Manager (CISM)
· Microsoft Certified: Cybersecurity Architect Expert (SC-100)
· Cisco Certified Network Professional (CCNP) Security
· Fortinet NSE Certification, · Develop and maintain the enterprise Operational Technology cybersecurity architecture.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Paying Jobs in Technology
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Is Software Engineering Over-Saturated?
Dev Digest 134 - Where pixels sing?