Cyber SDC - OT - Security Architect
Role details
Job location
Tech stack
Job description
Site-level architecture guidance, standards adherence, design validation, and technical risk advisory, Senior OT security architecture advisor supporting secure and supportable industrial environments, The Security Architect - OT role provides architecture guidance, design validation, and technical advisory support to help ensure OT environments are implemented and operated in alignment with established security requirements and approved design patterns., We are seeking an experienced Security Architect - Operational Technology (OT) to provide architecture guidance and technical oversight for industrial, manufacturing, laboratory, and operational technology environments.
This role supports site-level design reviews, network segmentation validation, secure connectivity planning, exception analysis, operational readiness, and risk-based technical decision-making. The architect works across cybersecurity, infrastructure, engineering, operations, and site teams to help ensure OT solutions are secure, supportable, and aligned to established standards.
Role positioning: This role applies and interprets established architecture standards rather than defining enterprise standards or performing routine day-to-day governance queue execution., Architecture Standards Adherence
- Apply established OT cybersecurity standards and approved design patterns to site-level implementations.
- Review proposed OT network, firewall, secure access, monitoring, and infrastructure designs for alignment with approved standards.
- Identify gaps between proposed implementations and established architecture requirements.
- Recommend practical remediation options for design constraints, exceptions, or operational support concerns.
Site-Level Design Review and Validation
- Support architecture reviews for site implementations, modernization activities, and operational changes.
- Validate alignment with segmentation, zoning, firewall, remote access, monitoring, and operational support expectations.
- Participate in design discussions for complex, high-risk, or non-standard OT implementations.
- Partner with engineering and operations teams to support transition of approved designs into steady-state support.
Risk and Exception Support
- Support technical risk assessments and impact analysis for non-standard architecture decisions.
- Provide technical input for exception reviews, risk acceptance discussions, and remediation planning.
- Escalate material design risks, control gaps, or operational concerns through appropriate governance channels.
- Ensure architecture decisions and risk outcomes are documented and supportable.
Secure Connectivity and Infrastructure Alignment
- Review secure connectivity patterns involving firewalls, remote access, segmentation controls, monitoring platforms, and related infrastructure.
- Support alignment of applicable Zero Trust principles to OT users, devices, applications, and remote access use cases.
- Advise on technical dependencies that may affect implementation, operations, lifecycle management, or supportability.
Operational Readiness and Technical Advisory
- Validate that designs include monitoring, alerting, documentation, support records, and escalation considerations.
- Support operational readiness discussions and post-implementation improvement activities.
- Provide senior technical advisory support for complex OT security architecture decisions.
- Develop reusable guidance, lessons learned, and implementation patterns based on site delivery experience., Security Architect - OT: Provides architecture guidance and technical oversight for operational technology environments, ensuring site-level implementations adhere to established cybersecurity standards, approved design patterns, network segmentation requirements, secure connectivity practices, monitoring expectations, and operational support needs. Supports design reviews, exception analysis, risk assessments, operational readiness, and transition into steady-state operations.
Requirements
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, Computer Science, or related field preferred.
- 8-10+ years of experience in cybersecurity, infrastructure, networking, industrial technology, or security architecture roles.
- 5+ years supporting OT, manufacturing, industrial, engineering, laboratory, or critical infrastructure environments.
- Strong understanding of network security, firewalls, segmentation, secure connectivity, remote access, and infrastructure support concepts.
- Experience reviewing technical designs against established architecture standards and operational requirements.
- Strong communication, documentation, stakeholder management, and risk-based decision-making skills., * Experience supporting manufacturing or industrial site environments.
- Knowledge of ICS and OT architectures, Purdue Model concepts, NIST CSF, and IEC 62443 concepts.
- Experience with firewall policy review, network segmentation, secure remote access, OT asset visibility, or security monitoring platforms.
- Relevant certifications such as CISSP, GICSP, GIAC, IEC 62443, Security+, Network+, or comparable security/network credentials.
TECHNICAL SKILLS
Architecture
Infrastructure
Operations
OT security architecture
Network segmentation
Operational readiness
Firewall policy architecture
Secure remote access
Risk assessment
Zero Trust principles
Industrial networking
Documentation and handoff
Security monitoring concepts
Routing and switching
Benefits & conditions
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
- We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.