Must Have Technical/Functional Skills
- Proven experience defining OT/ICS security architectures for manufacturing, engineering, research, laboratory, supply-chain, overhaul, repair, assembly, or test environments.
- Hands-on architecture experience for IT/OT network segmentation, zones and conduits, industrial DMZs, secure remote access, firewalls, switching, load balancing, and passive OT monitoring.
- Ability to lead site discovery, current-state assessment, architecture-gap analysis, target-state design, design reviews, implementation governance, validation, stabilization, and operational handover.
- Experience developing and approving High-Level Designs, Low-Level Designs, network and data-flow diagrams, bills of materials, security patterns, implementation roadmaps, technical standards, and architecture decision records.
- Strong knowledge of
IEC 62443, NIST SP
800-82, Purdue-model concepts, Zero Trust principles, least privilege, defense in depth, and secure change practices for operational environments.
- Knowledge of OT assets and protocols, including PLCs, HMIs, SCADA, historians, engineering workstations, industrial servers, network appliances, and industrial communications.
- Architecture knowledge of Nozomi Guardian/CMC or similar OT visibility platforms, Check Point and Palo Alto firewalls, Cisco or industrial switching, Zscaler, CyberArk, Splunk, ServiceNow, and CMDB integrations.
- Experience assessing security impact and operational risk for live-environment changes, including availability, safety, production continuity, rollback, testing, outage, and maintenance-window considerations.
- Experience establishing architecture governance, conducting design assurance and peer reviews, managing technical risks and exceptions, and ensuring alignment with customer policies and approved reference architectures.
- Experience supporting build and managed-service teams across incidents, vulnerabilities, changes, lifecycle refresh, platform optimization, compliance, and continuous improvement.
- Working knowledge of ITAR/export-control requirements, CUI or EC environments, RBAC, segregation of duties, secure administration, and evidence requirements.
- Relevant certifications such as
CISSP, GICSP, GRID, IEC
62443, TOGAF, SABSA, or vendor architecture certifications are preferred. Roles & Responsibilities
- Own and govern the OT security architecture for Secure Connected Shops and related OT network services across assigned sites and delivery towers.
- Lead discovery and assessment of existing IT/OT networks, assets, security controls, connectivity, data flows, remote-access paths, operational dependencies, and architecture gaps.
- Define target-state OT security architecture and site patterns covering segmentation, zones and conduits, industrial DMZs, firewalls, switching, load balancing, secure remote access, monitoring, logging, and management connectivity.
- Create, review, approve, and maintain HLDs, LLDs, Visio network diagrams, data-flow diagrams, bills of materials, implementation timelines, architecture standards, design patterns, and configuration requirements.
- Ensure proposed designs and changes align with approved customer architectures, cybersecurity policies, implementation processes, ITAR/export-control boundaries, and applicable OT-security practices.
- Provide architecture oversight to network, OT, firewall, Nozomi, Zscaler, CyberArk, cloud, infrastructure, SOC, and site implementation teams throughout build and rollo ut.
- Review changes proposed for live OT environments and evaluate security, safety, availability, production, dependency, testing, rollback, and maintenance-window risks before implementation.
- Chair or support architecture and design reviews, document decisions, technical debt, risks, exceptions, assumptions, and dependencies, and drive remediation to closure.
- Validate implementation against the approved design through design assurance, configuration review, evidence checks, testing support, and as-built documentation review.
- Support incident, vulnerability, problem, and major-change investigations where architecture analysis or cross-domain technical leadership is required.
- Define reusable templates, playbooks, guardrails, standards, and reference patterns to enable consistent execution across global sites and delivery pods.
- Guide operational readiness, stabilization, knowledge transfer, SOP development, monitoring requirements, support-model definition, and handover to
L1/L2/L3
operations.
- Collaborate with site IT/OT, engineering, facilities, maintenance, network, cybersecurity, compliance, business-validation, vendor, and governance stakeholders.
- Identify architecture optimization and continuous-improvement opportunities while preserving operational resilience, regulatory compliance, and production continuity.
Generic Managerial Skills, If any Strong architecture leadership, stakeholder influence, workshop facilitation, technical writing, design governance, risk-based decision-making, and ability to translate complex OT security requirements into executable site designs and standards.
Salary Range:
$120,000 - $140,000 per year
TCS Employee Benefits Summary:
Discretionary Annual Incentive.
Comprehensive Medical Coverage:
Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
Family Support:
Maternal & Parental Leaves.
Insurance Options:
Auto & Home Insurance, Identity Theft Protection.
Convenience & Professional Growth:
Commuter Benefits & Certification & Training Reimbursement.
Time Off:
Vacation, Time Off, Sick Leave & Holidays.
Legal & Financial Assistance:
Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.