Job Summary
We are seeking an experienced Integration & Security Architecture Engineer with strong expertise in API integration, security architecture, cloud and hybrid deployments, physical access control systems, OT/plant networks, and cybersecurity. The ideal candidate will have experience integrating Physical Access Control Systems (PACS) with HR, identity, payroll, time and attendance, and ERP platforms while ensuring secure, resilient, and compliant system architectures.
Key Responsibilities
• Design and implement API integrations using REST, webhooks, event streaming, and OAuth 2.0.
• Integrate Physical Access Control Systems (PACS) with enterprise platforms and APIs, including OnGuard OpenAccess, Genetec SDK, and C• CURE APIs.
• Design and implement integrations between PACS and HR/identity systems such as Workday, Active Directory, and Entra ID to support automated employee onboarding and offboarding.
• Integrate badge events with payroll, time and attendance, and ERP platforms such as SAP, UKG, and ADP.
• Design cloud and hybrid architectures supporting SaaS deployments, high availability, failover, and disaster recovery.
• Design data synchronization and reconciliation processes to ensure data integrity following system outages or connectivity failures.
• Design and implement OT and plant network architectures, including network segmentation, firewall configuration, and PoE connectivity for physical security devices.
• Apply cybersecurity hardening practices to physical security systems, including device certificates, encryption, patching, and tamper protection.
• Ensure video and badge data architectures support applicable data privacy, security, and regional data residency requirements.
• Apply ISO 27001/27002 and ISO 22340 principles to system architecture, security controls, and configuration.
• Develop scripts and automation using Python and PowerShell to support data migration, bulk cardholder operations, and system administration.
• Evaluate vendor technical solutions and capabilities through RFI/RFP processes and proof-of-concept testing.
• Collaborate with security, infrastructure, HR, identity, networking, OT, compliance, and business teams to define and implement secure integration solutions.
• Troubleshoot integration, security, network, synchronization, and operational issues across enterprise and physical security environments.
• Develop technical architecture documentation, integration specifications, security designs, and operational procedures.
Required Qualifications
• Strong API integration expertise with REST, webhooks, event streaming, and OAuth 2.0.
• Experience working with PACS technologies and APIs such as OnGuard OpenAccess, Genetec SDK, and C• CURE APIs.
• Experience integrating PACS with HR and identity platforms such as Workday, Active Directory, and Entra ID.
• Experience integrating badge events with payroll, time and attendance, or ERP platforms such as SAP, UKG, and ADP.
• Experience designing SaaS and hybrid cloud architectures, including failover and data synchronization/reconciliation.
• Strong OT and plant network experience, including network segmentation, firewalls, PoE, and industrial security device connectivity.
• Experience hardening physical security systems using device certificates, encryption, patching, and tamper protection.
• Knowledge of data privacy and compliance requirements for video and badge data, including GDPR and regional data residency.
• Working knowledge of ISO 27001/27002 and ISO 22340 and the ability to translate security controls into system configurations.
• Scripting and automation experience using Python and PowerShell.
• Experience supporting data migration and bulk cardholder operations.
• Strong vendor technical evaluation experience, including RFI/RFP assessment and proof-of-concept testing.
• Strong analytical, troubleshooting, communication, and stakeholder management skills.