We are looking for an
OT Security Architectto join our team in one of todays most exciting technologies.This role will report to
Chief Security Officer based in
Newark, Delaware. This is a fully on-site,5 daysin office role.
Role and Responsibilities
- Deploy, configure, and tune OT security platformsacross manufacturing sites endpoint protection, inline IPS, asset discovery, secure remote access, media scanning kiosks, and PLC backup including rulesets, allowlists, exclusions, and detection tuning on production assets.
- Own operational health of deployed tooling:agent coverage, sensor health, license utilization, upgrades, and version currency.
- Design and implement IT/OT convergence controls:OT DMZ at Level 3.5, brokered access, data flows, identity and directory integration, patching paths, and monitoring feeds.
- Implement defense-in-depth segmentationaligned to the Purdue model and ISA/IEC 62443 zone-and-conduit design, VLANs and rulesets, micro segmentation, and virtual patching for legacy assets partnering with Network Engineering on switching, routing, firewalls, wireless, IIoT, edge, and WAN.
- Run OT asset discovery and integrate telemetry into enterprise SIEM, EDR/XDR, NDR, and vulnerability management;maintain inventory and drive end-of-life OS remediation.
- Implement and test PLC/HMI backup, versioning, and golden-image recovery;support OT incident response and recovery, and lead POCs and production rollouts for new OT security technologies.
Skills and Experience
- Bachelors degree in Cybersecurity, Computer Science, Electrical Engineering, Industrial Engineering, Computer Engineering, or a related technical discipline, or equivalent hands-on experience.
- 8+ years of cyber security, network, or infrastructure engineering experience, including 4+ years hands-on OT/ICS cyber securityin productionindustrial or manufacturing environments.
- Demonstrated hands-on deployment and operation of OT security tooling at multiple sites.
- Strategy-only, advisory-only, or assessment-only backgrounds will not be considered.
Preferred Qualifications and Technologies
- Secure Remote Access:brokered vendor and engineer access to Levels 0 3, session recording, MFA, jump hosts, browser isolation
- Malware Scanning Kiosks:USB and vendor media inspection at plant entry points, scan engines, sanitization, and media workflows
- OT Endpoint Security:OT-native anti-malware and application allows listing on HMIs, engineering workstations, and legacy or unsupported OS
- OT Backup:PLC/HMI and production equipment configuration backup, version control, and testedgolden imagerestore on production assets
- Network Segmentation:OT DMZ at Level 3.5, zone-and-conduit design, VLAN-to-firewall migration,micro segmentation, inline IPS and virtual patching
- OT Vulnerability Management:passive and active OT asset discovery, risk-based prioritization, compensating controls for non-patchable assets
- Purdue Model:applied Levels 0 5 data-flow design and enforcement of trust boundaries across live plants
- TXOne,Claroty, Nozomi Networks, Dragos, Armis, KASM, Dispel, Salvador Technologies, OPSWAT,Octoplant, Cisco Cyber Vision / ISE / Catalyst IE, or equivalent OT security platforms.
- Enterprise security integration: SIEM, SOAR, XDR/EDR, NDR, PAM, and vulnerability management platforms.
- Windows and Linux server administration, Active Directory, virtualization, storage, backup, and hybrid cloud connectivity.
- Layer 2/3 switching and routing, VLANs, wireless,firewallrule design, NAT, VPN, and WAN connectivity.
- Scripting and automation (PowerShell, Python) for deployment, configuration management, and reporting at scale.
- PLC platforms (Siemens, Rockwell, Schneider, GE, ABB), SCADA, and HMI systems.
- Industrial protocols: Modbus, DNP3,Profinet, OPC/OPC-UA,EtherNet/IP, BACnet.
- Applied ISA/IEC 62443 and NIST SP 800-82: implementing controls, audit support, risk assessment, threat intelligence, and vulnerability management.
- Multi-site, multi-country manufacturing support experience; MES, historian, LIMS, and quality systems exposure.
- ERC CIP audit or utility customer cyber security requirement support.
- Certifications: GICSP, GRID, GCIP, GPPA, ISA/IEC 62443 Fundamentals or Specialist, CISSP, CCNP or equivalent.
- Ability to work safely on production floors, onsite in Delaware, with travel up to 25% and off-hours work during maintenance windows.
At Bloom Energy, we are committed to supporting the well-being of our employees and their families. Our comprehensive benefits package for eligible employees includes competitive Medical, Dental, and Vision plans with a large employer contribution, a 401(k) Retirement Plan with company match, generous Mental Health Support services, Legal services, virtual Physical Therapy access, and Fertility & Family Forming benefits.
Bloom Energy is committed to fair and equitable compensation practices. The total compensation for this position includes standard company benefits and is based on various factors including, but not limited to, relevant skills and experience.
Salary Ranges:$130,400.00 - $187,600.00