Staff Cybersecurity Architect - OTPosition SummaryThe OT Security Architect helps define and implement the cybersecurity strategy, architecture, and controls that protect Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and Industrial IoT (IIoT) environments.
This role works with plant operations, engineering, infrastructure, cybersecurity, and third-party vendors to secure industrial systems and align them with business, safety, reliability, and regulatory requirements. The OT Security Architect provides technical leadership for OT security architecture, site assessments, monitoring, incident response, and cybersecurity improvement initiatives across global operational sites.
This position reports to the Chief Information Security Officer and requires up to
25% travel.Key ResponsibilitiesOT Security Architecture & Design- Develop and maintain enterprise OT cybersecurity architecture standards, reference architectures, diagrams, and technical guidance aligned with ISA/IEC 62443, NIST 800-82, NIST CSF, and industry best practices.
- Design secure OT network architectures, including segmentation strategies, Purdue Model implementation, industrial DMZs, remote access controls, and zero trust principles.
- Review and approve OT system designs, modernization projects, and digital transformation initiatives.
OT Security Assessments- Conduct OT/ICS cybersecurity assessments, including risk assessments, architecture reviews, threat modeling, and maturity evaluations.
- Identify architectural and program security gaps and develop remediation roadmaps with site leadership and engineering teams.
OT Monitoring & Detection- Lead deployment and optimization of OT monitoring, asset discovery, and industrial threat detection platforms.
- Develop OT-specific use cases, dashboards, alerting strategies, and detection content.
Incident Response & Recovery- Support investigation, containment, eradication, and recovery for OT cyber events coordinated with security operations teams.
- Develop OT-specific incident response playbooks and recovery procedures.
- Participate in tabletop exercises, cyber simulations, and resilience testing.
Vulnerability & Risk Management- Lead OT vulnerability identification, prioritization, and remediation activities.
- Assess security impacts of patches and mitigations in operational environments.
- Balance cybersecurity needs with operational availability and safety.
- Track and report OT vulnerability and remediation metrics to security leadership.
Governance, Compliance & Leadership- Develop relationships and partner with audit, risk, engineering, and operations teams to demonstrate program effectiveness and support compliance.
- Provide OT cybersecurity subject matter expertise, technical leadership, and mentorship.
- Support vendor evaluations, system integrations, and cybersecurity requirements for new projects.
- Communicate OT cybersecurity risks, architecture decisions, and strategic recommendations to executive and business stakeholders.
Required QualificationsEducation- Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related fields. Equivalent experience will be considered.
Experience- 5+ years of cybersecurity, IT, or engineering experience. Preference given for candidates with exposure to manufacturing/industrial environments + those with OT/ICS cybersecurity experience
- Experience conducting OT cybersecurity assessments and architecture reviews.
- Experience supporting or leading OT cybersecurity incident response.
Technical Skills & Competencies- Strong understanding of industrial control systems and OT networking.
- Hands-on experience with OT security monitoring and detection tools.
- Knowledge of OT threats, attack techniques, and industrial risk management.
- Strong writing, presentation, relationship building, and communication skills.
Preferred Qualifications- Experience with OT monitoring platforms such as Nozomi, Claroty, Dragos, Armis, Microsoft Defender for IoT, or similar tools.
- Knowledge of industrial protocols including Modbus, DNP3, OPC-UA, PROFINET, EtherNet/IP, BACnet, and IEC 61850.
- Experience with firewalls, network segmentation, IDS/IPS, secure remote access, and industrial DMZ architectures.
- Ability to utilize scripting and automation for process improvements
- Experience working in manufacturing, rail, transportation, or critical infrastructure environments
- Experience conducting cyber tabletop exercises and recovery testing.
Preferred Certifications- GICSP (GIAC Global Industrial Cyber Security Professional)
- GRID (GIAC Response and Industrial Defense)
- CISSP
- ISA/IEC 62443 Cybersecurity Certification
- CISM
- CISA
QualificationsAdditional InformationOur job titles may span more than one career level. The salary rate for this role is currently $[redacted]00 The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include annual bonus, if eligible.