Search by job, company or skills

Network Security Architect

Fresher
Early Applicant
  • Posted 8 hours ago
  • Be among the first 10 applicants

Job Description

Job Description

Roles & Responsibilities :

We are seeking a Network Security Architect with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projects

Key Responsibilities

  • Represent OT network architecture with security and compliance, Connectivity architecture design and decision making

  • Define reference architectures standards and design frameworks for different OT networks

  • Responsible for designing, implementing, and governing secure, resilient, and scalable OT network architectures across industrial/manufacturing environments.

  • Develop HLD/LLD, network diagrams, IP addressing schemes, routing and firewall policies, and architecture standards

  • Analyze different products from OEMs and make the right decisions that fits with technical and commercial aspects

  • Lead Zero Trust adoption for OT environments (ZPA/ZIA, Cisco ZTA)

  • Drive architecture for multi-site, multi-region deployments

  • Define resiliency, redundancy, and failover strategies

  • Lead architecture reviews with Product, Cybersecurity, and Compliance

  • Influence vendor selection, technology standards, and long-term roadmaps

  • Work with cybersecurity teams on IDS/IPS, network monitoring, NAC, vulnerability management, and secure remote access.

  • Coordinate with enterprise IT Network teams for IT/OT convergence and secure remote access.


Qualifications

SKILLS Needed:

First preference: Juniper devices Second preference: Cisco devices

. Networking (L2/L3):Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols

. Firewall & Security:Cisco ASA / FTD / FMC, DMZ, Context design, segmentation

. Zero Trust:ZPA / ZIA / Cisco ZTA, MFA, privileged access

. Cloud - AWS (Mandatory):VPC, EC2, Transit Gateway, Direct Connect, virtual firewall

. Enterprise proxy solutions : Hands-on experience with (SOCKS5, Squid, HAProxy, NGINX, Zscaler, Blue Coat, or F5) for secure traffic forwarding and access control

. Standards (Awareness):IEC 62443, NIST CSF, ISO 27001, Purdue Model

. Certifications (Preferred):CCNP / CCIE, AWS Advanced Networking, CISSP

MUST-HAVE REQUIREMENTS

.Layer 2 / Layer 3 Networking -VLANs, STP, BGP, OSPF, VRF - must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)

.Firewall Architecture -Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design

.Zero Trust -Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA

.AWS Cloud Networking -VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 - mandatory, not optional

.Standards Awareness -Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level - does not need deep implementation experience

CLOUD NETWORKING DETAIL

Candidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.

.VPC & Subnets -Design public/private subnets, route tables, internet gateway, NAT gateway

.EC2 -Launch and configure instances, assign ENIs, Elastic IPs, IAM roles, Auto Scaling

.Virtual Firewall on EC2 -Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances

.Virtual Router on EC2 -Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS

.Connectivity -Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site

.Security -Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrail

STANDARDS - AWARENESS LEVEL IS ENOUGH

Candidate should be able to discuss these standards in an interview - not implement them from scratch.

IEC 62443:Industrial cybersecurity standard - security zones, conduits, and security levels

NIST CSF:Identify, Protect, Detect, Respond, Recover - risk-based security framework

ISO / IEC 27001:Information security management system (ISMS) - how security is governed

Purdue Model:Layered industrial network model - why OT/IT segmentation is designed in levels

NERC CIP:Power grid cybersecurity compliance - awareness is fine for energy sector projects

EXPERIENCE EXPECTATIONS - Mandatory

.Experience -10 to 12 years in network engineering

.Ownership -

. Architect secure OT/IT integration models aligned to IEC 62443

. Represent OT network architecture in customer, regulator, and executive discussions

. Drive architecture for multi-site, multi-region deployments

Has owned design and implementation decisions - not just followed instructions

.Leadership -Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above

.Communication -Comfortable speaking to executives, customers, and compliance teams

.Certifications:CCNP

].Certifications (Good-to-have) -CCIE, AWS Certified Advanced Networking, AWS Solutions Architect, CISSP

GOOD TO HAVE - NOT MANDATORY

.Any OT / SCADA exposure -even at project or client level

.Azure or GCP networking -as an addition to AWS

.Infrastructure as Code -Terraform, CloudFormation, or Ansible for network automation

QUALIFICATIONS

BTech / BCA / MCA

Experience:10 yrs - 12 yrs

More Info

Job Type:
Employment Type:

About Company

Job ID: 153173329

Beware of Scammers

We don’t charge money for job offers