
Search by job, company or skills
Role: Senior IT/OT Network Architect
Experience: 12+ Years
Location: Bangalore
Work Mode: Hybrid
We are seeking a Senior IT/OT Network Architect with deep expertise in Layer 2/Layer 3 networking, industrial (OT) segmentation, and secure AWS hybrid connectivity. This role serves as the technical authority for designing resilient plant-floor networks and the secure cloud/VPN architecture interconnecting global sites.
Key Responsibilities
Design industrial plant-floor (OT) networks with proper segmentation and security zoning
Architect secure site-to-site connectivity between plants, data centers, and AWS
Own AWS cloud network architecture:
VPC design, public/private subnets, route tables
Internet Gateway, NAT Gateway
Transit Gateway, Direct Connect, Site-to-Site VPN
Deploy and integrate virtual firewalls on EC2 (Cisco FTD / Palo Alto VM-Series / FortiGate)
Deploy virtual routers (Cisco CSR1000V / VyOS) with BGP peering in AWS
Define DMZ, segmentation, and firewall architecture using Cisco ASA / FTD / FMC
Implement Zero Trust Architecture (Zscaler / Cisco ZTA) replacing legacy VPN
Configure and govern AWS security controls:
Security Groups, NACLs, AWS Network Firewall
VPC Flow Logs, CloudTrail
Ensure alignment with industrial and security standards:
IEC 62443, NIST CSF, ISO 27001, Purdue Model, NERC CIP (awareness)
Review designs, mentor engineers, and drive technical decisions across teams
Communicate architecture to executives, customers, and compliance stakeholders
Required Experience
12-18 years in Network Engineering / Network Architecture
Proven ownership of architecture decisions (not only operations/support)
Hands-on experience designing networks in real production environments
Strong exposure to industrial/OT environments is highly preferred
Mandatory hands-on experience with AWS networking
Mandatory Technical Skills:
Networking (L2/L3)
VLANs, STP, BGP, OSPF, VRF, routing protocols
Firewall & Security Architecture
Cisco ASA / FTD / FMC
DMZ design and network segmentation
Zero Trust
Zscaler (ZIA/ZPA) or Cisco ZTA
MFA, privileged access
AWS Cloud Networking (Mandatory)
VPC, EC2, Transit Gateway, Direct Connect
Virtual firewall, virtual router deployments
Standards Awareness (Conceptual)
IEC 62443, NIST CSF, ISO 27001, Purdue Model, NERC CIP
Preferred Certifications
Job ID: 145752397