OT Network Security Architect/SME

OT Network Security Architect/SME

Posted 1 day ago by Project Recruit

Negotiable
Undetermined
Hybrid
Birmingham, UK

Summary: The role of OT Network Security Architect/SME involves designing secure and scalable network solutions for Operational Technology (OT) environments, focusing on Zero Trust delivery programs. The position is hybrid, requiring attendance at the Coventry office 2-3 days a week, and is a temporary contract lasting over 6 months. The architect will engage in both strategic and hands-on governance of OT network initiatives. The role demands a strong background in network architecture and security practices within enterprise and OT contexts.

Key Responsibilities:

  • Update and modernise OT site network architecture, including the removal of unmanaged switches
  • Develop and maintain up-to-date site network drawings
  • Assess technology hosting capability across updated network environments
  • Select and design network segmentation tools and deploy them across relevant sites
  • Map existing networks and data flows to inform segmentation and security strategies
  • Define protect surfaces for critical assets within the OT network
  • Design and govern the rollout of OT Next-Generation Firewalls, including selection, trials, and phased implementation
  • Implement DNS security enhancements across the organisation
  • Select, trial, and implement Operational Technology (OT) Network Access Control tools
  • Lead phased rollouts of Network Access Control, including integration with updated site networks
  • Write strategic decision papers on Secure Service Edge (SSE) for leadership review and approval
  • Select, design, and deploy Zero Trust Network Access (ZTNA) and Remote Browser Isolation (RBI) capabilities
  • Oversee ZTNA implementation specifically for VPN access scenarios
  • Oversee Claroty Phase 2 rollout, including deployment of new telemetry sensors at Critical National Infrastructure (CNI) OT sites
  • Ensure telemetry solutions align with architectural governance standards and Zero Trust Architecture
  • Produce High-Level Designs (HLDs) and Low-Level Designs (LLDs) aligning with business and security requirements.
  • Provide solution costing and budget estimates
  • Present and defend designs to governance bodies (eg, Design Authority)
  • Provide architectural governance and assurance throughout delivery phases
  • Act as a subject matter expert and advisor to internal delivery teams

Key Skills:

  • Proven experience in enterprise and OT network architecture
  • Expertise in hybrid cloud environments and multi-cloud network design
  • Experience with network segmentation strategies and tools
  • Strong background in Next-Generation Firewall (NGFW) design and implementation
  • Experience designing and deploying NAC and ZTNA solutions
  • Familiarity with Secure Service Edge (SSE) and Remote Browser Isolation (RBI) concepts
  • Understanding of DNS security best practices
  • Knowledge of telemetry and security monitoring tools, including solutions like Claroty
  • Experience with architectural governance processes
  • CCNP, CCIE, CISSP (desirable)
  • Extensive experience on Palo Alto, FortiGate or Checkpoint firewalls (desirable)
  • Knowledge of NIS-R framework and Zero Trust (desirable)
  • Familiarity with Water/Utilities sector and Critical National Infrastructure (desirable)
  • Understanding of Purdue Model and typical OT systems such as PLC/HMI/SCADA (desirable)

Salary (Rate): undetermined

City: Coventry

Country: UK

Working Arrangements: hybrid

IR35 Status: undetermined

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

OT Network Security Architect/SME

Our client, a leading global supplier for IT services, requires an experienced OT Network Security Architect/SME to be based at their client's office in Coventry, UK.

This is a hybrid role - you can work remotely in the UK and attend the Coventry office 2-3 days per week .

This is a 6+ month temporary contract to start asap

Day rate: Competitive Market rate

This role is dedicated to supporting OT Zero Trust delivery programmes by designing secure, scalable network and security solutions across on-premises, hybrid, and multi-cloud environments. The role will involve both strategy and hands-on architectural governance, supporting Operational Technology (OT) network initiatives.

Key Responsibilities:

Network Architecture Design & Implementation:

  • Update and modernise OT site network architecture, including the removal of unmanaged switches
  • Develop and maintain up-to-date site network drawings
  • Assess technology hosting capability across updated network environments
  • Select and design network segmentation tools and deploy them across relevant sites
  • Map existing networks and data flows to inform segmentation and security strategies
  • Define protect surfaces for critical assets within the OT network
  • Design and govern the rollout of OT Next-Generation Firewalls, including selection, trials, and phased implementation
  • Implement DNS security enhancements across the organisation

Access Control & Zero Trust Security:

  • Select, trial, and implement Operational Technology (OT) Network Access Control tools
  • Lead phased rollouts of Network Access Control, including integration with updated site networks
  • Write strategic decision papers on Secure Service Edge (SSE) for leadership review and approval
  • Select, design, and deploy Zero Trust Network Access (ZTNA) and Remote Browser Isolation (RBI) capabilities
  • Oversee ZTNA implementation specifically for VPN access scenarios

Security Monitoring & Telemetry:

  • Oversee Claroty Phase 2 rollout, including deployment of new telemetry sensors at Critical National Infrastructure (CNI) OT sites
  • Ensure telemetry solutions align with architectural governance standards and Zero Trust Architecture

Architectural Governance & Strategy:

  • Produce High-Level Designs (HLDs) and Low-Level Designs (LLDs) aligning with business and security requirements.
  • Provide solution costing and budget estimates
  • Present and defend designs to governance bodies (eg, Design Authority)
  • Provide architectural governance and assurance throughout delivery phases
  • Act as a subject matter expert and advisor to internal delivery teams

Key Requirements:

  • Proven experience in enterprise and OT network architecture
  • Expertise in hybrid cloud environments and multi-cloud network design
  • Experience with network segmentation strategies and tools
  • Strong background in Next-Generation Firewall (NGFW) design and implementation
  • Experience designing and deploying NAC and ZTNA solutions
  • Familiarity with Secure Service Edge (SSE) and Remote Browser Isolation (RBI) concepts
  • Understanding of DNS security best practices
  • Knowledge of telemetry and security monitoring tools, including solutions like Claroty
  • Experience with architectural governance processes

Desirable:

  • CCNP, CCIE, CISSP
  • Extensive experience on Palo Alto, FortiGate or Checkpoint firewalls
  • Knowledge of NIS-R framework and Zero Trust
  • Familiarity with Water/Utilities sector and Critical National Infrastructure
  • Understanding of Purdue Model and typical OT systems such as PLC/HMI/SCADA

Due to the volume of applications received, unfortunately we cannot respond to everyone

If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.

Please do keep an eye on our website for future roles.