OT Security Architect
Noida, Uttar Pradesh, India · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- há 1 hora
- Work mode
- In office
- Education
- Any graduate
- Eligibility
- Any graduate with relevant experience in IT/OT security architecture can apply.
- Resume
- Required to apply
Where you'll work
Job description
Overview
We are looking for a skilled OT Security Architect with strong expertise in Active Directory segmentation and Operational Technology (OT) security frameworks. This person will be responsible for designing and implementing secure Active Directory environments tailored to both IT and OT sectors, ensuring compliance with standards such as IEC 62443 and enabling secure interconnections between enterprise and industrial networks.
Primary Responsibilities
- Design and deploy dedicated OT Active Directory infrastructures according to security best practices.
- Establish secure trust relationships between separate IT and OT Active Directory forests when necessary.
- Create and manage Organizational Units, Group Policies, and security groups.
- Implement tiered administrative models dividing privileges into Tier 0, Tier 1, and Tier 2.
- Strengthen Domain Controllers by applying Microsoft baseline security configurations.
- Plan and enforce IT/OT identity segmentation based on the Purdue Model across zones including Enterprise IT, Industrial DMZ, Manufacturing, Control, and Safety Zones.
- Ensure secure integration of Active Directory authentication within OT networks with least-privilege access principles.
- Implement and support security controls aligned with IEC 62443 standards (specifically IEC 62443-2-1, 3-3, and 4-2).
- Support Identification & Authentication Control, Use Control, System Integrity, Restricted Data Flow, and Resource Availability security domains.
- Conduct gap analyses and recommend improvements for IEC 62443 compliance.
- Develop and manage Group Policy Objects covering USB restrictions, password policies, Windows Firewall, Credential Guard, Windows Defender, Remote Desktop restrictions, audit policies, and application allowlisting using tools like AppLocker or Windows Defender Application Control.
- Collaborate with OT teams to integrate Active Directory authentication with SCADA, HMI, Historians, Engineering Workstations, OPC Servers, and MES platforms.
- Support identity integration on industrial platforms such as Siemens, Rockwell Automation, Schneider Electric, Honeywell, Emerson, and Yokogawa.
Additional Information
Immediate joiners within 0-30 days are preferred for this position. Interested candidates should share their updated CV promptly.
Eligibility
The role is open to any graduate possessing relevant expertise in IT/OT security architecture.