Must Have Technical/Functional Skills
• Proven experience defining OT/ICS security architectures for manufacturing, engineering, research, laboratory, supply-chain, overhaul, repair, assembly, or test environments.
• Hands-on architecture experience for IT/OT network segmentation, zones and conduits, industrial DMZs, secure remote access, firewalls, switching, load balancing, and passive OT monitoring.
• Ability to lead site discovery, current-state assessment, architecture-gap analysis, target-state design, design reviews, implementation governance, validation, stabilization, and operational handover.
• Experience developing and approving High-Level Designs, Low-Level Designs, network and data-flow diagrams, bills of materials, security patterns, implementation roadmaps, technical standards, and architecture decision records.
• Strong knowledge of IEC 62443, NIST SP 800-82, Purdue-model concepts, Zero Trust principles, least privilege, defense in depth, and secure change practices for operational environments.
• Knowledge of OT assets and protocols, including PLCs, HMIs, SCADA, historians, engineering workstations, industrial servers, network appliances, and industrial communications.
• Architecture knowledge of Nozomi Guardian/CMC or similar OT visibility platforms, Check Point and Palo Alto firewalls, Cisco or industrial switching, Zscaler, CyberArk, Splunk, ServiceNow, and CMDB integrations.
• Experience assessing security impact and operational risk for live-environment changes, including availability, safety, production continuity, rollback, testing, outage, and maintenance-window considerations.
• Experience establishing architecture governance, conducting design assurance and peer reviews, managing technical risks and exceptions, and ensuring alignment with customer policies and approved reference architectures.
• Experience supporting build and managed-service teams across incidents, vulnerabilities, changes, lifecycle refresh, platform optimization, compliance, and continuous improvement.
• Working knowledge of ITAR/export-control requirements, CUI or EC environments, RBAC, segregation of duties, secure administration, and evidence requirements.
• Relevant certifications such as CISSP, GICSP, GRID, IEC 62443, TOGAF, SABSA, or vendor architecture certifications are preferred.
Roles & Responsibilities
• Own and govern the OT security architecture for Secure Connected Shops and related OT network services across assigned sites and delivery towers.
• Lead discovery and assessment of existing IT/OT networks, assets, security controls, connectivity, data flows, remote-access paths, operational dependencies, and architecture gaps.
• Define target-state OT security architecture and site patterns covering segmentation, zones and conduits, industrial DMZs, firewalls, switching, load balancing, secure remote access, monitoring, logging, and management connectivity.
• Create, review, approve, and maintain HLDs, LLDs, Visio network diagrams, data-flow diagrams, bills of materials, implementation timelines, architecture standards, design patterns, and configuration requirements.
• Ensure proposed designs and changes align with approved customer architectures, cybersecurity policies, implementation processes, ITAR/export-control boundaries, and applicable OT-security practices.
• Provide architecture oversight to network, OT, firewall, Nozomi, Zscaler, CyberArk, cloud, infrastructure, SOC, and site implementation teams throughout build and rollo ut.
• Review changes proposed for live OT environments and evaluate security, safety, availability, production, dependency, testing, rollback, and maintenance-window risks before implementation.
• Chair or support architecture and design reviews, document decisions, technical debt, risks, exceptions, assumptions, and dependencies, and drive remediation to closure.
• Validate implementation against the approved design through design assurance, configuration review, evidence checks, testing support, and as-built documentation review.
• Support incident, vulnerability, problem, and major-change investigations where architecture analysis or cross-domain technical leadership is required.
• Define reusable templates, playbooks, guardrails, standards, and reference patterns to enable consistent execution across global sites and delivery pods.
• Guide operational readiness, stabilization, knowledge transfer, SOP development, monitoring requirements, support-model definition, and handover to L1/L2/L3 operations.
• Collaborate with site IT/OT, engineering, facilities, maintenance, network, cybersecurity, compliance, business-validation, vendor, and governance stakeholders.
• Identify architecture optimization and continuous-improvement opportunities while preserving operational resilience, regulatory compliance, and production continuity.
Generic Managerial Skills, If any
Strong architecture leadership, stakeholder influence, workshop facilitation, technical writing, design governance, risk-based decision-making, and ability to translate complex OT security requirements into executable site designs and standards.
Salary Range: $120,000 - $140,000 per year
TCS Employee Benefits Summary:
Discretionary Annual Incentive.
Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
Family Support: Maternal & Parental Leaves.
Insurance Options: Auto & Home Insurance, Identity Theft Protection.
Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
Time Off: Vacation, Time Off, Sick Leave & Holidays.
Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
More Information
Application Details
- Organization DetailsTCS / Tata Consultancy Services


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.