Job Title: OT Network Segmentation & Security Architect
Location: Florencevile, Canada
Job Type: Full-Time Permanent
Must Have Technical/Functional Skills:
OT Operations & Manufacturing Systems Expertise
- 10+ years of experience supporting industrial/manufacturing environments.
- Hands-on knowledge of SCADA, HMI, Historian/PI systems, FactoryTalk, ThinManager, OT infrastructure, virtualization, backup/recovery, and industrial networking.
OT Cybersecurity Knowledge
- Strong understanding of ISA/IEC 62443 standards and OT security principles.
- Experience with SOC interactions, incident response, secure remote access, privileged access management (PAM), and Zero Trust security controls.
Identity & Access Management (IAM)
- Hands-on experience with Active Directory, Group Policy, DNS, DHCP, Microsoft Entra ID, MFA, Conditional Access, and enterprise IAM operations.
- Experience in IT/OT identity separation environments is highly desirable.
Cloud & Azure Operations
- Understanding of Azure infrastructure, Landing Zones, subscriptions, policies, vWAN, and cloud operations/support models.
- Ability to define operational runbooks and support frameworks for cloud platforms.
GitOps & Automation Literacy
- Working knowledge of Git-based workflows including pull requests, branch protections, approval gates, and GitOps operating models.
- Ability to design and document operational procedures around GitOps-driven identity management.
Roles & Responsibilities:
- Own Operational Readiness & Service Transition
- Ensure all OT solutions are supportable in production, define operational acceptance criteria, transition plans, and manage hypercare through BAU acceptance.
- Design OT Service Management Framework
- Lead the design of OT-specific ServiceNow processes including incident, request, access, change, problem, and knowledge management workflows.
- Establish OT Support & Service Coverage Model
- Build the support operating model, including business-hours support, on-call escalation, SLAs, incident response processes, and future 24x7/follow-the-sun support blueprint.
- Drive Operational Governance & Reporting
- Define governance structure, RACIs, escalation paths, KPIs, dashboards, service reviews, and ensure complete operational visibility through ServiceNow.
- Operationalize Identity, GitOps & Cloud Services
- Convert OT identity, GitOps, and Azure platform designs into sustainable operating procedures, runbooks, monitoring, and support models.
- Lead Monitoring, Incident Readiness & Cyber Response Coordination
- Define monitoring requirements, alert ownership, incident workflows, escalation procedures, and ensure readiness across OT, SOC, and security teams.
- Build the Plant Onboarding & Hypercare Factory
- Create a repeatable onboarding model for OT plants, including readiness checklists, deployment standards, stabilization support, and lessons learned for global rollout.
- Act as the MSP’s OT Operations Authority
- Serve as the embedded operational architect within the program team, influencing design decisions, challenging non-operable solutions, coordinating stakeholders, and ensuring scalable, supportable OT operations.