OT Cybersecurity Architect

Plexus

Neenah (WI)

Hybrid

USD 129,500 - 194,300

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Plexus is seeking an OT Cybersecurity Architect to bridge IT security with OT/ICS environments. You will define secure architectures, standards, and risk-management frameworks across manufacturing sites to protect uptime and safety.

The role requires deep knowledge of industrial protocols and governance, plus experience with legacy systems and secure remote access. Hybrid work is offered, with up to 25–30% travel to sites.

Qualifications

  • 8–10 years in cybersecurity with 4+ years OT/ICS architecture/engineering.
  • Bachelor's degree in Electrical/Computer Engineering, CS, or related field.
  • Experience in large-scale heavy industrial environments.
  • Knowledge of Modbus, Profinet, EtherNet/IP, DNP3, OPC UA.
  • ISA/IEC 62443, ISO 27001, NIST SP 800‑82, Purdue Model.

Responsibilities

  • Define OT Security Architecture using Purdue Model and ISA/IEC 62443.
  • Network Segmentation with iDMZs, firewalls, and micro-segmentation.
  • Roadmap and selection of OT security tools for ICS/SCADA environments.
  • Establish governance and standards for PLCs, SCADA, DCS, HMIs, and OT assets.
  • Bridge IT/Security with Plant Engineering to translate risks for leadership.
  • Lead Architecture Review Board for OT projects and security policies.
  • Vendor management with major automation vendors for secure access.
  • Lead threat modeling and risk assessments across sites for remediation.
  • Coordinate incident response logging and playbooks with SOC.

Skills

OT/ICS security
Industrial protocols
Security standards
Zero-trust remote access
Threat modeling

Education

Bachelor's degree in Electrical/Computer Engineering or CS

Job description

Our commitment to pay range transparency fosters an equitable workplace, where everyone can feel valued. The annual compensation range for this position is stated below. The salary offered within this range will be based upon the geographic location, work experience, education, licensure requirements and/or skill level.

Salary Range:
$129,500.00 - $194,300.00

At Plexus, lead technology-driven initiatives as part of a winning team, focused on creating products that build a better world.

Position Overview

The OT Cybersecurity Architect is a strategic role responsible for bridging the gap between our corporate IT security standards and our physical Operational Technology (OT) environments. In this role, you will be the primary authority responsible for defining the security architecture, engineering standards, and risk management frameworks across our manufacturing environment and industrial control systems (ICS). You will ensure that our deterministic, safety-first production environments are resilient against modern cyber threats without compromising operational uptime or human safety.

Key Responsibilities
  • Define OT Security Architecture: Design, maintain, and govern a secure, standardized global OT cybersecurity architecture utilizing the Purdue Model and ISA/IEC 62443 frameworks.
  • Network Segmentation: Design robust Industrial Demilitarized Zones (iDMZs), firewalls, and micro‑segmentation strategies to securely separate IT enterprise networks from the OT environment.
  • Technology Roadmap: Evaluate, select, and architect OT‑specific security tools (e.g., asset discovery, passive network monitoring, endpoint protection for legacy systems, and industrial SIEM/SOC integration).
  • Governance & Standards: Establish and maintain enterprise‑wide OT security governance and standards for Programmable Logic Controllers (PLCs), SCADA systems, Distributed Control Systems (DCS), Human‑Machine Interfaces (HMIs), and other operational technologies relevant to manufacturing.
  • Bridge the IT/OT Divide: Act as the trusted liaison between Corporate IT/Security teams and Plant Engineering/Operations teams. Translate complex cyber risks into operational impacts for leadership.
  • Architecture Review Board (ARB): Lead architectural cyber strategy and review for all projects affecting OT assets, guarding against unmitigated threats to manufacturing uptime or changes that violate defined cybersecurity policies and safety protocols.
  • Vendor Management: Partner with major automation vendors to ensure third‑party systems and remote access connections comply with corporate security architecture.
  • Risk Assessments: Lead threat modeling and vulnerability assessments across disparate manufacturing sites, prioritizing remediation based on operational risk and safety impacts.
  • Incident Response Integration: Partner with the Enterprise Security Operations Center to architect OT‑specific logging, monitoring, and incident response playbooks that respect the realities of a live production environment.
Qualifications & Experience
  • Minimum of 8–10 years of experience in cybersecurity, with at least 4+ years dedicated explicitly to OT/ICS cybersecurity architecture or engineering.
  • Bachelor’s degree in Electrical Engineering, Computer Engineering, Computer Science, or a related technical field (or equivalent practical experience).
  • Proven experience working within large‑scale, heavy industrial environments (e.g., manufacturing, pharmaceuticals, utilities, chemicals, or oil & gas).
  • Deep understanding of proprietary and open industrial protocols (e.g., Modbus, Profinet, EtherNet/IP, DNP3, OPC UA).
  • Expert-level knowledge of ISA/IEC 62443, ISO 27001, NIST SP 800‑82, and the Purdue Model.
  • Proven ability to architect defense‑in‑depth approaches around legacy, unpatchable operating systems and embedded firmware without disrupting deterministic operations.
  • Experience designing zero‑trust or secure multi‑factor remote access solutions for internal engineers and third‑party OEMs.
Additional Qualifications
  • SANS GIAC: GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), or GCIP.
  • ISA/IEC 62443 Cybersecurity Design/Expert.
  • CISSP (Certified Information Systems Security Professional) with a strong portfolio of physical site experience.
  • Demonstrated proficiency in cloud-native architectures utilizing MQTT and other Pub/Sub methodologies.
Work Environment

Hybrid

Travel Requirements

Up to 25-30% travel to manufacturing/operational sites

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

OT Cybersecurity Architect
OT Cybersecurity Architect

Plexus Corp. • Neenah (WI)

Hybrid
USD 129,000 - 195,000
Medical, dental, and vision insurance
Paid time off
Retirement savings
+2
OT Cybersecurity Architect
OT Cybersecurity Architect

Plexus Corp • Neenah (WI)

Hybrid
USD 129,000 - 195,000
OT Cybersecurity Architect: Secure Industrial Control
OT Cybersecurity Architect: Secure Industrial Control

Plexus • Neenah (WI)

Hybrid
USD 129,000 - 195,000
OT Cybersecurity Engineer
OT Cybersecurity Engineer

LVI Associates • Baltimore (MD)

On-site
USD 110,000 - 150,000
Cyber Security Architect
Cyber Security Architect

TI Automotive • Auburn Hills (MI)

On-site
USD 100,000 - 130,000
OT Cybersecurity Architect (ICS / Mfg Security)
OT Cybersecurity Architect (ICS / Mfg Security)

Bull City Talent Group • Georgia

Hybrid
USD 150,000 - 230,000
OT Cybersecurity Architect - Industrial Control Security
OT Cybersecurity Architect - Industrial Control Security

Plexus Corp. • Neenah (WI)

Hybrid
USD 129,000 - 195,000
Medical, dental, and vision insurance
Paid time off
Retirement savings
+2
OT Cybersecurity Architect - ICS Security Lead (Hybrid)
OT Cybersecurity Architect - ICS Security Lead (Hybrid)

Plexus Corp • Neenah (WI)

Hybrid
USD 129,000 - 195,000
Prin Cybersecurity Specialist - Exempt
Prin Cybersecurity Specialist - Exempt

TALENT Software Services • Town of Texas (WI)

On-site
USD 95,000 - 120,000
OT Security Architect
OT Security Architect

IPolarity • United States

Hybrid
USD 150,000 - 190,000