04 ago
|
SwiftCruit
|
Madrid
ph3Key Responsibilities /h3 pResponsibilities include but are not limited to: /p h31. Network Architecture Segmentation /h3 ul lipDefine and own secure OT network architecture aligned to IEC 62443 zone and conduit models utilising firewalls and data diodes. /p /li lipEstablish defense-in-depth architecture across OT, IT/OT DMZ, safety systems and remote access zones. /p /li lipDefine secure connectivity for OT–IT, OT–Cloud and vendor integrations. /p /li lipReview and approve OT network changes for cyber-physical risk impact. /p /li lipIntegrate identity-aware networking and Zero Trust principles where operationally feasible. /p /li lipOversee firewall rule lifecycle management, including review, validation, documentation and periodic recertification. /p /li lipEnsure firewall configurations support deterministic traffic, legacy protocols and high availability requirements in OT environments. /p /li /ul h32. Remote Access (Internal Third Party) /h3 ul lipArchitect and govern secure remote access solutions for OT environments, including vendor and contractor access. /p /li lipEnsure all remote access is identity-based, least-privilege, monitored and auditable. /p /li lipDefine secure patterns for jump hosts, architectures and privileged session management. /p /li lipEnforce segmentation and time-bound access for remote connections to OT assets. /p /li lipAlign remote access controls with safety, availability and regulatory requirements. /p /li lipEstablish incident-ready remote access capabilities, including rapid isolation and revocation. /p /li /ul h33. Identity Access Management (IAM) /h3 ul lipDefine OT-specific IAM architecture and control models aligned with risk tolerance.
/p /li lipAbility to identify and mitigate potential security risks and vulnerabilities related to identity and access management. /p /li lipGovern the use of Active Directory and directory services in OT, including trust relationships and segmentation boundaries. /p /li lipEnsure strong authentication (e.g., MFA, certificates) for privileged and remote OT access, adapted to operational constraints. /p /li lipDefine and oversee Identity Governance Administration (IGA) processes for OT users, vendors and service accounts. /p /li lipArchitect and govern Privileged Access Management (PAM) for engineering systems, administrators and service accounts. /p /li lipManage machine and non-human identities, including certificates, keys and service accounts. /p /li lipEnsure identity controls support availability, safety and incident response requirements. /p /li /ul h34. Data Management (Security Access Focused) /h3 ul lipDefine and govern secure OT data flows across zones, conduits and trust boundaries. /p /li lipEnsure OT data access is identity-controlled, role-based and least-privilege. /p /li lipDesign and approve architectures for OT data integration (historians, cloud platforms etc). /p /li lipEnsure encryption, integrity and secure transport for OT data in transit. /p /li lipSupport data classification and risk assessment for safety-critical and regulated OT data. /p /li lipEnsure data architectures do not compromise operational availability or safety. /p /li /ul h35. Crossover Responsibilities /h3 ul lipTranslate OT cyber risks into business, safety and operational risk language. /p /li lipSupport audits, regulatory assessments, and assurance activities related to OT cyber risk. /p /li lipAct as a bridge between engineering, operations, IT and security teams. /p /li /ul /p #J-18808-Ljbffr
📌 Global OT Security Architect – Identity & Networks (Madrid)
🏢 SwiftCruit
📍 Madrid