Wabtec

Staff Cybersecurity Architect - OT

Wabtec Fort Worth, Texas, United States · $105K–$149K/yr

Railroad Equipment Manufacturing · 10,001+ employees

6 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The OT Security Architect defines and implements cybersecurity strategies to protect industrial control systems and operational technology environments. This role leads site assessments, threat detection deployments, and incident response initiatives while ensuring compliance with safety and regulatory standards.

What they look for

OT security architecture ICS security Cybersecurity strategy Network segmentation Threat detection Incident response Vulnerability management Risk assessment ISA/IEC 62443 NIST 800-82 Industrial IoT Purdue Model Zero trust Technical leadership Compliance Mentorship

Requirements

Candidates must have a bachelor's degree in a technical field and at least 5 years of experience in cybersecurity, IT, or engineering. Strong knowledge of industrial control systems, OT networking, and relevant security frameworks like ISA/IEC 62443 is required.

Benefits

Health insurance Welfare benefits Retirement plan Annual bonus

Full description

Job Description

Staff Cybersecurity Architect - OT

Position Summary

The OT Security Architect helps define and implement the cybersecurity strategy, architecture, and controls that protect Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and Industrial IoT (IIoT) environments.

This role works with plant operations, engineering, infrastructure, cybersecurity, and third-party vendors to secure industrial systems and align them with business, safety, reliability, and regulatory requirements. The OT Security Architect provides technical leadership for OT security architecture, site assessments, monitoring, incident response, and cybersecurity improvement initiatives across global operational sites.

This position reports to the Chief Information Security Officer and requires up to 25% travel.

Key Responsibilities

OT Security Architecture & Design

  • Develop and maintain enterprise OT cybersecurity architecture standards, reference architectures, diagrams, and technical guidance aligned with ISA/IEC 62443, NIST 800-82, NIST CSF, and industry best practices.
  • Design secure OT network architectures, including segmentation strategies, Purdue Model implementation, industrial DMZs, remote access controls, and zero trust principles.
  • Review and approve OT system designs, modernization projects, and digital transformation initiatives.

OT Security Assessments

  • Conduct OT/ICS cybersecurity assessments, including risk assessments, architecture reviews, threat modeling, and maturity evaluations.
  • Identify architectural and program security gaps and develop remediation roadmaps with site leadership and engineering teams.

OT Monitoring & Detection

  • Lead deployment and optimization of OT monitoring, asset discovery, and industrial threat detection platforms.
  • Develop OT-specific use cases, dashboards, alerting strategies, and detection content.

Incident Response & Recovery

  • Support investigation, containment, eradication, and recovery for OT cyber events coordinated with security operations teams.
  • Develop OT-specific incident response playbooks and recovery procedures.
  • Participate in tabletop exercises, cyber simulations, and resilience testing.

Vulnerability & Risk Management

  • Lead OT vulnerability identification, prioritization, and remediation activities.
  • Assess security impacts of patches and mitigations in operational environments.
  • Balance cybersecurity needs with operational availability and safety.
  • Track and report OT vulnerability and remediation metrics to security leadership.

Governance, Compliance & Leadership

  • Develop relationships and partner with audit, risk, engineering, and operations teams to demonstrate program effectiveness and support compliance.
  • Provide OT cybersecurity subject matter expertise, technical leadership, and mentorship.
  • Support vendor evaluations, system integrations, and cybersecurity requirements for new projects.
  • Communicate OT cybersecurity risks, architecture decisions, and strategic recommendations to executive and business stakeholders.

Required Qualifications

Education

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related fields. Equivalent experience will be considered.

Experience

  • 5+ years of cybersecurity, IT, or engineering experience. Preference given for candidates with exposure to manufacturing/industrial environments + those with OT/ICS cybersecurity experience
  • Experience conducting OT cybersecurity assessments and architecture reviews.
  • Experience supporting or leading OT cybersecurity incident response.

Technical Skills & Competencies

  • Strong understanding of industrial control systems and OT networking.
  • Hands-on experience with OT security monitoring and detection tools.
  • Knowledge of OT threats, attack techniques, and industrial risk management.
  • Strong writing, presentation, relationship building, and communication skills.

Preferred Qualifications

  • Experience with OT monitoring platforms such as Nozomi, Claroty, Dragos, Armis, Microsoft Defender for IoT, or similar tools.
  • Knowledge of industrial protocols including Modbus, DNP3, OPC-UA, PROFINET, EtherNet/IP, BACnet, and IEC 61850.
  • Experience with firewalls, network segmentation, IDS/IPS, secure remote access, and industrial DMZ architectures.
  • Ability to utilize scripting and automation for process improvements
  • Experience working in manufacturing, rail, transportation, or critical infrastructure environments
  • Experience conducting cyber tabletop exercises and recovery testing.

Preferred Certifications

  • GICSP (GIAC Global Industrial Cyber Security Professional)
  • GRID (GIAC Response and Industrial Defense)
  • CISSP
  • ISA/IEC 62443 Cybersecurity Certification
  • CISM
  • CISA

 

Additional Information

Our job titles may span more than one career level. The salary rate for this role is currently $104800-149300 The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include annual bonus, if eligible.

What could you accomplish in a place that puts People First?

At Wabtec, it’s not just about a job - it’s about the impact you make. When our people come together, we’re Expanding the Possible by continuously improving what we do and how we do it - for our clients and each other.

If you’re ready to revolutionize how the world moves for future generations, Wabtec is the place for you.

 

Who are we?

Wabtec is a leading global provider of equipment, systems, digital solutions, and value-added services for the freight and transit rail sectors. Drawing on more than 150 years of experience, we are leading the way in safety, efficiency, reliability, innovation, and productivity. Whether it’s freight, transit, ports, logistics, mining, industrial, or marine, our expertise, technologies, and people together – are accelerating the future of transportation. With roots that date back to George Westinghouse, Thomas Edison, and Louis Faiveley, Wabtec has always built technologies and implemented solutions for a variety of sectors that are critical to meeting the needs of customers and governments alike.

Our global team of about 30,000 employees worldwide delivers performance that moves the world forward. We’re lifelong learners, obsessed with better. Learn more at www.WabtecCorp.com.

Culture powers us and the possibilities.

We believe the best ideas come from a mix of experiences and backgrounds. At Wabtec, we strive every day to create a place where everyone belongs. We’re building a culture where leadership, inclusion and your unique perspective fuel progress.

We’re proud to be an Equal Opportunity Employer. We welcome talent of all backgrounds, experiences, and identities, including race, gender, age, disability, veteran status and more.

Need accommodation? Just let us know - we’ve got you.

  • Worker Sub Type: Regular
  • Job Family: IT Cyber Security and Risk

Similar roles