OT Security Architect - Having Mandatory exp in Azure Sentinel, Splunk,Cloud Security,Guard Duty,
Summary: Experienced Cyber Security Architect specializing in designing and delivering security solutions across IT and OT environments, particularly in critical infrastructure and financial services. The role involves developing security risk assessment frameworks and expertise in cloud and hybrid infrastructure security, compliance, and incident detection. The candidate must have a strong background in securing industrial control systems and managing cross-functional teams for digital transformation. Proficiency in various security tools and frameworks is essential for success in this position.
Key Responsibilities:
- Design and deliver robust security solutions across IT and OT environments.
- Develop IT/OT security risk assessment frameworks leveraging STRIDE.
- Secure industrial control systems (ICS) through unified threat modelling and Zero Trust architectures.
- Align cross-functional teams and manage stakeholder expectations.
- Deliver secure digital transformation programs across diverse regulatory landscapes.
Key Skills:
- Expertise in cloud and hybrid infrastructure security (Azure, AWS, GCP).
- Proficiency in SIEM integration (Azure Sentinel, Splunk).
- Experience with IAM/PAM (CyberArk, BeyondTrust).
- Knowledge of compliance standards (NIST, IEC 62443, ISO 27001, GDPR).
- Strong understanding of networking and datacenter virtualization technologies.
- Familiarity with penetration and vulnerability assessment tools.
- Experience in DevSecOps practices and tools.
Salary (Rate): £550/day
City: Coventry
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: inside IR35
Seniority Level: undetermined
Industry: IT
- IT and OT environments
- Successfully developed IT/OT security risk assessment frameworks leveraging STRIDE, improving incident detection and resilience across industrial networks. Brings deep expertise in cloud and hybrid infrastructure security (Azure, AWS, GCP), SIEM integration (Azure Sentinel, Splunk), IAM/PAM (CyberArk, BeyondTrust), and compliance with NIST, IEC 62443, ISO 27001, and GDPR
- Cloud security
- Networking
- AWS Security: GuardDuty, Macie, Config, CloudTrail, Security Hub, Secrets Manager, Shield.
Job Description:
Experienced Cyber Security Architect with a proven track record of designing and delivering robust, scalable security solutions across IT and OT environments in critical infrastructure, utilities, and financial services. Specialises in securing industrial control systems (ICS), including SCADA, DCS, and PLCs, through unified threat modelling and Zero Trust architectures. Successfully developed IT/OT security risk assessment frameworks leveraging STRIDE, improving incident detection and resilience across industrial networks. Brings deep expertise in cloud and hybrid infrastructure security (Azure, AWS, GCP), SIEM integration (Azure Sentinel, Splunk), IAM/PAM (CyberArk, BeyondTrust), and compliance with NIST, IEC 62443, ISO 27001, and GDPR. Adept at aligning cross-functional teams, managing stakeholder expectations, and delivering secure digital transformation programmers across diverse regulatory landscapes.
Technical Skills:
- Information Security Management o Audit & Compliance: GDPR, COBIT, PCI DSS, ISO 27001, NIST, CIS Controls o Cyber Framework: NIST Cybersecurity Framework, Zero Trust Architecture o Security Incident & Event Management (SIEM): Azure Sentinel, LogRhythm, Splunk, ElasticSIEM o Identity & Access Management (IAM): Azure AD PIM, CyberArk, BeyondTrust o Penetration & Vulnerability Assessment: Kali Linux, ZAP, Nessus, Burp Suite, Metasploit o Threat Modelling: STRIDE, DREAD, MITRE ATT&CK
- Networking and Datacenter Virtualization Technologies o IP, NGFW, DMVPN, MPLS, BGP, OSPF, LISP, Anycast, VPC, NLB
- Cloud Security o OS: Linux, Windows o Cloud Platforms: Azure, AWS, GCP o Cloud Networking: VPC, IPsec VPN, Route53, ELB, CloudFront, vWAN, ExpressRoute o Azure Security: WAF, AD, Azure Entra, Defender for Cloud, M365, Intune o AWS Security: GuardDuty, Macie, Config, CloudTrail, Security Hub, Secrets Manager, Shield
- DevSecOps o Tools: Tenable.io, Veracode & AppScan (DAST, SAST, IAST) o Configuration Management: Chef, Ansible