- Location
- India - Pune
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Job Title:
Senior Manager, Network Security ArchitectJob Description:
The Role:
The Global Network Security Architect is responsible for designing, standardizing, and continuously improving secure network architectures across a global manufacturing footprint—spanning plants, labs, logistics hubs, and corporate/edge sites. This role provides technical leadership for enterprise network security, operational technology (OT) security, and cloud connectivity, ensuring resilient operations and compliance with industry frameworks (NIST CSF, IEC 62443) while enabling business growth through secure modernization (Zero Trust, SD-WAN/SASE, secure cloud adoption).
You will serve as the strategic owner for global network security reference architectures, controls, patterns, and roadmap—partnering closely with IT, OT, engineering, and business teams to reduce risk, improve reliability, and accelerate secure transformation.
What You’ll Do:
Strategy & Architecture
Develop and maintain global network security reference architectures and standards for enterprise, OT/ICS, and cloud environments.
Define and govern Zero Trust network segmentation models (macro/micro-segmentation) across data center, campus, branch, and manufacturing sites.
Architect secure SD-WAN/SASE deployments including policy models, identity-aware access, CASB/DLP integration, and performance baselines.
Establish secure cloud connectivity (AWS/Azure/GCP) patterns: PrivateLink, transit/virtual hubs, service insertion, firewalling, and identity federation.
Lead threat modeling and design reviews for network changes, new plants, M&A integrations, and brownfield modernization.
OT/Manufacturing Security
Lead segmentation of OT zones (Cell/Area, Site Operations, Enterprise) including jump hosts, historian access, and vendor remote maintenance with policy enforcement.
Govern industrial protocol security (e.g., Modbus, DNP3, OPC UA) with appropriate filtering and monitoring; coordinate with plant engineering on change control.
Develop secure deployment patterns for machine builders and system integrators; ensure contractor access is policy-compliant and time-bounded.
Engineering Leadership
Create and socialize security patterns: firewall rule baselines, IDS/IPS placement, SSL/TLS inspection strategy, DNS security, DHCP security, NAC, and micro-segmentation (e.g., host-based, overlay).
Partner with Network Engineering to architect high-availability designs (active/active paths, diverse carriers, QoS, jitter/latency targets) that meet manufacturing SLAs.
Drive secure vendor selection and lifecycle: RFP criteria, bake-offs, PoCs, architecture assurance, and hardening standards (routers, switches, WLCs, firewalls, proxies).
Establish configuration baselines and automation guardrails (e.g., IaC, CI/CD for network, golden images, change validation).
Establish & drive Infrastructure as Code as the delivery mechanism, standardizing architecture and operating patterns
Detection, Response & Resilience
Architect network security monitoring and telemetry pipelines (NetFlow/IPFIX, firewall logs, WAF/DNS, VPN, DHCP, NAC) to SIEM/SOAR.
Define use cases and playbooks for lateral movement detection, beaconing, DNS exfiltration, OT protocol anomalies, remote access misuse, and insider risk.
Design resilience patterns: failover, isolation, recovery of network security components, tabletop scenarios, and red team remediation pathways.
Governance & Stakeholder Management
Own network architecture roadmap and standards; lead design reviews; author decision records.
Provide executive-level risk communication and business impact narratives; translate complex technical topics into actionable decisions.
Mentor engineers and delivery teams; build global community of practice for network/OT/cloud security.
Tools & Technologies
Firewalls & Gateways: Palo Alto, Check Point, Cisco; OT firewalls.
SD-WAN/SASE: Ayraka, Cisco, Palo Alto, Netskope, Cloudflare, etc.
Cloud Networking: Azure vWAN, AWS TGW, GCP Cloud Router; PrivateLink/ExpressRoute/Direct Connect.
Segmentation & NAC: Cisco ISE, Palo Alto/Prisma, Forecsout
Monitoring & Telemetry: NetFlow/IPFIX, SPAN/TAP, OT DPI tools, SIEM/SOAR integrations.
Identity & Access: ZTNA, PAM, MFA, certificate management/PKI.
Frameworks, Controls & Compliance
Map network security controls to NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect, Respond, Recover) and enterprise policies.
Design OT/ICS network zones and conduits aligned to IEC 62443 (e.g., 62443-3-3, 62443-2-1), including Purdue model adaptations, DMZs, and remote access.
Define control objectives and measure effectiveness for encryption, segmentation, secure remote access, privileged access, logging/telemetry, and incident readiness.
What We Seek:
Bachelor's degree in Information Technology, Computer Science, or relevant experience
5-8+ years of experience in cybersecurity
Strong technical skills and excellent communication abilities
Experience in improving monitoring and response capabilities on a large scale
Strategic and tactical thinking with effective decision-making skills
Integrity, pride in work, and a drive for excellence
Knowledge of cloud computing technologies and modern security offerings (EDR, threat intelligence, etc.)
Expert knowledge of IAM principles and practices
Creative thinking for developing sustainable solutions
Proven ability to lead projects independently
10+ years of progressive experience designing and securing global enterprise networks within manufacturing or industrial sectors.
Proven expertise with network security architecture across data center, campus, branch, and OT environments.
Deep hands-on knowledge of firewalls, IDS/IPS, NAC, DNS/DHCP, PKI, VPN/ZTNA, proxy/WAF, and micro-segmentation (host & overlay).
Strong experience with SD-WAN/SASE (policy design, performance engineering, identity integration) and cloud networking (Azure/AWS/GCP).
Demonstrated application of NIST CSF and IEC 62443 in real-world architectures for compliance and risk reduction.
Ability to lead cross-functional initiatives and influence at executive levels; excellent communication and documentation skills.
Core Competencies
Architectural Rigor: Patterns, standards, decision records, and traceability to requirements and controls.
Risk-Driven Design: Balancing operational continuity, safety, and security with business velocity.
Systems Thinking: Holistic view across IT, OT, cloud, identity, and data.
Influence & Communication: Clear, business-aligned storytelling; stakeholder engagement from plant floors to exec suites.
Execution Leadership: From PoC to global rollout; measurable outcomes and operational handoffs.
Outstanding Candidates Will Have:
ISSAP – Information Systems Security Architecture Professional (CISSP concentration).
CISSP, CCSP, CCIE Security/Enterprise, AWS/Azure/GCP cloud networking certifications, GIAC (e.g., GRID/GICSP), or equivalent.
Experience with Zero Trust programs, SASE platforms, network automation (IaC), container/mesh networking, and industrial networking.
Familiarity with OT systems (DCS/PLC/SCADA), historian architectures, and vendor ecosystems common in manufacturing.
Extensive experience assessing and reviewing technology solutions
Familiarity with cybersecurity & privacy frameworks including NIST CSF, ISO 27001, SEMI E187/E188 & GDPR
Experience with enterprise management cybersecurity technologies
Reporting & Collaboration
Reports to: Director of Cybersecurity Architecture & Engineering
Partners with: Network Engineering, Plant/OT Engineering, Cloud Platform, Identity, Risk & Compliance, SOC/IR, and Regional IT Leaders.
Travel
~10–25% global travel to plants and regional hubs (as needed for design workshops, site assessments, and cutover support).
What We Offer:
At Entegris, we invest in providing opportunity to our employees and promote from within. The new hire in this role will have the potential to grow and create relationships across the organization and be recognized for demonstrated success and adherence to company PACE values.
Our total rewards package goes above and beyond just a paycheck. Whether you’re looking to build your career, improve your health, or protect your wealth, we offer generous benefits to help you achieve your goals.
Generous 401(K) plan with an impressive employer match
Excellent health, dental and vision insurance packages to fit your needs
Flexible work schedule and 11 paid holidays a year
Paid time off (PTO) policy that empowers you to take the time you need to recharge
Education assistance to support your learning journey
Values-driven culture with colleagues that rally around People, Accountability, Creativity and Excellence.
At Entegris we are committed to providing equal opportunity to all employees and applicants. Our policy is to recruit, hire, train, and reward employees for their individual abilities, achievements and experience without regard to race, color, religion, sexual orientation, age, national origin, disability, marital or military status.
Entegris strongly encourages all of its employees to be vaccinated against COVID-19. At Entegris, COVID-19 vaccination is preferred but not required at this time.