What are the responsibilities and job description for the W2 - 15+ OT Network Architect position at Prohires?
Senior OT Network Architect
Location: Manassas, VA (Onsite 100%)
Employment Type: Contract-to-Hire
Job Summary
We are seeking an experienced Senior OT Network Architect to lead the design, implementation, and modernization of Operational Technology (OT) network infrastructure in a mission-critical industrial environment. The ideal candidate will possess deep expertise in OT networking, SD-WAN architecture, cybersecurity, network segmentation, and industrial communication protocols within ICS/SCADA environments.
This role requires hands-on experience designing resilient, secure, and highly available OT network architectures while supporting IT/OT convergence initiatives and compliance standards such as NERC CIP.
Key Responsibilities
Architecture & Design
- Design and implement segmented OT network architectures transitioning from flat Layer 2 environments to SD-WAN-enabled, zone-based architectures.
- Develop network segmentation strategies using ISA/IEC 62443 zones and conduits models.
- Engineer resilient ring and fault-tolerant network topologies across substations and OT environments.
- Develop SD-WAN standards including:
- Underlay and overlay architecture
- Path selection policies based on latency, jitter, and packet loss
- QoS optimization for ICS protocols such as DNP3, Modbus, and IEC 61850
Security & Compliance
- Implement OT-specific cybersecurity controls including:
- Micro-segmentation
- Firewall zoning
- Least-privilege access
- Define and maintain firewall policies to restrict unauthorized inter-zone communication.
- Conduct OT-focused risk and vulnerability assessments related to ransomware, lateral movement, and supply chain threats.
- Ensure compliance with NERC CIP and other applicable cybersecurity frameworks.
Implementation & Operations
- Lead deployment and integration of SD-WAN solutions across OT sites.
- Configure and support high-availability and failover mechanisms including:
- Active/active and active/standby redundancy
- Rapid Spanning Tree
- ERPS
- MPLS-TP
- Troubleshoot OT network incidents and perform root cause analysis.
- Manage network implementation projects and provide regular status updates to leadership.
Required Qualifications
- 10 years of experience in network architecture and design, preferably within OT, ICS, or SCADA environments.
- Strong expertise in:
- SD-WAN technologies
- Routing and switching
- Firewall configurations
- Network segmentation
- Hands-on experience with industrial protocols including:
- Modbus
- DNP3
- OPC
- Ethernet/IP
- IEC 61850
- Strong understanding of IT/OT convergence principles.
- Experience with industrial-grade switching infrastructure and network resiliency technologies.
- Excellent troubleshooting and analytical skills.
Preferred Qualifications
- Experience with ICS and SCADA systems.
- Knowledge of OT cybersecurity best practices.
- Familiarity with network monitoring and management tools.
- Experience with Cisco networking environments and Extreme Networks switches.
Certifications
- CCNA or CCNP required
- CCIE
- Security certifications are a plus
Skills | No. of Years of Experience | Detailed Writeup |
Total No. of Years of Experience |
|
|
Certification in related fields (CCNA, CCNP) required. Security and Cisco Certified Internetwork Expert (CCIE), and experience in Extreme network switches is a plus. |
|
|
10 years of experience in network design and architecture, preferably in OT environments. |
|
|
Experience with industrial protocols (e.g., Modbus, DNP3, OPC, Ethernet/IP). |
|
|
Familiarity with IT/OT convergence principles. |
|
|
Minimum Technical Expertise: · Knowledge of design, configuration, installation, testing, and maintenance of local and wide area computer wired and wireless networks (Cisco Systems preferred). · Knowledge of computer network characteristics, network operating system software, and network components · Troubleshooting skills and the ability to diagnose/resolve network system problems. · Ability to interpret and apply complex technical manuals and reference materials. · Ability to assist with developing network security and related procedures; and performing network management activities. |
|
|
Prefer: Strong understanding of networking concepts, including routing, switching, and firewall configurations. |
|
|
Prefer: Proficiency in network monitoring and management tools. |
|
|
Prefer: Knowledge of cybersecurity best practices for OT networks. |
|
|
Prefer: Experience with industrial control systems (ICS) and SCADA systems. |
|
|