Lead the architecture and modernization of operational technology (OT) networks for critical infrastructure. Design and deploy segmented, SD-WAN-enabled OT environments aligned with ISA/IEC 62443 and NERC CIP standards. This is a hands-on, on-site role for a local expert ready to shape resilient, secure industrial network infrastructure.
Key Responsibilities Architect OT network segmentation using ISA/IEC 62443 zones/conduits model to isolate critical assets Transition flat Layer 2 OT networks to SD-WAN-enabled, zone-based architectures with deterministic performance Engineer resilient topologies (ring, ERPS, redundant paths) for substations and core OT sites Define SD-WAN standards: underlay/overlay design, path selection (latency/jitter/loss), QoS for ICS protocols (DNP3, Modbus, IEC 61850) Implement OT cybersecurity controls: micro-segmentation, firewall zoning, least-privilege access, NERC CIP compliance Conduct OT-focused risk assessments (ransomware, lateral movement, supply chain threats) Deploy and integrate SD-WAN solutions with industrial switches (Cisco/Extreme preferred) Configure high-availability mechanisms: active/standby, RSTP, MPLS-TP Support incident response, root cause analysis, and project delivery with executive reporting
Required Qualifications 10+ years in network design/architecture, with proven OT/ICS environment experience Deep knowledge of industrial protocols: Modbus, DNP3, OPC, Ethernet/IP, IEC 61850 Hands-on experience with OT network segmentation, firewall policy design, and zero-trust principles SD-WAN implementation experience in industrial or critical infrastructure settings Proficiency with Cisco networking (CCNA/CCNP required; CCIE/security cert a plus) Bachelor's degree in Computer Science, Networks, or related field Must live local to Manassas, VA and be available for on-site interviews & work
Preferred Skills Experience with Extreme Networks industrial switches Familiarity with SCADA systems and IT/OT convergence strategies Background in utilities, energy, manufacturing, or transportation infrastructure Knowledge of network monitoring tools and OT-specific threat modeling