Senior Manager, Network Security Architect (Pune)

Senior Manager, Network Security Architect (Pune)

16 Aug
|
4174 Entegris Korea Co.
|
Pune

16 Aug

4174 Entegris Korea Co.

Pune

Job Title:

Senior Manager, Network Security Architect

:

The Role:

The Global Network Security Architect is responsible for designing, standardizing, and continuously improving secure network architectures across a global manufacturing footprint—spanning plants, labs, logistics hubs, and corporate/edge sites. This role provides technical leadership for enterprise network security, operational technology (OT) security, and cloud connectivity, ensuring resilient operations and compliance with industry frameworks (NIST CSF, IEC 62443) while enabling business growth through secure modernization (Zero Trust, SD-WAN/SASE, secure cloud adoption).

You will serve as the strategic owner for global network security reference architectures, controls, patterns, and roadmap—partnering closely with IT, OT, engineering, and business teams to reduce risk, improve reliability, and accelerate secure transformation.

What You’ll Do:

Strategy & Architecture

- Develop and maintain global network security reference architectures and standards for enterprise, OT/ICS, and cloud environments.
- Define and govern Zero Trust network segmentation models (macro/micro-segmentation) across data center, campus, branch, and manufacturing sites.
- Architect secure SD-WAN/SASE deployments including policy models, identity-aware access, CASB/DLP integration, and performance baselines.
- Establish secure cloud connectivity (AWS/Azure/GCP) patterns: PrivateLink, transit/virtual hubs, service insertion, firewalling, and identity federation.
- Lead threat modeling and design reviews for network changes, current plants, M&A; integrations, and brownfield modernization.

OT/Manufacturing Security

- Lead segmentation of OT zones (Cell/Area, Site Operations, Enterprise) including jump hosts, historian access, and vendor remote maintenance with policy enforcement.
- Govern industrial protocol security (e.g., Modbus, DNP3, OPC UA) with appropriate filtering and monitoring; coordinate with plant engineering on change control.
- Develop secure deployment patterns for machine builders and system integrators; ensure contractor access is policy-compliant and time-bounded.

Engineering Leadership

- Create and socialize security patterns: firewall rule baselines, IDS/IPS placement, SSL/TLS inspection strategy, DNS security, DHCP security, NAC, and micro-segmentation (e.g., host-based, overlay).
- Partner with Network Engineering to architect high-availability designs (active/active paths, diverse carriers, QoS, jitter/latency targets) that meet manufacturing SLAs.
- Drive secure vendor selection and lifecycle: RFP criteria, bake-offs, PoCs, architecture assurance, and hardening standards (routers, switches, WLCs, firewalls, proxies).
- Establish configuration baselines and automation guardrails (e.g., IaC, CI/CD for network, golden images, change validation).
- Establish & drive Infrastructure as Code as the delivery mechanism, standardizing architecture and operating patterns

Detection, Response & Resilience

- Architect network security monitoring and telemetry pipelines (NetFlow/IPFIX, firewall logs, WAF/DNS, VPN, DHCP, NAC) to SIEM/SOAR.
- Define use cases and playbooks for lateral movement detection, beaconing, DNS exfiltration, OT protocol anomalies,



remote access misuse, and insider risk.
- Design resilience patterns: failover, isolation, recovery of network security components, tabletop scenarios, and red team remediation pathways.

Governance & Stakeholder Management

- Own network architecture roadmap and standards; lead design reviews; author decision records.
- Provide executive-level risk communication and business impact narratives; translate complex technical topics into actionable decisions.
- Mentor engineers and delivery teams; build global community of practice for network/OT/cloud security.

Tools & Technologies

- Firewalls & Gateways: Palo Alto, Check Point, Cisco; OT firewalls.
- SD-WAN/SASE: Ayraka, Cisco, Palo Alto, Netskope, Cloudflare, etc.
- Cloud Networking: Azure vWAN, AWS TGW, GCP Cloud Router; PrivateLink/ExpressRoute/Direct Connect.
- Segmentation & NAC: Cisco ISE, Palo Alto/Prisma, Forecsout
- Monitoring & Telemetry: NetFlow/IPFIX, SPAN/TAP, OT DPI tools, SIEM/SOAR integrations.
- Identity & Access: ZTNA, PAM, MFA, certificate management/PKI.

Frameworks, Controls & Compliance

- Map network security controls to NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect, Respond, Recover) and enterprise policies.
- Design OT/ICS network zones and conduits aligned to IEC 62443 (e.g., 62443-3-3, 62443-2-1), including Purdue model adaptations, DMZs, and remote access.
- Define control objectives and measure effectiveness for encryption, segmentation, secure remote access, privileged access, logging/telemetry, and incident readiness.

What We Seek:

- Bachelor's degree in Information Technology, Computer Science, or relevant experience
- 5-8+ years of experience in cybersecurity
- Strong technical skills and excellent communication abilities
- Experience in improving monitoring and response capabilities on a large scale
- Strategic and tactical thinking with effective decision-making skills
- Integrity, pride in work, and a drive for excellence
- Knowledge of cloud computing technologies and modern security offerings (EDR, threat intelligence, etc.)
- Expert knowledge of IAM principles and practices
- Creative thinking for developing sustainable solutions
- Proven ability to lead projects independently
- 10+ years of progressive experience designing and securing global enterprise networks within manufacturing or industrial sectors.
- Proven expertise with network security architecture across data center, campus, branch, and OT environments.
- Deep hands-on knowledge of firewalls, IDS/IPS, NAC, DNS/DHCP, PKI, VPN/ZTNA, proxy/WAF, and micro-segmentation (host & overlay).
- Strong experience with SD-WAN/SASE (policy design, performance engineering, identity integration) and cloud networking (Azure/AWS/GCP).
- Demonstrated application of NIST CSF and IEC 62443 in real-world architectures for compliance and risk reduction.




- Ability to lead cross-functional initiatives and influence at executive levels; excellent communication and documentation skills.

Core Competencies

- Architectural Rigor: Patterns, standards, decision records, and traceability to requirements and controls.
- Risk-Driven Design: Balancing operational continuity, safety, and security with business velocity.
- Systems Thinking: Holistic view across IT, OT, cloud, identity, and data.
- Influence & Communication: Clear, business-aligned storytelling; stakeholder engagement from plant floors to exec suites.
- Execution Leadership: From PoC to global rollout; measurable outcomes and operational handoffs.

Outstanding Candidates Will Have:

- ISSAP – Information Systems Security Architecture Professional (CISSP concentration).
- CISSP, CCSP, CCIE Security/Enterprise, AWS/Azure/GCP cloud networking certifications, GIAC (e.g., GRID/GICSP), or equivalent.
- Experience with Zero Trust programs, SASE platforms, network automation (IaC), container/mesh networking, and industrial networking.
- Familiarity with OT systems (DCS/PLC/SCADA), historian architectures, and vendor ecosystems common in manufacturing.
- Extensive experience assessing and reviewing technology solutions
- Familiarity with cybersecurity & privacy frameworks including NIST CSF, ISO 27001, SEMI E187/E188 & GDPR
- Experience with enterprise management cybersecurity technologies

Reporting & Collaboration

- Reports to: Director of Cybersecurity Architecture & Engineering
- Partners with: Network Engineering, Plant/OT Engineering, Cloud Platform, Identity, Risk & Compliance, SOC/IR, and Regional IT Leaders.

Travel

- ~10–25% global travel to plants and regional hubs (as needed for design workshops, site assessments, and cutover support).

What We Offer: At Entegris, we invest in providing opportunity to our employees and promote from within. The new hire in this role will have the potential to grow and create relationships across the organization and be recognized for demonstrated success and adherence to company PACE values.

Our total rewards package goes above and beyond just a paycheck. Whether you’re looking to build your career, improve your health, or protect your wealth, we offer generous benefits to help you achieve your goals.

- Generous 401(K) plan with an impressive employer match
- Excellent health, dental and vision insurance packages to fit your needs
- Flexible work schedule and 11 paid holidays a year
- Paid time off (PTO) policy that empowers you to take the time you need to recharge
- Education assistance to support your learning journey
- Values-driven culture with colleagues that rally around People, Accountability, Creativity and Excellence.

At Entegris we are committed to providing equal opportunity to all employees and applicants. Our policy is to recruit, hire, train, and reward employees for their individual abilities, achievements and experience without regard to race, color, religion, sexual orientation, age, national origin, disability, marital or military status. Entegris strongly encourages all of its employees to be vaccinated against COVID-19. At Entegris, COVID-19 vaccination is preferred but not required at this time.

📌 Senior Manager, Network Security Architect (Pune)
🏢 4174 Entegris Korea Co.
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, network security architect (pune) / pune