Network and Security Architect (Bengaluru)

Network and Security Architect (Bengaluru)

29 Aug
|
Quess
|
Bengaluru

29 Aug

Quess

Bengaluru

Urgently Hiring Network Security Architect

Follow the URL

https://www.quesscorp.com/

Client- Robert Bosch.

: Network Security Architect

Roles &

Responsibilities : We are seeking a Network Security Architect with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projectsKey ResponsibilitiesRepresent OT network architecture with security and compliance, Connectivity architecture design and decision makingDefine reference architectures standards and design frameworks for different OT networksResponsible for designing, implementing, and governing secure, resilient, and scalable OT network architectures across industrial/manufacturing environments.Develop HLD/LLD, network diagrams, IP addressing schemes, routing and firewall policies, and architecture standardsAnalyze different products from OEMs and make the right decisions that fits with technical and commercial aspectsLead Zero Trust adoption for OT environments (ZPA/ZIA, Cisco ZTA)Drive architecture for multi-site, multi-region deploymentsDefine resiliency, redundancy, and failover strategiesLead architecture reviews with Product, Cybersecurity, and ComplianceInfluence vendor selection, technology standards, and long-term roadmapsWork with cybersecurity teams on IDS/IPS, network monitoring, NAC, vulnerability management, and secure remote access.Coordinate with enterprise IT Network teams for IT/OT convergence and secure remote access.QualificationsSKILLS Needed:First preference: Juniper devices ; Second preference: Cisco devices• Networking (L2/L3): Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols• Firewall & Security: Cisco ASA / FTD / FMC, DMZ, Context design, segmentation• Zero Trust: ZPA / ZIA / Cisco ZTA, MFA,



privileged access• Cloud AWS (Mandatory): VPC, EC2, Transit Gateway, Direct Connect, virtual firewall• Enterprise proxy solutions : Hands-on experience with (SOCKS5, Squid, HAProxy, NGINX, Zscaler, Blue Coat, or F5) for secure traffic forwarding and access control• Standards (Awareness): IEC 62443, NIST CSF, ISO 27001, Purdue Model• Certifications (Preferred): CCNP / CCIE, AWS Advanced Networking, CISSPMUST-HAVE REQUIREMENTS• Layer 2 / Layer 3 Networking VLANs, STP, BGP, OSPF, VRF — must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)• Firewall Architecture — Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design• Zero Trust — Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA• AWS Cloud Networking — VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 — mandatory, not optional• Standards Awareness — Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level — does not need deep implementation experienceCLOUD NETWORKING DETAILCandidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.

- VPC & Subnets — Design public/private subnets, route tables, internet gateway, NAT gateway• EC2 — Launch and configure instances, assign ENIs, Elastic IPs,



IAM roles, Auto Scaling• Virtual Firewall on EC2 — Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances• Virtual Router on EC2 — Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS• Connectivity — Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site• Security — Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrailSTANDARDS — AWARENESS LEVEL IS ENOUGHCandidate should be able to discuss these standards in an interview — not implement them from scratch.IEC 62443: Industrial cybersecurity standard — security zones, conduits, and security levelsNIST CSF: Identify, Protect, Detect, Respond, Recover — risk-based security frameworkISO / IEC 27001: Information security management system (ISMS) — how security is governedPurdue Model: Layered industrial network model — why OT/IT segmentation is designed in levelsNERC CIP: Power grid cybersecurity compliance — awareness is fine for energy sector projectsEXPERIENCE EXPECTATIONS - Mandatory• Experience —9 years in network engineering• Ownership —• Architect secure OT/IT integration models aligned to IEC 62443• Represent OT network architecture in customer, regulator, and executive discussions• Drive architecture for multi-site, multi-region deploymentsHas owned design and implementation decisions — not just followed instructions• Leadership — Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above• Communication — Comfortable speaking to executives, customers, and compliance teams• Certifications: CCNP

📌 Network and Security Architect (Bengaluru)
🏢 Quess
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: network and security architect (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: network and security architect (bengaluru) / bengaluru