Roles & Responsibilities
- Position Summary:
- Design, implement, and maintain security controls across enterprise IT networks and Operational Technology (OT) environments (including manufacturing and plant floor systems). Ensure systems are secure, compliant, and resilient in a regulated pharmaceutical manufacturing setting.
- Key Responsibilities:
- Network Security (IT):
- Design, implement, and manage security architecture across LAN/WAN, wireless, VPN, firewalls, and cloud connectivity (Azure/Entra ID environments).
- Administer and optimize perimeter and internal segmentation controls (firewalls, NAC, DNS security/Cisco Umbrella, proxies).
- Monitor network traffic for anomalies; collaborate with SOC/MDR partners (e.g., Arctic Wolf) to triage and respond to alerts.
- Manage VPN, remote access, and secure site-to-site connectivity across manufacturing plants, distribution centers, and corporate offices.
- Support identity and access controls for network infrastructure (802.1x, RADIUS, privileged access).
- OT/ICS Security:
- Assess and secure OT environments including SCADA, PLCs, DCS, HMIs, and manufacturing execution systems (MES).
- Implement IT/OT segmentation (Purdue Model alignment), including DMZs between corporate IT and plant floor networks.
- Conduct OT asset inventory, vulnerability assessments, and risk scoring specific to legacy and vendor-locked industrial systems.
- Partner with Manufacturing, Engineering, and Automation teams to embed security requirements into OT change control, patch management, and vendor remote access.
- Ensure OT security controls align with regulatory constraints (validated systems, GxP change control) without disrupting production uptime.
- Cybersecurity Program Support:
- Support NIST CSF 2.0-aligned governance activities, risk assessments, control gap remediation, and regulatory audits (FDA 21 CFR Part 11, GxP, SOC 2 Type II, DSCSA-related systems).
- Support penetration testing and remediation cycles for network and OT-facing assets.
- Participate in incident response for network/OT security events, including forensics and root-cause coordination with managed security partners.
- Maintain network security documentation, diagrams, standard operating procedures, and technical policy artifacts.
- Provide input into vendor risk assessments for network and OT equipment/software suppliers.
Required Skills
Must-have Skills
- 10–12 years of progressive network security experience with demonstrable hands-on exposure to both IT and OT/ICS environments.
- Strong working knowledge of firewalls, network segmentation, VPN, NAC, IDS/IPS, and secure remote access architectures.
- Practical experience with OT/ICS security frameworks (IEC 62443, NIST SP 800-82) and Purdue Model segmentation.
- Familiarity with SCADA / PLC / DCS environments and operational constraints of legacy industrial systems.
- Experience with cloud network security in Azure / Entra ID or equivalent environments.
- Solid understanding of NIST CSF 2.0 and broader security governance frameworks.
- Experience with SIEM/MDR-based monitoring and incident response workflows.
- Strong technical documentation skills (network diagrams, risk assessments, SOPs).
Nice-to-have Skills
- Prior experience in pharmaceutical, life sciences, or other regulated manufacturing environments (GxP, validated systems, DSCSA/serialization awareness).
- Experience working alongside managed security service providers (MDR/SOC partners e.g., Arctic Wolf) and coordinating cross-functional incident response.
- Exposure to identity lifecycle and privileged access management (PAM) concepts as applied to network devices and OT assets.
Education & Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field (or equivalent practical experience).
- Preferred Certifications: CISSP, GICSP, CCNP Security, CCNA, ISA/IEC 62443 Cybersecurity Certificate, or equivalent.
Ideal Candidate
- Proven ability to balance IT security rigor with OT operational realities (uptime, safety, validation constraints).
- Strong cross-functional collaboration skills (able to work seamlessly with Manufacturing, Automation/Engineering, Compliance, and Quality teams).
- Analytical and methodical approach to risk assessment and incident triage.
- Clear written and verbal communication for both technical and non-technical stakeholders.
Perks & Benefits
- Medical insurance (for Self and family): Yes/No
- Vehicle Fuel Allowance: Yes/No
- Travel Allowance (outside city or state Travel): Yes/No
- Travel Dearness (manage daily expenses during Travel) Allowance: Yes/No
- Annual Performance Bonus: Yes/No
- Sales Incentive: Yes/No
- Festival Bonus: Yes/No
- Others (if any):