Senior Manager, Network Security Architect
Entegris · Pune, India
Entegris · Pune, India
Job Title: Senior Manager, Network Security Architect Job Description: The Role: The Global Network Security Architect is responsible for designing, standardizing, and continuously improving secure network architectures across a global manufacturing footprint—spanning plants, labs, logistics hubs, and corporate/edge sites. This role provides technical leadership for enterprise network security, operational technology (OT) security, and cloud connectivity, ensuring resilient operations and compliance with industry frameworks (NIST CSF, IEC 62443) while enabling business growth through secure modernization (Zero Trust, SD-WAN/SASE, secure cloud adoption). You will serve as the strategic owner for global network security reference architectures, controls, patterns, and roadmap—partnering closely with IT, OT, engineering, and business teams to reduce risk, improve reliability, and accelerate secure transformation. What You’ll Do: Strategy & Architecture • Develop and maintain global network security reference architectures and standards for enterprise, OT/ICS, and cloud environments. • Define and govern Zero Trust network segmentation models (macro/micro-segmentation) across data center, campus, branch, and manufacturing sites. • Architect secure SD-WAN/SASE deployments including policy models, identity-aware access, CASB/DLP integration, and performance baselines. • Establish secure cloud connectivity (AWS/Azure/GCP) patterns: PrivateLink, transit/virtual hubs, service insertion, firewalling, and identity federation. • Lead threat modeling and design reviews for network changes, new plants, M&A integrations, and brownfield modernization. OT/Manufacturing Security • Lead segmentation of OT zones (Cell/Area, Site Operations, Enterprise) including jump hosts, historian access, and vendor remote maintenance with policy enforcement. • Govern industrial protocol security (e.g., Modbus, DNP3, OPC UA) with appropriate filtering and monitoring; coordinate with plant engineering on change control. • Develop secure deployment patterns for machine builders and system integrators; ensure contractor access is policy-compliant and time-bounded. Engineering Leadership • Create and socialize security patterns: firewall rule baselines, IDS/IPS placement, SSL/TLS inspection strategy, DNS security, DHCP security, NAC, and micro-segmentation (e.g., host-based, overlay). • Partner with Network Engineering to architect high-availability designs (active/active paths, diverse carriers, QoS, jitter/latency targets) that meet manufacturing SLAs. • Drive secure vendor selection and lifecycle: RFP criteria, bake-offs, PoCs, architecture assurance, and hardening standards (routers, switches, WLCs, firewalls, proxies). • Establish configuration baselines and automation guardrails (e.g., IaC, CI/CD for network, golden images, change validation). • Establish & drive Infrastructure as Code as the delivery mechanism, standardizing architecture and operating patterns Detection, Response & Resilience • Architect network security monitoring and telemetry pipelines (NetFlow/IPFIX, firewall logs, WAF/DNS, VPN, DHCP, NAC) to SIEM/SOA