Design and Implementation: Develop and implement network architectures for ICS environments, including local area networks (LANs), wide area networks (WANs), and industrial Ethernet networks.
Security Management: Implement robust security measures, including firewalls, VPNs, and intrusion detection systems, to protect ICS networks from cyber threats.
Network Monitoring: Monitor network performance and conduct regular assessments to identify and resolve potential issues.
Documentation: Maintain detailed documentation of network configurations, designs, and security protocols.
Collaboration: Work closely with IT and OT (Operational Technology) teams to ensure seamless integration and operation network systems.
Vendor Coordination: Coordinate with vendors to procure necessary networking equipment and software.
Upgrades and Maintenance: Plan and execute network upgrades and maintenance activities to ensure optimal performance and security.
Compliance: Ensure network designs and operations comply with industry standards and regulatory requirements.
Required Experience:
Minimum of 5 years of experience in network architecture, with a focus on industrial control systems.
Knowledge of network protocols, including TCP/IP, DNS, DHCP, and routing protocols (e.g., OSPF, BGP).
Experience in designing and implementing network security solutions in critical infrastructure, especially in the electrical or energy sectors.
Strong understanding of industrial control system protocols (e.g., Modbus, DNP3, IEC 61850) and network segmentation strategies.
ICS/Substation experience. Be able to understand the terminology and experience in working at a control house at a substation for example.
Certification
Relevant certifications such as CISSP, CCNA, or CCNP are preferred.
Technical Skills:
Understanding of compliance standards (e.g., PCI DSS, NERC CIP, ISO 27001). Familiarity with industry standards such as IEC 62443, NIST SP 800-82, and ISO/IEC 27001.
Knowledge of network segmentation, DMZ architecture, and zero-trust security models.
Ability to analyze and troubleshoot complex security issues in ICS and OT environments