Cyber SDC -Solution Architect - OT Monitoring & Security Tooling
$104.8k - $218.5kErnst & Young
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Role Description
Role Family
OT Operations Architecture / Monitoring & Tooling
Primary Focus
OT monitoring, asset visibility, security tooling strategy, platform health, SOC integration, and operational maturity
Seniority
Lead / Senior Solution Architect
Role Positioning
Operations-oriented solution architecture role supporting OT monitoring and security tooling capabilities
PRACTICE DESCRIPTION
Operational technology environments require sustained visibility, monitoring, security tooling, and operational integration to support stable, secure, and compliant operations. The Solution Architect – OT Monitoring & Security Tooling role provides technical leadership for the strategy, architecture, integration, and continuous improvement of monitoring, asset visibility, detection, and security enablement platforms used in industrial and operational technology environments.
This role works across operations, cybersecurity, platform engineering, asset management, network/security operations, SOC teams, vendors, and site stakeholders to improve monitoring coverage, platform health, event visibility, alert quality, and supportability across OT environments.
JOB SUMMARY
We are seeking a senior Solution Architect – OT Monitoring & Security Tooling to provide solution architecture leadership for OT monitoring, visibility, detection, and security tooling capabilities supporting industrial and operational technology environments.
The role is responsible for defining monitoring and tooling strategies, validating platform capabilities, identifying visibility gaps, guiding tool integrations, supporting incident and alert workflows, and aligning OT security tooling with operational support needs. The architect helps ensure monitoring platforms, asset visibility tools, security telemetry, alerting workflows, and operational integrations remain effective as the OT environment scales and matures.
This is a senior operations-oriented architecture role focused on platform strategy, monitoring maturity, integration alignment, technical advisory support, and continuous improvement. The role provides technical direction and solution guidance while partnering with operations teams responsible for day-to-day service execution.
KEY RESPONSIBILITIES
OT Monitoring and Visibility Strategy
- Define and maintain OT monitoring, visibility, and security tooling strategies aligned to operational support needs.
- Establish monitoring coverage expectations for OT environments, including asset visibility, network traffic monitoring, platform health, and event visibility.
- Identify gaps in monitoring coverage, telemetry quality, alert fidelity, and visibility across site environments.
- Develop recommendations to improve monitoring effectiveness, operational supportability, and security outcomes.
- Partner with operations and cybersecurity teams to maintain a practical roadmap for monitoring and tooling maturity.
Security Tooling Architecture and Platform Alignment
- Provide solution architecture leadership for OT monitoring, asset visibility, vulnerability, endpoint, remote access, and security enablement platforms.
- Evaluate how OT monitoring platforms integrate with enterprise security services, SOC workflows, CMDB/asset platforms, and operational support tools.
- Support architecture decisions for tooling integrations, data flows, alert routing, platform onboarding, and support model alignment.
- Coordinate with platform owners and operational teams to improve platform health, coverage, usability, and lifecycle management.
- Support standardization of monitoring and security tooling patterns across OT environments.
Detection, Alerting, and SOC Integration
- Define monitoring and alerting requirements for OT security and operational support use cases.
- Support development, tuning, and improvement of OT detection logic, alert workflows, escalation paths, and event triage processes.
- Partner with SOC, incident response, and operations teams to improve the usability and actionability of OT alerts.
- Review alert volumes, false-positive trends, visibility gaps, and escalation performance to drive continuous improvement.
- Support integration of OT monitoring outputs with enterprise detection and response processes.
Asset Visibility and Data Integration
- Support solution architecture for OT asset discovery, asset inventory enrichment, and visibility integration with operational systems of record.
- Guide integration patterns between OT monitoring platforms, asset discovery tools, CMDB, service management platforms, vulnerability workflows, and reporting capabilities.
- Identify opportunities to improve asset context, communication baselines, vulnerability visibility, and operational data quality.
- Support definition of minimum required OT asset attributes and data quality expectations for operational support.
- Partner with asset management and operations teams to improve asset visibility maturity over time.
Platform Health, Lifecycle, and Reliability
- Monitor and evaluate health, coverage, reliability, and lifecycle status of OT monitoring and security tooling platforms.
- Support planning for platform upgrades, patching, configuration validation, sensor/collector health, data ingestion, and tool lifecycle activities.
- Identify operational risks related to platform degradation, incomplete coverage, unsupported integrations, or tooling drift.
- Provide architecture guidance for remediation of recurring tooling or monitoring issues.
- Support continuous improvement of platform reliability, supportability, and operational maturity.
Operational Escalation and Technical Advisory
- Serve as a senior technical advisor for complex OT monitoring, tooling, telemetry, visibility, and security platform questions.
- Support escalations involving monitoring gaps, alerting issues, integration defects, platform health problems, or operational visibility challenges.
- Coordinate with engineering, cybersecurity, SOC, network/security operations, site teams, and vendors to resolve complex tooling concerns.
- Translate operational pain points into architecture, integration, or process improvement recommendations.
- Provide guidance to operations teams while preserving clear day-to-day operational ownership.
Standards, Patterns, and Continuous Improvement
- Develop and maintain practical monitoring and tooling guidance for OT operations teams.
- Define repeatable patterns for monitoring coverage, alert routing, platform onboarding, asset visibility, and operational integration.
- Support lessons learned reviews and identify systemic improvements to tooling, processes, or support models.
- Produce architecture guidance, operational playbooks, platform integration notes, and decision records as needed.
- Drive continuous improvement of OT monitoring and security tooling capabilities as the operational footprint grows.
RELEVANT TECHNOLOGY AREAS
The role may work with or provide architectural guidance for technologies and platform categories such as:
- OT monitoring and asset visibility platforms such as Nozomi Networks, Claroty, Dragos, or comparable OT visibility solutions.
- Asset discovery and enrichment platforms such as runZero or comparable discovery tooling.
- Service management, CMDB, and workflow platforms such as ServiceNow and related service graph or integration capabilities.
- Enterprise vulnerability management and security platforms such as Qualys or comparable vulnerability management tooling.
- Security monitoring, SIEM, SOC, and incident response platforms used for detection, alerting, triage, investigation, and escalation.
- Endpoint, remote access, network security, Zero Trust, and firewall platforms that provide telemetry or support OT operations workflows.
- Dashboards, reporting, and operational analytics tools used to monitor coverage, health, risk, and support performance.
QUALIFICATIONS
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Computer Science, or equivalent experience preferred.
- 8+ years of experience in cybersecurity, infrastructure, monitoring, security operations, operational technology, platform architecture, or solution architecture roles.
- Experience supporting monitoring, visibility, security tooling, SOC integration, asset management, or operational support platforms.
- Strong understanding of operational technology environments, industrial networks, asset discovery, security monitoring, and managed operations.
- Ability to translate operational monitoring and tooling needs into practical architecture, integration, and improvement plans.
- Experience collaborating across operations, SOC, cybersecurity, engineering, platform, vendor, and site teams.
- Strong analytical, communication, documentation, and technical leadership skills.
Preferred Qualifications
- Experience with OT monitoring or visibility tools such as Nozomi Networks, Claroty, Dragos, runZero, or comparable platforms.
- Experience with ServiceNow CMDB, Service Graph, OT asset inventory, vulnerability response, or operational workflow integrations.
- Familiarity with SIEM/SOC operations, detection engineering, alert tuning, incident response, and escalation workflows.
- Knowledge of network traffic analysis, industrial protocols, Purdue Model concepts, and OT security monitoring approaches.
- Experience with vulnerability management, endpoint security, remote access, Zero Trust, firewall, or network security tooling in operational environments.
- Relevant certifications such as CISSP, GICSP, GIAC certifications, Security+, Network+, CCSP, ITIL, or comparable security/operations certifications.
TECHNICAL SKILLS
| Monitoring & Security Tooling | OT Operations Integration | Architecture & Improvement |
| OT monitoring tools | SOC and alert workflows | Monitoring strategy |
| Asset visibility platforms | CMDB / asset integration | Tooling roadmap |
| Vulnerability tooling | Operational escalation paths | Integration architecture |
| SIEM and detection workflows | Platform health and coverage | Continuous improvement |
| Remote access / ZT telemetry | Operations reporting | Standards and playbooks |
WHAT WE OFFER
At EY, we are committed to professional development and career growth. This role provides the opportunity to work across cybersecurity, OT operations, platform engineering, security monitoring, asset management, and managed services teams. The role offers exposure to complex industrial environments and the opportunity to improve monitoring visibility, security tooling effectiveness, and operational resilience across OT environments.
SHORT STAFFING PROFILE VERSION
Solution Architect – OT Monitoring & Security Tooling: Provides operations-oriented solution architecture leadership for OT monitoring, asset visibility, detection, security tooling, platform health, SOC integration, and operational visibility. Guides tool strategy, monitoring coverage, telemetry quality, alerting workflows, platform integrations, and continuous improvement across OT environments. Works with operations, SOC, cybersecurity, platform, asset management, and site teams to improve monitoring effectiveness and supportability while partnering with teams responsible for day-to-day service execution.
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.
$124.6k - $148.2k
Job Description Summary: Cyber OT SecOps Overview The Manager, Cyber... ...'s operational leader for monitoring, detecting, and responding to... ...and owns the SOC-side of OT security — ensuring that threats to plant... ...engineering team to ensure monitoring tools are properly deployed,...CyberFull timeWork at officeLocal areaRelocation$104.8k - $218.5k
...Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events PRACTICE... ...SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards. Experience coordinating...CyberFull timeSummer holidayFlexible hours$144.9k - $302.1k
...External Role Description Role Family OT Platform Integration / Operations... ...documentation, control/evidence support, monitoring validation, and operational stabilization... ...that OT assets, site infrastructure, and security components are represented in appropriate...CyberFull timeSummer holidayRemote workFlexible hours$1,500 per month
...USA, is seeking an entry-level Information Security Analyst to join our team. This full-time... ...’s sensitive information and systems from cyber threats, conducting risk assessments, implementing security measures, and monitoring network activity for potential breaches....CyberFull time$104.8k - $218.5k
...Description Role Family OT Field Engineering / Site... ...troubleshooting of network and security infrastructure. Support connectivity... ...assets, site infrastructure, monitoring platforms, and approved... ...switches, firewalls, monitoring tools, endpoint connectivity, or infrastructure...CyberFull timeSummer holidayLocal areaRemote workFlexible hours- Acuity Inc. in Mexico is seeking an OT/ICS cybersecurity specialist to join the Security team. You will design, implement, and manage security for industrial... ..., IT and Risk teams. The ideal candidate has strong cyber security and ICS backgrounds, with experience protecting...Cyber
$169.01k - $370.53k
...facility, and leading market tools, we help our people continue... ...a Specialist Director, Cloud Security to join our Managed Services... ..., compliance, and continuous monitoring programs; Lead enterprise cloud... ...and oversight of Cyber Managed Services delivery across...CyberH1bLocal area- ...ll make an impact:The Senior Security is a member of the IT Security... ...improvement efforts on monitoring, detecting, administration, or... ...takes ownership of advanced cyber security activities. The Senior... ...recommending new security technologies, tools, and vendorsParticipating in...CyberFull timeLocal areaFlexible hours
- ...Purpose: Summary Of Purpose: The Senior IT Security Analyst serves as INPO's primary... ...actions, assessments and decision‑making Monitors emerging cyber and AI risks, regulatory changes, and... ...enterprise vulnerability management tools (e.g. Qualys) and Governance, Risk and...CyberWork experience placement
- ...protecting the organization's digital assets from cyber threats by monitoring networks, identifying vulnerabilities, implementing security measures, threat hunting, responding to... ...utilizing and configuring various security tools such as IDP, EDR/XDR, SIEM, SOAR, IDS/IPS...Cyber
- ...Operator leads advanced offensive security operations designed to assess... ...improve the organization's cyber resilience. This role is... ...controls. Develop custom tools, payloads, exploits, and automation... ...of security controls, monitoring capabilities, and incident response...Cyber
- CRH Americas Building Products is seeking a Senior OT Systems Engineer to design, secure, and manage plant-floor OT infrastructure and its integration... ...vendor designs, and lifecycle management while aligning with industry cyber and safety practices. #J-18808-Ljbffr CRHCyberWork at office
- DescriptionCompany Overviewiboss is a cloud security company that enables the modern... ...ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and... ...audits, leveraging automated tools and established processes to maintain...Cyber
$1,400 per month
...seeking a Junior Information Security Analyst to join our team As a... ...you will be responsible for monitoring and analyzing our companys systems... ...measures to protect against cyber attacks including firewalls... ...with common security tools such as intrusion detection systems...CyberVisa sponsorship$94.1k - $150k
...Position Overview The Cyber Threat Hunter proactively protects... ...that may evade conventional security controls. This role establishes... ...to detection engineering, monitoring enhancements, automation development... ..., PowerShell, or similar tools) to streamline threat hunting...CyberContract workWork at office$70k - $140k
...detection content across the organization's security platforms. This role leverages threat... ...to identify opportunities for improved monitoring coverage.Develop content and requirements... ...frameworks including MITRE ATT&CK, Cyber Kill Chain, NIST CSF, and detection engineering...CyberFull timeWork at officeRemote workWork from homeFlexible hours$155.4k - $261.1k
...technologies that connect the world. Our Chief Security Office ensures that our assets are... ...it.Reporting to the Associate Director of Cyber Risk Management, you will be responsible... ...stakeholders to identify, assess, respond to, and monitor infrastructure and data security risks,...CyberTemporary workWork at officeLocal areaRelocation- ...Job TitleAssists the Office of Security Systems and Emergency Management (OSSEM)/EPU with... ...to ensure the operation, maintenance and monitoring of video technology system equipment and... ...Design (CPTED) program and cyber security related initiatives in coordination...CyberWork at office
- Sr. Security Program Manager, Commercial & Federal Compliance Remote... ...standards (e.g., ISO 27701,Cyber Essentials, TISAX). The ideal... ...authorization and continuous monitoring efforts (Moderate/High baselines... ...program/project management tools (e.g.,Wrike, SharePoint,Confluence...CyberRemote work
- Pritchard Global Alliance is seeking a professional Security Officer to join our team in Atlanta, GA. The role focuses on creating a safe... ..., and property. The ideal candidate will patrol premises, monitor entrances, handle surveillance equipment, and report incidents...Flexible hours
$126k - $165k
Make your mark for patientsWe are looking for an E&BI Insights Monitoring Program Lead who is an experienced, strategic, analytical, and... ...Impact Findings (HIF) and drive continuous improvementUse analytics tools to provide actionable insightsMinimum RequirementsBachelor’s...Permanent employmentWork at officeLocal area- ...Application MonitoringApplication Monitoring Skills must have: Onboard new log files in Splunk Instrument applications with APM tools like CA APM, AppDynamics and Dynatrace Develop Synthetic monitoring scripts in CA ASM, Sitescope, Thousand eyes Onboard Applications on...
- ..., accuracy, availability, and security of revenue-grade meter data and... .... You will: Administer, monitor, maintain , and enhance the end... ...associated reporting and analytics tools. Maintain operating... ...maintain Bulk Electric System Cyber Authorized Status as defined by...CyberWork experience placementRemote work
$80 per hour
...running in customer environments using orchestration and operational tools.Maintain availability, reliability, performance of services... .../DevOps experience involving CI/CD, reliability, scale, monitoring, and live site cultureSolid understanding of cloud-based architectures...CyberRemote work$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives...Contract workWork at officeShift work$127.2k - $246.9k
...Automation to join our Enterprise Security Services organization.... ...tracesSupport and streamline Cyber Operations by actively automating... ...experience in security monitoring, security operations, and incident... ...Security Operations tools (such as Azure Sentinel, XDR,...CyberH1bLocal area- ...Phoenix Cyber is looking for a Data Protection Engineer to join our... ...DLP endpoint protection tool options and help the customer... ...configure Endpoint policies in monitoring mode. Must have the ability... ...process and owners to move to secure information exchange, develop...CyberFull timeWork at office
- ...Engineers to work with our customers in various security testing, architecture, implementation,... ..., you will run daily processes and tools for managing cybersecurity :... ...End Point Protection, Security Logging, Monitoring, and Incident Response, Security Compliance...CyberFull timePart timeInternshipLocal area
- ...review the following job description:The Cyber Hunt & Respond Senior Engineer is a senior... ...threats. The engineer collaborates with security, technology, and business partners to identify... ...packet capture analysis, and associated tools (e.g., Wireshark, tcpdump). Knowledge of...CyberPermanent employmentFull timePart timeH1bWork at officeWork visaShift workNight shiftDay shift
- ...candidate will lead and implement cyber risk oversight, establish and... ...risk assessments, continuous monitoring, and will serve as the... ...extensive knowledge of information security, cyber risk, and technology... ..., and experience with modern tools for measuring the...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber SDC -Solution Architect - OT Monitoring & Security Tooling. Be the first to apply!
- business solutions architect Atlanta, GA
- solution designer Atlanta, GA
- cloud solutions architect Atlanta, GA
- anaplan senior solutions architect Atlanta, GA
- aws solution architect Atlanta, GA
- solutions architect Atlanta, GA
- senior cloud solutions architect Atlanta, GA
- enterprise solution architect Atlanta, GA
- senior solutions architect Atlanta, GA
- lead solution architect Atlanta, GA


