Network Cybersecurity Architect
Computer Network Defense
Cybersecurity Architecture
Cybersecurity Tools
Iec 62443
Industrial Control Systems
Industrial Cybersecurity
Industrial Cybersecurity
Industrial Networking Security
Information Security
InfoSec
Intrusion Detection And Prevention
Nerc Cip
Network Security
Network Security Engineering
Network Segmentation
Ot Security
Security Compliance
Security Engineer
Security Engineering
Security Information And Event Management
Security Standards
Security Testing
Solution Architecture
Job Description
Lead network cybersecurity architecture and engineering for critical-infrastructure clients, with technical leadership across the full delivery lifecycle and a focus on secure, resilient IP networks and OT/network security transitions.
Responsibilities
- Perform network infrastructure cybersecurity assessments, including vulnerability assessments, risk evaluations, and architecture reviews
- Produce technical reports documenting findings, risk impacts, and prioritized remediation actions
- Support adversarial testing and security validation activities, including red team-style exercises where applicable
- Partner with other teams to evaluate and secure SCADA, DCS, and industrial network architectures
- Create and review system designs and provide cybersecurity input aligned with operational requirements such as availability and safety
- Lead implementation of network cybersecurity infrastructure solutions, including configuration, integration, and deployment of security technologies such as firewalls, IDS/IPS, segmentation, and secure remote access for resilient OT environments
- Support development and enhancement of cybersecurity standards, methodologies, and testing procedures
- Contribute to business development, including proposal support, scope development, and client presentations
- Attend internal and external project meetings and deliver cybersecurity subject matter expertise
- Support cybersecurity assessments, including vulnerability scanning and, when applicable, penetration testing across network, system, application, and OT/ICS environments
- Deliver high-quality technical work while aligning with project budgets, schedules, and quality requirements
- Mentor junior staff and support knowledge sharing across teams
- Stay current on cybersecurity technologies, threats, and industry trends relevant to IT and OT environments
Requirements
- 8+ years of relevant experience in network cybersecurity, penetration testing, or cyber assessments
- Hands-on experience with network cybersecurity solutions including firewalls, IDS/IPS, NAC, secure remote access, zero trust network architectures, and SIEM
- Strong networking fundamentals, including routing, switching, segmentation, and firewalls
- Ability to complete pre-employment onboarding requirements if selected, which may include background check, drug screen, and motor vehicle records search, in compliance with applicable laws and regulations
Relevant Technologies
- Firewalls, IDS/IPS, segmentation, secure remote access, NAC, zero trust network architectures, SIEM
- SCADA, DCS, OT/ICS, NERC CIP, NIST CSF, IEC 62443
- Penetration testing methodologies, vulnerability assessment tools
- OSCP, GPEN, GWAPT, CISSP, CISM, GICSP
The Opportunity
- Lead and expand Black & Veatch’s network cybersecurity architecture and engineering capabilities for critical-infrastructure clients
- Provide technical leadership across the full project lifecycle, including pursuit development, requirements definition, network cybersecurity assessments, architecture and detailed design, implementation oversight, testing, commissioning, and operational transition with a network security focus
- Lead cybersecurity design and delivery of secure, resilient IP network environments, including segmentation, industrial DMZs, electronic security perimeters, network access controls, secure remote access, network management security, encryption, monitoring integration, and related network cybersecurity technologies
- Help develop NCS standards, methodologies, quality processes, service offerings, and personnel for the Network & Cybersecurity Services team
- Coordinate with the Industrial Cybersecurity Services team on engagements involving cybersecurity program strategy, governance, risk, compliance, policy, application or system security, incident-response planning, managed security services, or broader adversarial testing
Team and Work Environment
- BV Operations: skills aligned to projects across all BV supported market sectors
- Instrumentation & Control department: global team specializing in instrumentation, control systems, wireless communications, networks, and cybersecurity for BV Market Sectors and Solutions
- Hybrid or flexible work options may be offered after the first 90 days based on manager discretion, job performance, and work assignments
Preferred Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Engineering, or related discipline preferred, or equivalent experience
- Familiarity with Industrial Control Systems technologies including SCADA, PLCs, and industrial networks
- Knowledge of standards and frameworks such as NERC CIP, NIST CSF, and IEC 62443
- Experience developing cybersecurity standards, tools, or internal methodologies
- Relevant certifications such as OSCP, GPEN, GWAPT, CISSP, CISM, or GICSP
- Strong consulting and client-facing experience
- Ability to translate complex technical concepts into clear, actionable recommendations
- Familiarity with penetration testing methodologies and vulnerability assessment tools, with ability to contribute to testing across IT and OT/ICS environments
Benefits
- Health care benefits including medical, dental, and vision insurances
- Disability
- Robust wellness program
- Flexible work schedules
- Paid vacation and holiday time
- Sick time; dependent sick time
- Company-matched 401k plan
- Adoption reimbursement; tuition reimbursement
- Vendor discounts
- Employment referral program
- AD&D insurance
- Pre-taxed accounts
- Voluntary legal plan
- B&V Credit Union
- Performance-based bonus program (professionals may be eligible)
- 100 percent ESOP-owned company (stock ownership)