
Job Title:
Senior Manager, Network Security Architect
TheRole:
The Global Network Security Architectis responsible fordesigning, standardizing, and continuously improving secure network architectures across a global manufacturing footprint—spanning plants, labs,logisticshubs, and corporate/edge sites. This role provides technical leadership for enterprise network security, operational technology (OT) security, and cloud connectivity, ensuring resilient operations and compliance with industry frameworks (NIST CSF, IEC 62443) while enabling business growth through secure modernization (Zero Trust, SD-WAN/SASE, secure cloud adoption).
You will serve as the strategic owner for global network security reference architectures, controls, patterns, and roadmap—partnering closely with IT, OT, engineering, and business teams to reduce risk, improve reliability, and accelerate secure transformation.
WhatYou’llDo:
Strategy & Architecture
Develop andmaintainglobal network security reference architectures and standards for enterprise, OT/ICS, and cloud environments.
Define and govern Zero Trust network segmentation models (macro/micro-segmentation) across datacenter,campus,branch, and manufacturing sites.
Architect secure SD-WAN/SASE deployments including policy models, identity-aware access, CASB/DLP integration, and performance baselines.
Establish secure cloud connectivity (AWS/Azure/GCP) patterns:PrivateLink, transit/virtual hubs, service insertion, firewalling, and identity federation.
Lead threat modeling and design reviews for network changes, new plants, M&A integrations, and brownfield modernization.
OT/Manufacturing Security
Lead segmentation of OT zones (Cell/Area, Site Operations, Enterprise) including jump hosts, historian access, andvendorremote maintenance with policy enforcement.
Govern industrial protocol security (e.g., Modbus, DNP3, OPC UA) withappropriate filteringand monitoring; coordinate with plant engineering on change control.
Develop secure deployment patterns for machine builders and system integrators; ensure contractor access is policy-compliant and time-bounded
Engineering Leadership
Create and socialize security patterns:firewallrule baselines, IDS/IPS placement, SSL/TLS inspection strategy, DNS security, DHCP security, NAC, and micro-segmentation (e.g., host-based, overlay).
Partner with Network Engineering to architect high-availability designs (active/active paths, diverse carriers, QoS, jitter/latency targets) that meet manufacturing SLAs.
Drive secure vendor selection and lifecycle: RFP criteria, bake-offs,PoCs, architecture assurance, and hardening standards (routers, switches, WLCs, firewalls, proxies).
Establish configuration baselines and automation guardrails (e.g.,IaC, CI/CD for network, golden images, change validation).
Establish& driveInfrastructure as Code asthedelivery mechanism,standardizingarchitectureand operating patterns
Detection, Response & Resilience
Architect network security monitoring and telemetry pipelines (NetFlow/IPFIX,firewalllogs, WAF/DNS, VPN, DHCP, NAC) to SIEM/SOAR.
Define use cases and playbooks for lateral movement detection, beaconing, DNS exfiltration, OT protocol anomalies, remote access misuse, and insider risk.
Design resilience patterns: failover, isolation, recovery of network security components, tabletop scenarios, and red team remediation pathways.
Governance & Stakeholder Management
Ownnetworkarchitectureroadmap and standards;leaddesign reviews; author decision records.
Provide executive-level risk communication and business impact narratives; translate complex technical topics into actionable decisions.
Mentor engineersand deliveryteams; buildglobalcommunity of practice for network/OTcloudsecurity.
Tools & Technologies
Firewalls & Gateways: Palo Alto, Check Point, Cisco; OT firewalls.
SD-WAN/SASE:Ayraka,Cisco, Palo Alto,Netskope, Cloudflare, etc.
Cloud Networking: AzurevWAN, AWS TGW, GCP Cloud Router;PrivateLinkExpressRoute/Direct Connect.
Segmentation & NAC: Cisco ISE,Palo Alto/Prisma,Forecsout
Monitoring & Telemetry: NetFlow/IPFIX, SPAN/TAP, OT DPI tools, SIEM/SOAR integrations.
Identity & Access: ZTNA, PAM, MFA, certificate management/PKI.
Frameworks, Controls & Compliance
Map network security controls to NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect, Respond, Recover) and enterprise policies.
Design OT/ICS network zones and conduits aligned to IEC 62443 (e.g.,62443-3-3, 62443-2-1), including Purdue model adaptations, DMZs, and remote access.
Define controlobjectivesand measure effectiveness for encryption, segmentation, secure remote access, privileged access, logging/telemetry, and incident readiness.
WhatWeSeek:
Bachelor's degree in Information Technology, Computer Science, orrelevant experience
5-8+ years of experience in cybersecurity
Strong technical skills and excellent communication abilities
Experience in improving monitoring and response capabilities on a large scale
Strategic and tactical thinking with effective decision-making skills
Integrity, pride in work, and a drive for excellence
Knowledge of cloud computing technologies and modern security offerings (EDR, threat intelligence, etc.)
Expert knowledge of IAM principles and practices
Creative thinking for developing sustainable solutions
Proven ability to lead projects independently
10+ years of progressive experience designing and securing global enterprise networks within manufacturing or industrial sectors.
Provenexpertisewith network security architecture across datacenter,campus,branch, and OT environments.
Deep hands-on knowledge of firewalls, IDS/IPS, NAC, DNS/DHCP, PKI, VPN/ZTNA, proxy/WAF, and micro-segmentation (host & overlay).
Strong experience with SD-WAN/SASE (policy design, performance engineering, identity integration) and cloud networking (Azure/AWS/GCP).
Demonstrated application of NIST CSF and IEC 62443 in real-world architectures for compliance and risk reduction.
Ability to lead cross-functional initiatives and influence at executive levels; excellent communication and documentation skills.
Core Competencies
Architectural Rigor: Patterns, standards, decision records, and traceability to requirements and controls.
Risk-Driven Design: Balancing operational continuity, safety, and security with business velocity.
Systems Thinking: Holistic view across IT, OT, cloud, identity, and data.
Influence & Communication: Clear, business-aligned storytelling; stakeholder engagement from plant floors to exec suites.
Execution Leadership: From PoC to global rollout; measurable outcomes and operational handoffs.
Outstanding Candidates Will Have:
ISSAP – Information Systems Security Architecture Professional (CISSP concentration).
CISSP, CCSP, CCIE Security/Enterprise, AWS/Azure/GCP cloud networking certifications, GIAC (e.g., GRID/GICSP), or equivalent.
Experience with Zero Trust programs, SASE platforms, network automation (IaC), container/mesh networking, and industrial networking.
Familiarity with OT systems (DCS/PLC/SCADA), historian architectures, and vendor ecosystems common in manufacturing.
Extensive experience assessing and reviewing technology solutions
Familiarity with cybersecurity & privacy frameworks including NIST CSF, ISO 27001, SEMI E187/E188 & GDPR
Experience with enterprise management cybersecurity technologies
Reporting & Collaboration
Reports to:Director of Cybersecurity Architecture & Engineering
Partners with: Network Engineering, Plant/OT Engineering, Cloud Platform, Identity, Risk & Compliance, SOC/IR, and Regional IT Leaders.
Travel
~10–25% global travel to plants and regional hubs (as needed for design workshops, site assessments, and cutover support).
WhatWeOffer:
At Entegris, we invest in providingopportunitytoour employees andpromotefromwithin.Thenewhireinthisrolewillhavethepotentialtogrowandcreaterelationships across the organization and be recognized for demonstrated success and adherence to company PACE values.
Ourtotalrewardspackagegoesaboveandbeyondjustapaycheck.Whetheryou’re looking to build your career, improve your health, or protect your wealth, we offer generous benefits to help you achieve your goals.
Generous401(K)planwithanimpressiveemployermatch
Excellenthealth,dentalandvisioninsurancepackagestofityourneeds
Flexibleworkscheduleand11paidholidaysayear
Paidtimeoff(PTO)policythatempowersyoutotakethetimeyouneedtorecharge
Educationassistancetosupportyourlearningjourney
Values-drivenculturewithcolleaguesthatrallyaroundPeople,Accountability,CreativityandExcellence.
At Entegris wearecommittedto providingequal opportunitytoallemployees and applicants. Our policy is to recruit, hire, train,and reward employeesfortheirindividualabilities,achievementsandexperiencewithoutregardtorace,color,religion,sexualorientation,age,national origin, disability, marital or military status.
EntegrisstronglyencouragesallofitsemployeestobevaccinatedagainstCOVID-19.AtEntegris,COVID-19vaccinationispreferredbut not required at this time.

Artificial intelligence, augmented reality, Internet of Things – these are not just trends, they are drivers changing the way people live across the globe. With these new drivers and the increasing speed of innovation, there comes an expectation for higher-quality, higher-performing technologies at a faster pace.
Every day, and for more than 50 years, Entegris’ singular mission has been to help customers utilize our advanced science-based solutions to support demand drivers; to innovate faster and more efficiently; and ultimately to transform the world. Through the power of our solutions and technology expertise, Entegris provides customers with innovative, science-based solutions to their toughest technology challenges.
Headquartered in Billerica, Massachusetts, Entegris employs approximately 8,000 people worldwide, with roughly half employed in Asia-Pacific or Europe.
With research and development, customer service, analytical labs, and manufacturing in Asia-Pacific, North America and Europe, Entegris supports customers around the globe as they take technology to the next level.