Praha
Monthly: 120 000 CZK
From: 5/2026 (12m)
Contract via CP Home office: 99%
OT Security Architect (42813)
I'm seeking a skilled OT Security Architect with strong experience in application migration, SCADA systems, and industrial cybersecurity. Your mission will be to analyze legacy workstation applications and operational technologies, map service dependencies, and define secure migration paths into the client’s target environment. The ideal candidate understands how applications consume services, can identify migration risks, and knows how to mitigate them throughout the entire lifecycle. Knowledge of NIST, ISO 27001, encryption standards, incident response, and cloud security capabilities is essential.
🚀 Project
- analyzing existing workstation site applications (including SCADA and legacy systems) to understand their architecture, service dependencies, and integration points
- designing and driving end-to-end application migration strategies into the client’s environment
- dssessing IT/OT security posture across manufacturing lines and defining architecture patterns aligned with industry frameworks (NIST, ISO 27001)
- identifying and mitigating security risks throughout the migration lifecycle, including network segmentation, access control, and endpoint hardening
- collaborating with cross-functional teams to ensure migrated systems meet regulatory requirements (GDPR, HIPAA, GxP where applicable)
- defining and implementing security controls across network layers — firewalls, VPNs, IDS/IPS — with particular focus on OT/SCADA environments
- supporting incident response planning and ensuring recovery procedures are in place post-migration
- leveraging cloud security capabilities (AWS / Azure / GCP) where relevant to the target architecture
- contributing to or leading workstreams using Python/PowerShell for automation of migration or security tasks
🎯 Skills
- proven experience in IT/OT security architecture
- hands-on knowledge of application migration — understanding how apps consume services, what dependencies need to be mapped, and how to safely transition them
- familiarity with SCADA systems and legacy OT application landscapes
- network security expertise: firewalls, VPNs, IDS/IPS
- understanding of encryption standards (SSL/TLS, PKI)
- risk management and incident response experience