
Cyber SDC -Solution Architect - OT Monitoring & Security Tooling
Ernst and Young10 days ago
Base Salary
$105k - $219k/yr
Responsibilities
- Define OT monitoring, asset visibility, and security tooling strategies aligned with operational support needs.
- Establish monitoring coverage expectations and identify gaps in asset visibility, telemetry quality, alert fidelity, and platform health.
- Provide solution architecture leadership for OT monitoring, asset visibility, vulnerability, endpoint, remote access, and security enablement platforms.
- Guide integrations among OT monitoring platforms, SOC workflows, CMDB and asset platforms, service-management systems, vulnerability workflows, and reporting tools.
- Define detection and alerting requirements and support alert tuning, escalation workflows, event triage, and SOC integration.
- Support OT asset discovery, inventory enrichment, data-quality standards, and integration with operational systems of record.
- Evaluate platform reliability, lifecycle status, sensor and collector health, data ingestion, upgrades, patching, and configuration validation.
- Serve as a senior technical advisor for complex monitoring, telemetry, tooling, integration, and operational visibility issues.
- Develop monitoring standards, onboarding patterns, operational playbooks, architecture guidance, and continuous-improvement recommendations.
Requirements
- 8+ years of experience in cybersecurity, infrastructure, monitoring, security operations, operational technology, platform architecture, or solution architecture roles.
- Experience with monitoring, visibility, security tooling, SOC integration, asset management, or operational support platforms.
- Strong understanding of OT environments, industrial networks, asset discovery, security monitoring, and managed operations.
- Ability to translate monitoring and tooling needs into practical architecture, integration, and improvement plans.
- Experience collaborating across operations, SOC, cybersecurity, engineering, platform, vendor, and site teams.
- Strong analytical, communication, documentation, and technical leadership skills.
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, or Computer Science is preferred, or equivalent experience.
- Preferred experience with Nozomi Networks, Claroty, Dragos, runZero, ServiceNow CMDB, Service Graph, OT asset inventory, vulnerability response, or operational workflow integrations.
- Preferred familiarity with SIEM/SOC operations, detection engineering, alert tuning, incident response, escalation workflows, network traffic analysis, industrial protocols, Purdue Model concepts, and OT security monitoring.
- Relevant certifications such as CISSP, GICSP, GIAC, Security+, Network+, CCSP, or ITIL are preferred.
Benefits
- Base salary range is $104,800 to $192,200 in most US geographic locations and $125,800 to $218,500 in New York City Metro Area, Washington State, and California excluding Sacramento.
- Medical and dental coverage, pension and 401(k) plans, paid time off, EY paid holidays, winter and summer breaks, personal and family care leave, and other leaves of absence.
- Hybrid work model with most external client-serving employees expected to work in person 40–60% of the time over an engagement, project, or year.
- Flexible vacation policy and professional development and career-growth opportunities.
- Applications are accepted on an ongoing basis.
Categories
Solutions Engineering