Network Security Architect

Bosch Group · Bangalore, India

Full Time

Company Description Bosch Global Software Technologies Private Limited  is a 100% owned subsidiary of Robert Bosch GmbH, one of the world's leading global supplier of technology and services, offering end-to-end Engineering, IT and Business Solutions. With over 27,000+ associates, it’s the largest software development center of Bosch, outside Germany, indicating that it is the Technology Powerhouse of Bosch in India with a global footprint and presence in the US, Europe and the Asia Pacific region.

Job Description

Roles & Responsibilities

  • We are seeking a Network Security Architect with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projects

Key Responsibilities

  • Represent OT network architecture with security and compliance, Connectivity architecture design and decision making
  • Define reference architectures standards and design frameworks for different OT networks
  • Responsible for designing, implementing, and governing secure, resilient, and scalable OT network architectures across industrial/manufacturing environments.
  • Develop HLD/LLD, network diagrams, IP addressing schemes, routing and firewall policies, and architecture standards
  • Analyze different products from OEMs and make the right decisions that fits with technical and commercial aspects
  • Lead Zero Trust adoption for OT environments (ZPA/ZIA, Cisco ZTA)
  • Drive architecture for multi-site, multi-region deployments
  • Define resiliency, redundancy, and failover strategies
  • Lead architecture reviews with Product, Cybersecurity, and Compliance
  • Influence vendor selection, technology standards, and long-term roadmaps
  • Work with cybersecurity teams on IDS/IPS, network monitoring, NAC, vulnerability management, and secure remote access.
  • Coordinate with enterprise IT Network teams for IT/OT convergence and secure remote access.

Qualifications

SKILLS Needed

  • First preference: Juniper devices ; Second preference: Cisco devices
  • ·       Networking (L2/L3):  Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols
  • ·       Firewall & Security:  Cisco  ASA / FTD / FMC, DMZ, Context design, segmentation
  • ·       Zero Trust:  ZPA / ZIA / Cisco ZTA, MFA, privileged access
  • ·       Cloud — AWS (Mandatory):  VPC, EC2, Transit Gateway, Direct Connect, virtual firewall
  • ·       Enterprise proxy solutions : Hands-on experience with (SOCKS5, Squid, HAProxy, NGINX, Zscaler, Blue Coat, or F5) for secure traffic forwarding and access control
  • ·       Standards (Awareness):  IEC 62443, NIST CSF, ISO 27001, Purdue Model
  • ·       Certifications (Preferred):  CCNP / CCIE, AWS Advanced Networking, CISSP
  • MUST-HAVE REQUIREMENTS
  • Layer 2 / Layer 3 Networking —  VLANs, STP, BGP, OSPF, VRF — must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)
  • Firewall Architecture —  Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design
  • Zero Trust —  Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA
  • AWS Cloud Networking —  VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 — mandatory, not optional
  • Standards Awareness —  Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level — does not need deep implementation experience
  • CLOUD NETWORKING DETAIL
  • Candidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.
  • VPC & Subnets —  Design public/private subnets, route tables, internet gateway, NAT gateway
  • EC2 —  Launch and configure instances, assign ENIs, Elastic IPs, IAM roles, Auto Scaling
  • Virtual Firewall on EC2 —  Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances
  • Virtual Router on EC2 —  Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS
  • Connectivity —  Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site
  • Security —  Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrail
  • STANDARDS — AWARENESS LEVEL IS ENOUGH
  • Candidate should be able to discuss these standards in an interview — not implement them from scratch.
  • IEC 62443:  Industrial cybersecurity standard — security zones, conduits, and security levels
  • NIST CSF: Identify, Protect, Detect, Respond, Recover — risk-based security framework
  • ISO / IEC 27001:  Information security management system (ISMS) — how security is governed
  • Purdue Model: Layered industrial network model — why OT/IT segmentation is designed in levels
  • NERC CIP: Power grid cybersecurity compliance — awareness is fine for energy sector projects
  • EXPERIENCE EXPECTATIONS - Mandatory
  • Experience —  10 to 12 years in network engineering
  • Ownership —
  • Architect secure OT/IT integration models aligned to IEC 62443
  • Represent OT network architecture in customer, regulator, and executive discussions
  • Drive architecture for multi-site, multi-region deployments
  • Has owned design and implementation decisions — not just followed instructions
  • Leadership —  Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above
  • Communication —  Comfortable speaking to executives, customers, and compliance teams
  • Certifications: CCNP
  • ]•       Certifications (Good-to-have) —  CCIE, AWS Certified Advanced Networking, AWS Solutions Architect, CISSP
  • GOOD TO HAVE — NOT MANDATORY
  • Any OT / SCADA exposure —  even at project or client level
  • Azure or GCP networking —  as an addition to AWS
  • Infrastructure as Code —  Terraform, CloudFormation, or Ansible for network automation

QUALIFICATIONS

  • BTech / BCA / MCA
  • Experience: 10 yrs - 12 yrs