{"id":217978,"url":"https://alion.io/job/bosch-network-security-architect-3","title":"Network Security Architect","company":{"id":132,"name":"Bosch","domain":"bosch.com","url":"https://alion.io/company/bosch","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"B","score":75,"open_postings":877,"ghost_share":0,"stale_share":0.992,"repost_share":0,"time_to_fill_p50_days":25,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":22000,"max_usd":52000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":415},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon EC2","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"BGP","optional":false},{"name":"GCP","optional":false},{"name":"HAProxy","optional":false},{"name":"ISO 27001","optional":false},{"name":"Layer 2","optional":false},{"name":"Nginx","optional":false},{"name":"NIST CSF","optional":false},{"name":"OSPF","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false},{"name":"Ansible","optional":true},{"name":"CloudFormation","optional":true},{"name":"FortiGate","optional":true},{"name":"IAM","optional":true},{"name":"Terraform","optional":true}],"status":"live","first_seen_at":"2026-08-27T04:54:57Z","employer_posted_date":"2026-08-27","last_verified_at":"2026-10-01T18:52:42Z","board_verified":true,"closed_at":null,"days_open":35,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":35},"description":"Bosch Global Software Technologies Private Limited is a 100% owned subsidiary of Robert Bosch GmbH, one of the world's leading global supplier of technology and services, offering end-to-end Engineering, IT and Business Solutions. With over 27,000+ associates, it’s the largest software development center of Bosch, outside Germany, indicating that it is the Technology Powerhouse of Bosch in India with a global footprint and presence in the US, Europe and the Asia Pacific region.\n Roles & Responsibilities :\nWe are seeking a Network Security Architect with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projects\nKey Responsibilities\nRepresent OT network architecture with security and compliance, Connectivity architecture design and decision making\n\nDefine reference architectures standards and design frameworks for different OT networks\n\nResponsible for designing, implementing, and governing secure, resilient, and scalable OT network architectures across industrial/manufacturing environments.\n\nDevelop HLD/LLD, network diagrams, IP addressing schemes, routing and firewall policies, and architecture standards\n\nAnalyze different products from OEMs and make the right decisions that fits with technical and commercial aspects\n\nLead Zero Trust adoption for OT environments (ZPA/ZIA, Cisco ZTA)\n\nDrive architecture for multi-site, multi-region deployments\n\nDefine resiliency, redundancy, and failover strategies\n\nLead architecture reviews with Product, Cybersecurity, and Compliance\n\nInfluence vendor selection, technology standards, and long-term roadmaps\n\nWork with cybersecurity teams on IDS/IPS, network monitoring, NAC, vulnerability management, and secure remote access.\n\nCoordinate with enterprise IT Network teams for IT/OT convergence and secure remote access.\n\nSKILLS Needed:\nFirst preference: Juniper devices ; Second preference: Cisco devices\n· Networking (L2/L3): Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols\n· Firewall & Security: Cisco ASA / FTD / FMC, DMZ, Context design, segmentation\n· Zero Trust: ZPA / ZIA / Cisco ZTA, MFA, privileged access\n· Cloud - AWS (Mandatory): VPC, EC2, Transit Gateway, Direct Connect, virtual firewall\n· Enterprise proxy solutions: Hands-on experience with (SOCKS5, Squid, HAProxy, NGINX, Zscaler, Blue Coat, or F5) for secure traffic forwarding and access control\n· Standards (Awareness): IEC 62443, NIST CSF, ISO 27001, Purdue Model\n· Certifications (Preferred): CCNP / CCIE, AWS Advanced Networking, CISSP\nMUST-HAVE REQUIREMENTS\nLayer 2 / Layer 3 Networking - VLANs, STP, BGP, OSPF, VRF - must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)\nFirewall Architecture - Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design\nZero Trust - Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA\nAWS Cloud Networking - VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 - mandatory, not optional\nStandards Awareness - Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level - does not need deep implementation experience\nCLOUD NETWORKING DETAIL\nCandidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.\nVPC & Subnets - Design public/private subnets, route tables, internet gateway, NAT gateway\nEC2 - Launch and configure instances, assign ENIs, Elastic IPs, IAM roles, Auto Scaling\nVirtual Firewall on EC2 - Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances\nVirtual Router on EC2 - Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS\nConnectivity - Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site\nSecurity - Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrail\nSTANDARDS - AWARENESS LEVEL IS ENOUGH\nCandidate should be able to discuss these standards in an interview - not implement them from scratch.\nIEC 62443: Industrial cybersecurity standard - security zones, conduits, and security levels\nNIST CSF: Identify, Protect, Detect, Respond, Recover - risk-based security framework\nISO / IEC 27001: Information security management system (ISMS) - how security is governed\nPurdue Model: Layered industrial network model - why OT/IT segmentation is designed in levels\nNERC CIP: Power grid cybersecurity compliance - awareness is fine for energy sector projects\nEXPERIENCE EXPECTATIONS - Mandatory\nExperience - 10 to 12 years in network engineering\nOwnership -\nArchitect secure OT/IT integration models aligned to IEC 62443\nRepresent OT network architecture in customer, regulator, and executive discussions\nDrive architecture for multi-site, multi-region deployments\nHas owned design and implementation decisions - not just followed instructions\nLeadership - Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above\nCommunication - Comfortable speaking to executives, customers, and compliance teams\nCertifications: CCNP\n]\nCertifications (Good-to-have) - CCIE, AWS Certified Advanced Networking, AWS Solutions Architect, CISSP\nGOOD TO HAVE - NOT MANDATORY\nAny OT / SCADA exposure - even at project or client level\nAzure or GCP networking - as an addition to AWS\nInfrastructure as Code - Terraform, CloudFormation, or Ansible for network automation\nQUALIFICATIONS\nBTech / BCA / MCA\nExperience: 10 yrs - 12 yrs","description_format":"text","description_chars":5499,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security","Industrial Automation","Information Security","HVAC & Refrigeration"],"lifecycle":[{"event":"open","at":"2026-09-05T08:55:49Z"}],"liveness":{"score":26,"band":"fade","label":"Fading","p_open":1,"p_active":0.464,"p_room":0.55,"age_days":35,"expected_fill_days":25,"reasons":["conf:25","stale_co","velocity","win:tail","comp:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/bosch-network-security-architect-3","json_url":"https://alion.io/job/bosch-network-security-architect-3.json","meta":{"generated_at":"2026-10-01T20:14:20Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2850,"day_limit":5000,"remaining_today":2150,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}