About this role
PURPOSE OF THE JOB
The Sr. OT Security Architect is a key member of the Owens Corning Global Information Services (GIS) Security organization. This role is responsible for defining, implementing, and governing Operational Technology (OT) security architecture, security operations capabilities, and cybersecurity standards across Owens Corning's global manufacturing environments.
The role serves as the technical leader for OT cybersecurity initiatives, ensuring secure design principles, defense-in-depth strategies, and consistent security controls are deployed across manufacturing sites. Key accountabilities include building and maturing OT Security Operations capabilities, developing OT security standards, governing firewall architecture and policy management, and driving vulnerability management, patching, and remediation programs.
This position partners with Manufacturing, Engineering, Infrastructure, Cybersecurity, the IT Security Operations Center, site teams, and external service providers to identify and mitigate cyber risk while maintaining reliability, availability, safety, and continuity of manufacturing operations. The role also provides oversight of OT monitoring, incident response and recovery, technology lifecycle management, and monthly security metrics and dashboards.
Reports to: Director, Manufacturing Security & Infrastructure
Span of Control: Individual Contributor; will coordinate work of third-party resources
JOB RESPONSIBILITIES
Knowing Our Businesses and their Strategies
- Understand the strategic direction of the company’s businesses and execute technical strategies to enhance business results
- Develop and maintain a strong understanding of Owens Corning specific business processes and operations locally and globally
- Build relationships within the organization, cross-functionally, and with key business stakeholders; continuously enhance connection to remain aligned with core objectives
- Understand how IT/OT Security and services are directly aligned with the company's strategic objectives by regularly engaging with key business stakeholders
- Know what best-in-class IT organizations do and obtain outside-in market insights to understand and then apply to positively impact Owens Corning.
Executing Strategy
OT Security Architecture and Governance
- Define, maintain, and govern global OT security architecture standards, patterns, reference designs, and technical requirements.
- Maintain secure design principles aligned with the Purdue Model, defense in depth, least privilege, ISA/IEC 62443, NIST guidance, and applicable industry practices.
- With oversight, will develop and maintain OT security standards, procedures, roadmaps, technical specifications, implementation guidance, and architecture decision records.
- Perform security architecture reviews for manufacturing systems, network designs, segmentation, remote access, cloud integrations, digital manufacturing initiatives, and material technology changes.
- Provide technical leadership for global OT security initiatives and participate in risk reviews for new technologies, projects, acquisitions, integrations, and modernization efforts.
- Govern security exceptions, compensating controls, residual-risk documentation, and architecture acceptance decisions.
Vulnerability Management, Patching, and Lifecycle Management
- Lead the OT vulnerability management process from discovery through risk assessment, prioritization, remediation planning, exception management, validation, and closure.
- Prioritize vulnerabilities using asset criticality, exploitability, exposure, compensating controls, operational impact, vendor support, and maintenance-window constraints.
- Develop and govern OT patching standards, testing expectations, deployment controls, rollback plans, reporting, and exception processes for operating systems, applications, firmware, network devices, and security platforms.
- Coordinate vulnerability remediation with manufacturing sites, engineering, infrastructure teams, application owners, equipment vendors, and service partners; validate evidence and track residual risk.
- Define lifecycle-management requirements for OT assets and develop strategies for legacy or unsupported technologies through segmentation, monitoring, hardening, replacement planning, and documented compensating controls.
- Identify systemic vulnerability and lifecycle trends and translate them into remediation initiatives, roadmap priorities, and measurable risk-reduction plans.
Incident Response and Cyber Risk Management
- Partner with IT Security Operations, Incident Response, Infrastructure, Manufacturing, and site teams during cybersecurity incidents affecting OT environments.
- Serve as an OT security technical lead for incident analysis, containment, eradication, recovery, lessons learned, and control-improvement of workstreams.
- Develop and maintain OT incident response and recovery playbooks, including roles, communications, evidence handling, site engagement, isolation options, restoration dependencies, and validation steps.
- Participate in cyber exercises, tabletop events, and recovery testing activities.
- Conduct risk assessments and threat evaluations and recommend practical mitigations that preserve manufacturing safety, reliability, and continuity.
Firewall Architecture and Security Controls
- Provide architecture oversight and governance for OT firewalls, segmentation strategies, remote access technologies, intrusion detection, security monitoring, and network security controls.
- Define and review firewall standards, policy requirements, zone strategies, allowed services, logging expectations, remote access, and segmentation designs.
- Participate in firewall-rule reviews, recertification, exception approvals, policy-lifecycle governance, and remediation overly broad, obsolete, or unnecessary access.
- Ensure firewall policies align with least-privilege principles, approved OT architecture, and secure manufacturing operations.
- Evaluate security technologies and recommend scalable enhancements that improve OT visibility, resilience, and cyber-risk reduction.
Influencing in the Function
- Identify areas of waste (process, time, etc.) and ideate and execute action plans to create productivity
- Lead or participate in special projects that support the long-term strategic goals of the business and/or organization
- Identify opportunities to improve effectiveness, value, and perception of the function
Developing Talent
- Invest in personal growth and development, clearly focused on self-learning
- Always strive to elevate the capabilities of the team and GIS organization across the company, drive change management, and technology adoption
JOB REQUIREMENTS
MINIMUM QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related discipline; equivalent relevant experience may be considered.
- 7+ years of progressive experience in cybersecurity, security architecture, network security, infrastructure security, or security engineering, including 3+ years supporting OT, ICS, manufacturing, or other cyber-physical environments.
EXPERIENCE, KNOWLEDGE & ABILITIES:
- Strong experience with security architecture, network security, firewalls, vulnerability management, patch governance, cybersecurity operations, and risk-based remediation.
- Hands-on experience implementing, managing, and troubleshooting security technologies and controls.
- Experience analyzing security alerts and supporting incident response, containment, recovery, and remediation activities.
- Knowledge of core networking, complex routing, security protocols, industrial segmentation, secure remote access, IPsec, NAT, VPNs, intrusion detection or prevention, logging, and authentication concepts.
- Experience designing, reviewing, implementing, or governing firewall policies and centrally managed security rules in complex enterprise or manufacturing environments.
- Ability to solve complex security and infrastructure problems and translate findings into practical actions.
- Strong knowledge of OT and ICS security concepts, including the Purdue Model, industrial zones and conduits, defense in depth, secure remote access, safety and availability requirements, and legacy-system constraints.
- Knowledge of ISA/IEC 62443, the NIST Cybersecurity Framework, NIST SP 800-82, ISO 27001/27002, CIS Controls, MITRE ATT&CK for ICS, and applicable risk-management practices.
- Experience building or maturing OT SOC operating models, monitoring use cases, response playbooks, escalation processes, service-provider governance, and performance metrics.
- Experience with SIEM, case management, network detection, asset visibility, vulnerability scanning, endpoint security, firewall management, and security analytics technologies.
- Experience governing vulnerability prioritization, remediation tracking, patch testing and deployment, security exceptions, compensating controls, and technology lifecycle management.
- Ability to interpret alerts and technical evidence from network, endpoint, firewall, identity, asset-discovery, vulnerability, and threat-intelligence sources.
- Ability to produce accurate monthly dashboards and translate operational data into clear trends, risks, decisions, and recommended actions.
- Ability to communicate and collaborate effectively with Manufacturing, Engineering, Infrastructure, Cybersecurity, IT, site teams, business partners, technology suppliers, and managed security providers.
- Proven ability to build trust, influence without direct authority, establish accountability, and drive issues to documented closure.
- Experience managing supplier relationships and leading resolution of advanced technical issues with internal teams and external providers.
- Strong written and verbal communication, analytical thinking, technical judgment, organizational skills, facilitation, and problem-solving capabilities.
- Ability to work successfully across cultures and within a global manufacturing organization.
- Ability to travel up to 25%, including internationally
#LI-JP1
#LI-ONSITE
About Owens Corning
Owens Corning is a branded building products leader with three complementary market-leading businesses providing roofing, insulation, and doors primarily for residential markets in North America and Europe. The company operates with an integrated go-to-market strategy and a unique set of OC Advantages™ – including its iconic brand, unparalleled commercial strength, leading technology, and winning cost position – to help customers win and grow in the market. Owens Corning is committed to helping build better and achieve more through winning partnerships, leading performance, and engaging people. Founded in 1938 and headquartered in Toledo, Ohio, Owens Corning is listed on the New York Stock Exchange (NYSE: OC). For more information, visit www.owenscorning.com .
Owens Corning is an equal opportunity employer. Except in limited circumstances such as formal apprenticeship programs, Owens Corning does not employ anyone under the age of 18.