Senior
Bosch Global Software Technologies Private Limited is a 100% owned subsidiary of Robert Bosch GmbH, one of the world's leading global supplier of technology and services, offering end-to-end Engineering, IT and Business Solutions. With over 27,000+ associates, it’s the largest software development center of Bosch, outside Germany, indicating that it is the Technology Powerhouse of Bosch in India with a global footprint and presence in the US, Europe and the Asia Pacific region.
Roles & Responsibilities :
We are seeking a Network Security Architect with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projects
Key Responsibilities
Represent OT network architecture with security and compliance, Connectivity architecture design and decision making
Define reference architectures standards and design frameworks for different OT networks
Responsible for designing, implementing, and governing secure, resilient, and scalable OT network architectures across industrial/manufacturing environments.
Develop HLD/LLD, network diagrams, IP addressing schemes, routing and firewall policies, and architecture standards
Analyze different products from OEMs and make the right decisions that fits with technical and commercial aspects
Lead Zero Trust adoption for OT environments (ZPA/ZIA, Cisco ZTA)
Drive architecture for multi-site, multi-region deployments
Define resiliency, redundancy, and failover strategies
Lead architecture reviews with Product, Cybersecurity, and Compliance
Influence vendor selection, technology standards, and long-term roadmaps
Work with cybersecurity teams on IDS/IPS, network monitoring, NAC, vulnerability management, and secure remote access.
Coordinate with enterprise IT Network teams for IT/OT convergence and secure remote access.
SKILLS Needed:
First preference: Juniper devices ; Second preference: Cisco devices
Networking (L2/L3): Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols
Firewall & Security: Cisco ASA / FTD / FMC, DMZ, Context design, segmentation
Zero Trust: ZPA / ZIA / Cisco ZTA, MFA, privileged access
Cloud — AWS (Mandatory): VPC, EC2, Transit Gateway, Direct Connect, virtual firewall
Enterprise proxy solutions: Hands-on experience with (SOCKS5, Squid, HAProxy, NGINX, Zscaler, Blue Coat, or F5) for secure traffic forwarding and access control
Standards (Awareness): IEC 62443, NIST CSF, ISO 27001, Purdue Model
Certifications (Preferred): CCNP / CCIE, AWS Advanced Networking, CISSP
MUST-HAVE REQUIREMENTS
Layer 2 / Layer 3 Networking — VLANs, STP, BGP, OSPF, VRF — must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)
Firewall Architecture — Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design
Zero Trust — Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA
AWS Cloud Networking — VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 — mandatory, not optional
Standards Awareness — Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level — does not need deep implementation experience
CLOUD NETWORKING DETAIL
Candidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.
VPC & Subnets — Design public/private subnets, route tables, internet gateway, NAT gateway
EC2 — Launch and configure instances, assign ENIs, Elastic IPs, IAM roles, Auto Scaling
Virtual Firewall on EC2 — Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances
Virtual Router on EC2 — Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS
Connectivity — Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site
Security — Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrail
STANDARDS — AWARENESS LEVEL IS ENOUGH
Candidate should be able to discuss these standards in an interview — not implement them from scratch.
IEC 62443: Industrial cybersecurity standard — security zones, conduits, and security levels
NIST CSF: Identify, Protect, Detect, Respond, Recover — risk-based security framework
ISO / IEC 27001: Information security management system (ISMS) — how security is governed
Purdue Model: Layered industrial network model — why OT/IT segmentation is designed in levels
NERC CIP: Power grid cybersecurity compliance — awareness is fine for energy sector projects
EXPERIENCE EXPECTATIONS - Mandatory
Experience — 10 to 12 years in network engineering
Ownership —
Architect secure OT/IT integration models aligned to IEC 62443
Represent OT network architecture in customer, regulator, and executive discussions
Drive architecture for multi-site, multi-region deployments
Has owned design and implementation decisions — not just followed instructions
Leadership — Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above
Communication — Comfortable speaking to executives, customers, and compliance teams
Certifications: CCNP
Certifications (Good-to-have) — CCIE, AWS Certified Advanced Networking, AWS Solutions Architect, CISSP
GOOD TO HAVE — NOT MANDATORY
Any OT / SCADA exposure — even at project or client level
Azure or GCP networking — as an addition to AWS
Infrastructure as Code — Terraform, CloudFormation, or Ansible for network automation
QUALIFICATIONS
BTech / BCA / MCA
Experience: 10 yrs - 12 yrs
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well Bosch Group matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.