Principal OT Product Security Architect
- Salary
- $147.6K–$184.5K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
We offer:
- Career Development
- Competitive Compensation and Benefits
- Pay Transparency
- Global Opportunities
Learn More Here: https://www.dematic.com/en-us/about/careers/what-we-offer/
Dematic provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
The base pay range for this role is estimated to be $147,600 - $184,500 at the time of posting. Final compensation will be determined by various factors such as work location, education, experience, knowledge, and skills.
Tasks and Qualifications:
What you will do in this role:
The Principal OT Product Security Architect will provide technical leadership to ensure Dematic products and solutions are secure by design and protect customer supply chain operations. The scope encompasses system-wide cybersecurity across OT/ICS, warehouse automation equipment, machine controls, robotics, software, networks, edge systems, and cloud-connected environments. The role will collaborate with Product Management, R&D, Software and Controls Engineering, IT, Customer Service, and regional teams to embed cybersecurity throughout the product and solution lifecycle.
- Define and maintain OT cybersecurity architecture, requirements, standards, and reference architectures for Dematic products and solutions.
- Lead security architecture and technical design reviews across OT, software, controls, networking, and cloud environments.
- Define secure network architectures, including segmentation, zones/conduits, firewalls, industrial DMZs, secure remote access, and OT-to-cloud connectivity.
- Integrate secure-by-design and DevSecOps principles into product and system development lifecycles.
- Define cybersecurity requirements for products, systems, software, embedded components, and customer deployments.
- Lead or support threat modeling, attack-surface assessments, vulnerability assessments, penetration testing, and security architecture assessments.
- Establish risk-based approaches for OT vulnerability remediation, including compensating controls where patching may impact safety, availability, reliability, or operations.
- Define requirements for OT security monitoring and platforms and their integration with customer SOC/SIEM/MDR environments.
- Translate applicable cybersecurity standards and regulations into technical requirements, including IEC 62443, NIST CSF, NIST SP 800-82, ISO 27001, and EU Cyber Resilience Act (CRA).
- Support product certification, conformity assessments, audits, customer security reviews, and cybersecurity evidence development.
- Perform and support OT cybersecurity assessments of Dematic and customer environments and provide practical remediation strategies.
- Partner with Engineering, Product Security, Infrastructure, and Operations teams to develop secure architectures throughout the product lifecycle.
- Provide technical expertise during OT cybersecurity incidents and support secure recovery and resilience strategies.
- Mentor cybersecurity, software, controls, and engineering teams on OT cybersecurity architecture and secure design practices.
- Evaluate emerging OT cybersecurity technologies and contribute to Dematic's long-term OT cybersecurity architecture and capability roadmap.
What we are looking for:
- Bachelor's or Master's degree in Cybersecurity, Computer Science, Computer Engineering, Electrical Engineering, Information Technology, or related field, or equivalent experience.
- 8+ years of cybersecurity, OT/ICS security, product security, network security, systems engineering, or related experience, with demonstrated experience designing or assessing OT cybersecurity architectures.
- Experience with industrial automation, robotics, warehouse automation, manufacturing, control systems, or other OT environments.
- Strong understanding of OT/ICS architecture, industrial networks, PLCs, HMIs, SCADA, robotics, segmentation, firewalls, VPNs, and secure remote access.
- Experience applying cybersecurity principles across complex hardware, software, and integrated systems.
- Knowledge of vulnerability management, penetration testing, threat modeling, security monitoring, and risk-based remediation in OT environments.
- Working knowledge of networking, Windows/Linux, cloud environments, and scripting/automation such as Python or PowerShell.
- Knowledge of IEC 62443, NIST CSF, NIST SP 800-82, ISO 27001, and/or applicable regulatory requirements such as the EU CRA.
- Strong ability to translate cybersecurity risks and regulatory requirements into practical architecture, engineering requirements, and controls.
- Strong communication, technical writing, consulting, and stakeholder management skills.
- Ability to influence technical decisions across engineering and business teams without direct authority.
- Preference for and ability to thrive in highly collaborative work environments.
- Passionate and quick learner.
- Dedicated, highly motivated, energetic and relentless pursuer of quality and successful outcomes that benefit the broader team, organization, and community.
- Preferred certifications: CISSP, GICSP, GRID, GCIP, Security+, Network+, ISA/IEC 62443 (IC32/IC33), or equivalent.
- Ability to travel occasionally to customer sites and Dematic facilities.
- Individual contributor with the ability to support the team in a lead role.
Location & Authorization: This is a hybrid role requiring proximity to one of our U.S. offices (Grand Rapids MI, Atlanta GA, Plano TX). Applicants must be authorized to work in the U.S. without the need for current or future sponsorship.
About us
KION brands keep the world moving – globally, regionally, and locally.
KION is the Supply Chain Solutions Company. With over 42,000 employees in more than 100 countries, we enable smart, sustainable, and reliable supply chains worldwide - wherever goods are stored, moved, or delivered.
KION offers its customers the full spectrum of solutions to make their supply chains future-ready. Our international brands, Linde Material Handling, STILL, and Baoli and our regional brands, Fenwick and OM, stand for outstanding technological innovation, intelligent automation and service excellence in forklift trucks and warehouse equipment. Dematic complements this expertise with state-of-the-art automation technology and AI-supported software solutions that optimize intralogistics across warehousing, production, and distribution.
Whether locally or globally – we offer exciting career opportunities in an innovative environment shaped by our core values: Integrity, Collaboration, Courage, and Excellence.
Together, we create the magic of supply chain solutions. Join our team – Push it forward.