ASTRA
Website:
astracyber.com
Job details:
CRITICAL INFRASTRUCTURE & INDUSTRIAL CYBERSECURITY
Hands-on OT cybersecurity project delivery across India and West Asia
Location
India, with regional project travel
Experience
5-6 years hands-on
Employment
Full-time
Compensation
Up to INR 12 LPA CTC
Role type
Hands-on project delivery
Travel
India and West Asia
Reporting to
Regional Head - India
Project stages
Design, build, FAT, SAT and support
This is a hands-on engineering role, not a coordination-only, presales-only or advisory-only position.
******Please only apply if you are okay with the CTC as it is fixed *********************
The role
Astra Cyber Security delivers OT cybersecurity design, implementation, commissioning and lifecycle support for industrial and critical infrastructure environments. Our projects combine servers, virtualisation, storage, firewalls, switching, monitoring, secure remote access, logging, backup and integration with SCADA and other operational systems.
You will take practical ownership of the OT network and firewall workstream from detailed design and equipment staging through FAT, SAT, site commissioning, documentation and early-life support. You must be able to configure the devices yourself, prove the required traffic paths and diagnose failures at packet and session level.
You will work closely with the other senior engineer, project stakeholders, equipment vendors, EPC partners and client teams. The two engineers jointly own the integrated outcome, FAT/SAT readiness, commissioning quality and an orderly handover to support.
What you will own
• Translate approved architectures into implementable IP plans, VLANs, zones, conduits, interface schedules, routing, high-availability and firewall-rule designs.
• Stage, configure and commission Cisco switching, Fortinet and Palo Alto firewalls, including management access, HA, routing, NAT, security policies, VPN, IPS profiles, logging and configuration backup.
• Implement Layer 2 and Layer 3 services such as VLANs, trunks, access ports, STP, LACP, static or dynamic routing and redundant network paths appropriate to the design.
• Build least-privilege firewall rules from validated application flows and test both permitted and denied traffic without weakening the security architecture to make an application work.
• Configure and validate SPAN/TAP or port-mirroring paths for OT monitoring platforms and coordinate sensor reachability and management access with the systems engineer.
• Integrate the network side of secure remote access, jump hosts, log forwarding, data-diode services and third-party connections to SCADA, OPC UA, forecasting, metering and SOC environments.
• Troubleshoot with packet captures, session tables, routing tables, ARP/MAC information, policy tests and interface counters, and document the evidence behind the conclusion.
• Prepare configurations, rule matrices, network drawings, interface schedules, test procedures, rollback plans, FAT/SAT evidence and final as-built documentation.
• Support site mobilisation, cabling and optics checks, commissioning, defect closure and early-life support while following access, safety and change-control requirements.
Technical experience we need
• 5-6 years of relevant hands-on network and firewall engineering experience, including delivery of at least one environment from build through testing and handover.
• Strong practical knowledge of Ethernet, IP addressing and subnetting, VLANs, trunking, STP, LACP, routing, NAT, ACL/security policy, VPN and high-availability concepts.
• Strong hands-on capability with at least one of Fortinet FortiGate or Palo Alto Networks firewalls, plus practical exposure to or a clear ability to work with the other platform.
• Hands-on experience with Cisco Catalyst or comparable managed switching, including configuration, backup, upgrades and fault isolation.
• Confidence using Wireshark or similar tools and firewall/session diagnostics to distinguish routing, NAT, policy, application, DNS, time or endpoint faults.
• Understanding of OT segmentation, the Purdue model, zones and conduits, least privilege and the availability impact of network changes in industrial environments.
• Awareness of industrial communications such as OPC UA, Modbus TCP, IEC 60870-5-104, DNP3 or IEC 61850. Deep expertise in every protocol is not required, but you must be able to reason about flows and dependencies.
How you work - equally important
• Ownership and follow-through. You take responsibility for connectivity and security issues until they are resolved, handed over clearly or escalated with useful evidence.
• Structured troubleshooting. You remain calm, follow the packet path, test assumptions and avoid broad rule changes or reboots that hide the actual cause.
• Clear communication. You can explain rule intent, technical risk, test results and next actions to engineers, vendors, project managers and client representatives.
• Documentation discipline. You keep IP plans, rule matrices, configurations, drawings, rollback steps and test records accurate throughout delivery.
• Teamwork without ego. You collaborate closely with the systems engineer, share packet-level evidence, invite peer review and help the wider team reach the correct outcome.
• Client and site maturity. You are respectful, punctual, safety-conscious and dependable during FAT, commissioning, cutovers and work in live industrial environments.
• Adaptability and learning. You can move between vendors, read technical documentation carefully and engage vendor support efficiently when specialist input is needed.
• Sound judgement. You understand that an apparently simple firewall or routing change can affect plant availability, security, warranty and acceptance.
Qualifications and practical requirements
• Bachelor's degree or diploma in computer science, information technology, electronics, instrumentation or a related field. Equivalent practical experience will also be considered.
• Strong written and spoken English, including the ability to write clear test steps, rule justifications, technical findings and client updates.
• Current passport and willingness to travel for staging, FAT, SAT, commissioning and support assignments across India and West Asia.
• Ability to work safely in industrial and power-sector environments and to comply with site access, permit, confidentiality and change-control requirements.
• Willingness to undertake planned work outside normal business hours when required for cutovers, FAT/SAT or site commissioning.
Useful, but not mandatory
We do not expect a candidate with 5-6 years of experience to hold every vendor certification or know every OT protocol. Helpful exposure includes Cisco Enterprise Switching, FortiGate and Palo Alto firewalls, OT NIDS monitoring, data diodes, secure remote access, OT DMZ integration, and relevant CCNA/CCNP, Fortinet, Palo Alto training. Strong networking fundamentals, safe hands-on delivery and disciplined troubleshooting matter most.
Click on Apply to know more.