OT Network Segmentation (Core Responsibility)
- Design and implement zero-trust segmentation policies using Elisity
- Configure Elisity identity-based segmentation (policy enforcement via Edge Nodes / Policy Engine)
- Define zone & conduit architecture aligned with ISA/IEC 62443
Industrial Network Integration
- Work with OT assets :
- PLCs (Siemens, Rockwell, B&R)
- SCADA systems (Ignition, WinCC, FactoryTalk)
- MES (Tulip, eMaint, etc.)
- Integrate Elisity with:
- Active Directory / Identity providers
- Asset inventory / discovery tools
Asset Discovery & Classification
- Identify and classify:
- OT devices (PLCs, HMIs, Robots)
- IT-OT boundary systems (historians, MES)
- Map communication flows:
PLC
Policy Design & Implementation
- Create granular access control policies based on:
- Identity
- Device type
- Application
- Implement:
- Least privilege access
- East-West traffic control
Security & Compliance
- Align segmentation design with:
- IEC 62443
- NIST Cybersecurity Framework
- Support:
- Vulnerability mitigation
- Incident response (containment using segmentation)
Monitoring & Troubleshooting
- Monitor segmentation policies and traffic flows
- Troubleshoot:
- Communication blocks between OT systems
- Network latency or performance issues
- Optimize policies for high availability of critical plant systems
Documentation & Reporting
- Prepare:
- Network segmentation diagrams
- Policy documentation
- Security assessment reports
Support audits and compliance reviews