Skip to main content

OT Security Engineer, Architect, or Manager: Which Role Do You Actually Need?

You have approval for an OT security hire. Engineering wants someone who can work through technical problems. The security team wants a consistent design across plants. Leadership wants a plan, a budget, and someone accountable for progress. Which title goes on the requisition?

Start by deciding which of those needs will occupy most of the person's working week. Engineer, architect, and manager describe different centers of responsibility. A title can help candidates find the position, but the work behind it determines whether the search reaches the right people.

Write down the decisions waiting for this person

Take three unfinished pieces of work and describe what is preventing progress. A sensor rollout may need an engineer who can coordinate deployment and investigate missing traffic. Conflicting remote access designs may need an architect who can establish an approved approach. A stalled program may need a leader who can agree priorities and obtain resources.

NIST's NICE Framework separates work roles from job titles. An employer can combine responsibilities within a job, and a team can share a work role. That is a useful starting point for hiring: describe the responsibilities first, then choose a title that makes the position recognizable.

What each role is expected to own

The boundaries between these roles vary by employer. An experienced engineer may lead a major deployment without managing staff. An architect may remain deeply involved in implementation. A manager may need substantial technical judgment while spending much of the week on staffing, budgets, and decisions.

What each role is expected to own
RoleTypical center of responsibilityEvidence to explore
OT security engineerImplementing, operating, and improving controls in an industrial environment.Changes delivered, investigations completed, and coordination with plant engineering.
OT security architectDesign choices, technical standards, and how controls fit together across systems or sites.Design decisions, operational tradeoffs, exceptions, and implementation follow-through.
OT security managerPriorities, people, resources, delivery, and communication with business leadership.Work assigned, resources secured, decisions escalated, and program outcomes owned.

A three-plant example

Imagine a manufacturer with capable controls engineers at each plant and an established corporate security team. Each site has developed its own way of connecting vendors. The company now wants a common approach, but local operating requirements differ. Hiring an architect could make sense if the immediate work is to develop the design, settle exceptions, and guide the existing teams through implementation.

Change the situation slightly. The company already has an approved design, but deployments keep slipping because nobody has time to configure, coordinate, document, and troubleshoot them. That points toward an engineering hire. If neither funding nor site participation has been agreed, the company also needs a leadership decision before a technical hire can make meaningful progress.

Give the role enough authority to do the job

A person responsible for a design needs a route to resolve disagreement over that design. A person responsible for delivery needs access to the teams and information required to deliver. A manager expected to build a team needs to know whether additional headcount is approved, proposed, or unavailable.

Put those boundaries in the hiring brief. State who approves technical changes, who owns plant scheduling, and who resolves competing priorities. Candidates should be able to understand how a decision moves through the business. A broad title with no practical authority makes the role harder to assess and harder to accept.

Choose interview questions from the actual work

For an engineer, ask the candidate to walk through a change they implemented, including preparation, approvals, unexpected behavior, and handover. For an architect, examine a design decision and the constraints that shaped it. For a manager, explore how they chose priorities when resources were limited and how they secured agreement from operations.

Listen for the candidate's own responsibility. Being present during a project is different from owning its design, carrying out its implementation, or being accountable for its delivery. The distinction helps you compare people whose titles differ but whose experience may fit the same need.

Give the recruiter a position they can explain

A usable brief names the primary responsibility, the important decisions, the reporting relationship, and the support already in place. It also identifies the work this person will hand to someone else. With that information, a recruiter can explain the opportunity in a way a qualified practitioner can recognize and evaluate.

Tell Zylarity what you need this person to own. We can help shape the role and the experience the search should look for.

Start Your Hiring Brief