Staff Network Architect - OT/SCADA
at On.Energy · 101-250 employees
- Seniority
- Staff Principal
- Location
- Houston, Texas, United States
- Posted
- 5d ago
at On.Energy · 101-250 employees
On.Energy is a Miami-headquartered independent power producer that develops, integrates and operates AI-driven battery energy storage systems across the Americas.
<div class="content-intro"><p>ON.energy<span class="Apple-converted-space"> </span>is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software,<span class="Apple-converted-space"> </span>ON.energy<span class="Apple-converted-space"> </span>develops projects worldwide that set new benchmarks for resilience.</p></div><h3>Role Summary</h3> <p>We're hiring a Senior OT/SCADA Network Architect to be the in-house design authority on OT networks for our AI data center UPS projects. You'll work side by side with the engineering manager, who sets direction and approves the architecture. Within that, the design work is yours.<br>We build from a standard base network design that serves as the template for every project, adapted per site for size, topology, and interconnection requirements. You'll help refine that template and apply it project by project, so your work compounds across the portfolio instead of being rebuilt each time.</p> <p> </p> <h3>Key Responsibilities</h3> <p>Architect the OT network</p> <ul> <li>Develop the designs, analyze the options, and make the technical recommendations decisions are built on. The manager gives final approval; the design is your craft.</li> <li>Refine the base design template: zoning model, IP and VLAN scheme, redundancy topology, equipment baseline and adapt it per project, flagging when a site genuinely needs to deviate rather than quietly forcing a fit.</li> <li>Produce the design packages: L1/L2/L3 diagrams, IP and VLAN schedules, switching and routing configurations, port maps, and cable/fiber schedules.</li> <li>Design heavily segmented, multi-zone networks: Purdue-aligned levels, DMZs, conduits between zones, along with the redundancy, QoS, and time synchronization (NTP/PTP/IRIG-B) that keep control traffic reliable.</li> <li>Design site-to-site VPN connectivity into our cloud environment, secure remote access for our engineers and vendors, and out-of-band management.</li> <li>Support design reviews and commissioning: network test plans, troubleshooting during energization, and as-builts. Document decisions clearly enough that project engineers and technicians can execute without re-deriving your reasoning.</li> </ul> <p>Own the IT/OT boundary</p> <ul> <li>Apply a clear model of IT/OT separation: where the boundary sits, what crosses it, and why.</li> <li>Map dataflows end to end, from PCS, BMS, meters, and site SCADA through to our cloud environment and client-facing platforms.</li> <li>Design the DMZ, gateway, and data-transfer patterns that get business systems the data they need without exposing control systems, and coordinate with IT and cloud teams on identity and remote access.</li> </ul> <p>Guide vendor and equipment selection</p> <ul> <li>Recommend network and infrastructure equipment: industrial switches, routers, firewalls, media converters, gateways, to include weighing environmental ratings, form factor, PoE budgets, protocol support, lifecycle, and spares. Present trade-offs, not a single answer.</li> <li>Review vendor and OEM submittals against our base design, recommend how to close gaps, and support procurement with sizing justification and lead-time input.</li> <li>Support spec compute and infrastructure (industrial and rack servers, virtualization sizing, storage, redundant power, UPS) and coordinate with electrical teams on panel layouts, enclosures, grounding, and surge protection.</li> </ul> <p>Design with security in mind</p> <ul> <li>Build in segmentation, least privilege, hardened baselines, and explicit trust boundaries between IT, OT, client, and vendor networks.</li> <li>Contribute to industrial firewall design: zone-to-zone rule sets, OT protocol inspection where required and secure remote access patterns (jump hosts, MFA, SSO).</li> <li>Apply IEC 62443 concepts in design decisions and support compliance and audit work with drawings and documentation.</li> <li>Support asset inventory, network monitoring, and centralized logging so we can see what's on our networks.</li> </ul> <p>Understand the protocols</p> <ul> <li>Know the protocols in our stack: Modbus TCP/RTU, DNP3, IEC 61850, IEC 60870-5-104, OPC UA, MQTT, to include their bandwidth, timing, and segmentation implications, and how to troubleshoot them at the packet level.</li> <li>Our controls and SCADA engineers own protocol configuration and point mapping. You don't need to own that layer, but you do need to speak the language and anticipate how design choices affect it.</li> </ul> <p> </p> <h3>Required Experience</h3> <ul> <li>8+ years in network engineering and architecture, including 5+ years designing OT, ICS, or SCADA networks. This experience can be within energy, utilities, data centers or mission-critical facilities, oil & gas, water, or heavy industry.</li> <li>Proven experience designing heavily segmented, multi-zone networks for large systems. Be ready to walk us through a zoning model you worked on, why the boundaries fell where they did, and what you'd change now.</li> <li>Strong routing and switching: VLANs, trunking, L3 routing (OSPF/BGP/static), NAT, ACLs, spanning-tree and ring redundancy, and structured IP planning.</li> <li>Site-to-site IPsec VPN design and troubleshooting, including tunnel routing, redundancy, and failover.</li> <li>Clear grasp of IT/OT separation and dataflow design: DMZs, gateways, and why a control network isn't just another VLAN.</li> <li>Working fluency in industrial protocols (Modbus, DNP3, IEC 61850 or IEC 60870-5-104, OPC UA) and how they behave on