OT Security Engineer L3
Indexed description
Position Summary
We are seeking an experienced OT Security Engineer L3 to lead the design, deployment, integration, support, and optimization of OT security monitoring solutions across ICS, SCADA, DCS, and IIoT environments. The ideal candidate will bring 6–10 years of experience in OT cybersecurity and industrial network defense, act as the highest technical escalation point within the OT SOC, and drive implementation, threat hunting, incident response, detection engineering, customer engagement, and continuous improvement for complex industrial environments.
Key Roles & Responsibilities
- OT Security Architecture, Deployment, and Implementation
Design OT monitoring architecture for industrial environments covering asset visibility, protocol decoding, segmentation-aware telemetry collection, and secure integration patterns.
Install and configure SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security for OT use cases.
- Integration and Automation
Configure Syslog, REST APIs, STIX/TAXII feeds, automation workflows, and custom integrations for OT firewalls, switches, historians, HMIs, PLCs, and engineering workstations.
- Incident Response and Technical Escalation
Coordinate containment, eradication, recovery, root-cause analysis, and technical communication with customer incident response teams and internal stakeholders.
- Threat Hunting and Detection Engineering
Develop and optimize detection rules, dashboards, correlation logic, and OT-specific use cases to improve fidelity and reduce false positives.
- Security Monitoring, Packet Analysis, and Forensics
Perform advanced packet analysis using Wireshark, support forensic triage, validate malware indicators, and guide evidence collection for OT investigations.
- Customer Engagement and Technical Leadership
Serve as the senior technical SME for OT SOC operations and provide strategic guidance during architecture reviews, escalations, and service improvement planning.
- Engineering, Optimization, and Playbooks
Optimize detection logic, data onboarding, alert tuning, and reporting workflows to improve MTTR, response quality, and customer outcomes.
- OT Domain, Protocol, and Asset Expertise
Demonstrate strong command of industrial protocols such as Modbus, DNP3, IEC 60870-5-104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.
- Reporting and Documentation
Maintain high-quality technical documentation for deployments, incidents, integrations, customer environments, and engineering changes.
- Compliance, Risk, and Assessments
Ensure delivery quality, SLA adherence, audit readiness, and operational alignment with plant safety and production constraints.
- Mentoring and Knowledge Transfer
Drive continuous learning around OT attack techniques, threat intelligence, use-case maturity, and industrial cybersecurity best practices.
- Report deviations and concerns to the SOC Manager
- Bachelor's degree in computer science, Information Technology, Cybersecurity, Electronics, Instrumentation, Industrial Automation, or a related field.
- 6–10 years of experience in OT cybersecurity, ICS/SCADA security monitoring, industrial network engineering, SOC operations, or related security engineering roles.
- Hands-on expertise with OT monitoring and SIEM platforms such as Nozomi Guardian, Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security.
- Strong understanding of ICS, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial switches, and asset visibility concepts.
- Deep knowledge of industrial protocols including Modbus, DNP3, IEC 60870-5-104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.
- Strong OT/industrial networking fundamentals covering TCP/IP, VLANs, routing, switching, firewall policies, VPNs, IDS/IPS, packet capture, and secure remote access.
- Experience with Wireshark, Nmap, PowerShell, Linux, Windows Server, REST APIs, troubleshooting, deployment documentation, and RCA preparation.
- Excellent customer communication, presentation, technical leadership, problem-solving, and mentoring skills.
- Certifications such as GICSP, ISA/IEC 62443 Cybersecurity Expert, CISSP, CEH, CompTIA Security+, Nozomi Certified Engineer, Microsoft SC-200, Splunk Certified Consultant, or equivalent.
- Experience designing OT visibility architectures, deploying collectors/sensors, validating TAP/SPAN strategies, and integrating packet, log, and asset telemetry.
- Exposure to threat intelligence platforms, SOAR orchestration, CMDB/ticketing integrations, custom parser development, and OT-specific detection engineering.
- Working knowledge of Purdue Model, zones and conduits, industrial segmentation, change management in plant environments, and maintenance-window-aware deployment practices.
- Experience supporting industrial sectors such as manufacturing, energy, utilities, pharma, chemicals, transportation, or other critical infrastructure domains.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search