OT SOC Analyst(Nozomi & Splunk)
الوصف الوظيفي
Position Overview
We are seeking an experienced OT SOC Analyst with deep expertise in Nozomi Networks and Splunk Enterprise Security to lead cybersecurity monitoring, incident investigation, threat hunting, and response initiatives within industrial operational technology (OT) environments. The ideal candidate will possess a strong background in securing industrial control systems (ICS), supervisory control and data acquisition (SCADA) networks, and Purdue Architecture-compliant environments. This role requires a proactive approach to identifying and mitigating cyber threats while collaborating closely with cross-functional teams to ensure robust OT security posture.
Key Responsibilities
- Incident Investigation & Response: Lead the investigation and resolution of OT security incidents escalated from Level 1 monitoring teams, ensuring timely and accurate remediation to minimize operational disruption.
- Platform Administration: Monitor, administer, and optimize Nozomi Networks solutions, including Guardian, CMC, and Vantage platforms, to enhance visibility and security across OT environments.
- Threat Detection & Analysis: Conduct advanced threat hunting, perform root cause analysis, and correlate security events using Splunk Enterprise Security (SIEM) to identify and neutralize potential threats before they escalate.
- Use Case Development: Design, implement, and fine-tune OT-specific security use cases, dashboards, and reports within Splunk ES to improve detection capabilities and streamline incident response workflows.
- Cross-Team Collaboration: Partner with OT, IT, and SOC teams to facilitate seamless incident response, remediation efforts, and knowledge sharing to strengthen overall cybersecurity resilience.
- Compliance & Reporting: Support platform onboarding activities, conduct regular health checks, ensure compliance with industry standards (e.g., IEC 62443, NIST SP 800-82), and generate comprehensive security reports for stakeholders.
Qualifications & Skills
To excel in this role, candidates must meet the following requirements:
- Experience: Minimum of 5–8 years in cybersecurity, with at least 3 years dedicated to OT/ICS security operations.
- Technical Proficiency: Hands-on experience with Nozomi Networks (Guardian, CMC, Vantage) and Splunk Enterprise Security (SIEM) is mandatory. Familiarity with OT protocols, SCADA, PLC, HMI, DCS, and Purdue Architecture is essential.
- Industry Standards: Strong understanding of key OT security frameworks, including IEC 62443, NIST SP 800-82, and the MITRE ATT&CK for ICS matrix.
- Certifications (Preferred): NNCE/NNCSE, Splunk certifications (e.g., Splunk Core Certified User, Splunk Enterprise Security Certified Admin), GICSP, GCIH, CEH, Security+, or CCNA.
Why Join Us?
This is an exceptional opportunity to contribute to the cybersecurity resilience of critical industrial infrastructure while working with cutting-edge technologies and industry-leading tools. The successful candidate will play a pivotal role in safeguarding OT environments against evolving cyber threats, ensuring operational continuity and security for our clients.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.