Sr. SOC Engineer - Up to 26k QAR
Job Description & How to Apply Below
Administration, management, and Support deployment and tuning of OT security tools (Nozomi, Forescout).
- Administration, management, and Support deployment and tuning of OT security tools (Nozomi, Forescout).
- Monitor OT/ICS environments using SIEM and OT security monitoring platforms
- Detect, analyze, and respond to cyber threats targeting industrial control systems
- Support and ensure micro segmentation strategies for OT network zones (Purdue Model alignment)
- Collaborate with engineering teams to safely implement containment actions in live OT environments
- Conduct threat hunting across industrial environments using network and log data
- Handle and support incident response for OT cyber events with minimal operational disruption
- Maintain OT asset visibility and network behavior baselines
- Ensure compliance with IEC 62443, NIST ICS, and organizational security standards
- Work with firewall, IDS/IPS, NAC, and segmentation technologies in OT networks
- Develop and tune OT-specific detection rules and correlation logic in SIEM platforms.
- Align detection use cases with MITRE ATT&CK for ICS framework.
- Reduce false positives and improve detection accuracy and coverage.
- Periodically review and optimize alert thresholds and detection logic.
- Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation tools.
- Assist in onboarding log sources, parser development, and normalization of OT data.
- Optimize dashboards, alerts, and reporting for operational visibility.
- Operate packet brokers and TAP infrastructure to enable full OT network visibility.
- Perform deep packet inspection of industrial protocols (Modbus, DNP3, OPC-UA, IEC 104, Ethernet/IP).
- Analyze east-west and north-south traffic for suspicious activity and lateral movement.
- Identify unauthorized communications and protocol anomalies.
- Support network telemetry collection for OT environments.
- Maintain complete OT asset inventory and network topology visibility.
- Identify unauthorized devices, rogue connections, and shadow OT assets.
- Conduct proactive threat hunting using logs, network telemetry, and behavioral analytics.
- Correlate threat intelligence with OT environment risks and vulnerabilities.
- Ensure compliance with IEC 62443, NIST ICS, ISO standards, and internal security policies.
- Support internal/external audits and provide security evidence for compliance reporting.
- Contribute to risk assessments and OT security posture improvement initiatives.
- Prepare and present OT security reports (incidents, risks, and trends)
- Maintain dashboards for vulnerabilities, threats, and compliance status
- Communicate critical incidents and risks to SOC, OT, and business stakeholders
- Provide executive-level reporting on OT security posture and exposure
- Track remediation status and SLA Tracking
- Support audit and regulatory reporting requirements (IEC 62443, NIST ICS)
- Bachelor’s degree in Cybersecurity, Information Security, Computer science or related field.
Certification any one Mandatory:
- GIAC Global Industrial Cyber Security Professional (GICSP)
- ISA/IEC 62443 Cybersecurity Certificate
- GIAC Response and Industrial Defense (GRID)
- ISA Certified Automation Cybersecurity Specialist (IACS)
- Microsegmentation & Zero Trust for OT
- Packet analysis & Deep Packet Inspection (DPI)
- Packet brokers & TAP/SPAN technologies
- Incident response in OT environments
- OT threat hunting & anomaly detection
- Industrial firewalling & remote access security
- OT vulnerability management & asset visibility
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×