Senior SOC Engineer – OT/ICS Cybersecurity
Location
Doha, Qatar
Job Category- Information Technology (IT) & Software
- Engineering & Technical
- Telecommunications
- Energy, Oil & Gas
- Security & Defence
We are seeking a Senior SOC Engineer – OT/ICS Cybersecurity with 5–8 years of relevant experience in operational technology and industrial control system security. The role focuses on security monitoring and incident response across SCADA, DCS, PLC, and other OT/ICS environments
, with responsibility for threat detection, investigation, containment, and cybersecurity operations.
The successful candidate will work with technologies including SIEM platforms, Microsoft Sentinel or equivalent solutions, Nozomi, Forescout, packet analysis, OT asset visibility, and industrial network security. Strong knowledge of OT architecture, segmentation, industrial protocols, and cybersecurity frameworks will be essential to protecting critical industrial environments.
This position offers opportunities for career growth, professional development, advanced OT cybersecurity expertise, and technical specialization
. Candidates holding recognized OT/ICS cybersecurity certifications will be well positioned for continued progression within industrial cybersecurity and Security Operations Center environments.
- Monitor OT/ICS environments including SCADA, DCS, and PLC systems for cybersecurity threats and anomalies.
- Administer SIEM platforms and tune detection rules to improve threat identification.
- Operate Microsoft Sentinel or equivalent SIEM technologies.
- Utilize OT security platforms such as Nozomi and Forescout.
- Investigate and respond to OT cybersecurity incidents.
- Perform incident containment and support service restoration activities.
- Conduct OT threat hunting and anomaly detection.
- Apply the Purdue Model to OT network security architecture.
- Design and maintain OT DMZ and network segmentation strategies.
- Support micro-segmentation and Zero Trust security approaches for OT environments.
- Perform packet analysis and Deep Packet Inspection.
- Work with packet brokers and TAP/SPAN technologies.
- Analyze industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
- Maintain OT asset visibility and support vulnerability-management activities.
- Apply MITRE ATT&CK for ICs techniques to threat detection and security analysis.
- Support compliance with IEC 62443 and NIST ICs cybersecurity requirements.
- Collaborate with relevant technical and cybersecurity teams to strengthen OT security controls.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field
. - 5–8 years of relevant professional experience
. - Strong hands-on experience in OT/ICS cybersecurity
. - Practical experience securing SCADA, DCS, and PLC environments.
- Experience with SIEM administration and detection-rule tuning.
- Experience with Microsoft Sentinel or an equivalent SIEM platform.
- Knowledge of Nozomi and Forescout.
- Strong OT incident response, containment, threat hunting, and anomaly-detection capabilities.
- Knowledge of the Purdue Model, OT DMZ, network segmentation, and micro-segmentation.
- Understanding of Zero Trust principles within OT environments.
- Experience with packet analysis, Deep Packet Inspection, packet brokers, TAP, and SPAN technologies.
- Strong knowledge of industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
- Experience with OT asset visibility and vulnerability management.
- Knowledge of MITRE ATT&CK for ICs.
- Understanding of IEC 62443 and NIST ICs cybersecurity frameworks.
At least ONE of the following certifications is required:
- GICSP
- ISA/IEC 62443 Cybersecurity Certificate
- GRID
- IACS
OT/ICS cybersecurity experience and at least one of the listed certifications are essential requirements.
Salary, Benefits & Career GrowthSalary and specific employment benefits have not been provided in the job posting.
The position provides opportunities for career progression and professional development within OT/ICS cybersecurity and SOC operations
. Continued training and certification in industrial cybersecurity frameworks, threat detection, incident response, and OT security technologies can support long-term technical advancement.
The role also provides valuable exposure to critical industrial environments, cybersecurity monitoring, threat hunting, OT network architecture, and compliance frameworks.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).