Operational Technology; OT Cyber Threat Analyst
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Information Security, Network Security
Description
RMC is seeking an Operational Technology (OT) Cyber Threat Analyst for a full-time in-office position in San Antonio, TX!
Are you ready to embark on a fulfilling and impactful career journey with Risk Mitigation Consulting (RMC)? We're in search of an exceptional OT Cyber Threat Analyst to become a part of our mission-driven team, dedicated to making a difference in the federal and commercial markets. At RMC, we're all about enhancing security for both our military and global commercial partners, offering an array of services such as Risk Management, Mission Assurance, and Cybersecurity.
Our team's well-being is paramount, and we reflect this commitment through our flexible work environment and exceptional company culture. By joining RMC, you become a key contributor to our mission –
Assuring Tomorrow!
When you join RMC, you'll experience a range of benefits, including:
- Comprehensive health, vision, and dental insurance plans fully covered for employees
- Subsidized dependent health care coverage
- Participation in our Annual Bonus Program
- Life insurance policy equivalent to 1x your annual salary.
- Company paid short and long-term disability
- Cell phone reimbursement of $65 per month
- 401(k) Plan with contributions
- A 401(k) Safe Harbor Employer Contribution Program, which includes a 3% contribution
The OT Cybersecurity Analyst supports the protection and resilience of critical infrastructure environments through threat intelligence analysis, security monitoring, incident response, and vulnerability assessment activities focused on Operational Technology (OT) and Industrial Control Systems (ICS). This role is responsible for identifying and analyzing cyber threats targeting industrial environments, supporting incident response efforts, and helping clients strengthen the security posture of mission‑critical systems across sectors such as energy, water, transportation, and manufacturing.
The position works closely with clients, government partners, and internal technical teams to provide actionable intelligence, risk‑based recommendations, and regulatory compliance support. Successful candidates will bring a strong understanding of OT/ICS environments, evolving cyber threats, and the operational considerations required to secure critical infrastructure systems.
- Monitor, collect, and analyze cyber threat intelligence from open‑source, commercial, and government feeds (ISACs, CISA, sector‑specific advisories) with specific focus on threats targeting critical infrastructure sectors (energy, water, transportation, manufacturing)
- Assess threat actor TTPs (Tactics, Techniques, and Procedures) relevant to ICS/SCADA environments using frameworks such as MITRE ATT&CK for ICS and the Purdue Model
- Produce timely, actionable threat intelligence reports tailored to both technical and executive audiences
- Perform continuous monitoring of OT/ICS network environments, including SCADA systems, PLCs, RTUs, HMIs, and historian servers, for anomalous or malicious activity
- Analyze network traffic, asset telemetry, and security events across IT/OT boundaries using OT‑aware tools (e.g., Claroty, Dragos, Nozomi Networks, Tenable OT)
- Identify and document Indicators of Compromise (IoCs) and Indicators of Attack (IoAs) specific to industrial control system environments
- Triage, investigate, and elevate security incidents in accordance with client incident response plans and sector‑specific regulatory requirements
- Support containment, eradication, and recovery activities for cyber incidents affecting OT/ICS environments, with acute awareness of operational safety and uptime constraints
- Maintain detailed incident timelines, chain‑of‑custody documentation, and post‑incident lessons‑learned reports
- Conduct vulnerability assessments of OT assets, applying risk‑based prioritization that accounts for operational impact, compensating controls, and the consequences of patching in live industrial environments
- Map identified vulnerabilities to threat actor capabilities and likelihood of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).