OT Cybersecurity Data Engineer focusing on SIEM solutions for OT environments. Collaborating on security measures and optimizing monitoring for industrial infrastructure.
Responsibilities
Design, implement, and test SIEM and SOAR solutions tailored for OT environments, considering the unique challenges and protocols involved.
Integrate various OT data sources (e.g., IDS, EDR, control system logs, network traffic from industrial protocols) into the SIEM platform.
Develop and maintain custom parsers, normalizers, and correlation rules to effectively analyze OT-specific logs and events within the SIEM.
Collaborate with OT operations and engineering teams to understand their systems, data sources, and security monitoring requirements.
Configure and optimize the SIEM platform for performance, scalability, and stability in an OT context.
Develop and maintain OT-focused dashboards and reports within the SIEM to provide actionable insights into security posture and potential threats.
Tune and optimize SIEM rules and alerts to minimize false positives and ensure high-fidelity detection of OT security incidents.
Develop and maintain documentation for the OT SIEM architecture, data sources, rules, and operational procedures.
Collaborate with IT security teams to ensure seamless integration and correlation of security events across both IT and OT environments.
Stay up-to-date on the latest OT cybersecurity threats, vulnerabilities, and SIEM capabilities relevant to industrial control systems.
Evaluate and recommend new SIEM features, integrations, and related security technologies for enhancing OT security monitoring.
Provide training and support to security analysts and other stakeholders on the use of the OT SIEM.
Requirements
Demonstrated experience working with SIEM platforms (e.g., Sumo Logic, Palo Alto Cortex XSOAR) and a strong understanding of their architecture, configuration, and rule development.
Understanding of OT protocols (e.g., Modbus, DNP3, IEC 61850), industrial control systems (e.g., PLC, SCADA, DCS), and their logging mechanisms.
Experienced in parsing and normalizing complex log formats, including those specific to OT devices and applications.
5+ years of experience integrating OT data sources with enterprise SIEM platforms.
Knowledge of security frameworks and standards relevant to OT (e.g., NIST SP 800-82, IEC 62443).
Experienced in scripting languages (e.g., Python, PowerShell) for SIEM automation and data manipulation.
Relevant certifications such as GICSP, GRID, CISSP, or SIEM-specific certifications.
Familiarity with threat intelligence platforms and their integration with SIEM for OT threat detection.
Willing to work with shift timings: 12:00 PM to 09:00 PM.
Benefits
Comprehensive mindfulness programmes with a premium membership to Calm.
Volunteer Paid Time off available after 6 months of employment for eligible employees.
Company volunteer and donation matching programme – Your volunteer hours or personal cash donations to an eligible charity can be matched with a charitable donation.
Employee Assistance Program.
Personalised wellbeing programs through our OnTrack programme.
On-demand digital course library for professional development.
Security Supervisor providing comprehensive safety services across Nord Anglia International School campus. Leading security team to ensure operational and Health and Safety compliance while mitigating risks.
Security Officer ensuring safety and compliance at WarHorse Gaming in Lincoln, NE. Monitoring premises, responding to incidents, and assisting guests and team members.
Security Supervisor overseeing loss prevention and security operations at WarHorse Gaming Lincoln casino. Ensuring a safe environment for guests and team members while upholding regulatory requirements.
Consultor de Segurança do Trabalho na Votorantim Cimentos consolidando medidas de segurança e gestão de EPIs. Gestão de processos e compliance em segurança de trabalho com foco em excelência.
Coordination role for Health and Safety in Underground Mine at Atlantic Nickel in Itagibá/BA. Focus on strategies for safety and health systems in underground operations.
Entry - Level Software Security Engineer at Tektronix focusing on secure product development and automation scripting. Collaborating with engineers to maintain cybersecurity best practices and standards.
Senior Cybersecurity Engineer at GM Financial designing scalable security capabilities to mitigate threats. Collaborating across teams and leveraging automation for enhanced security measures.
Senior Security Implementation Consultant responsible for implementing security controls in HPC environments. Working with teams on PKI, PAM, IAM, and infrastructure security solutions.
Lead Security Architect at Synchrony focusing on Zero Trust networking across various environments. Partnering with teams to design and implement secure connectivity and policies.
Enterprise Account Specialist engaging with key clients to design customized solutions within sales. Conducting market research and driving contract renewals for mid - to - large accounts.