Lead SOC Engineer - OT Cybersecurity
Abu Dhabi, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 8–10 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Education
- Bachelor's degree in computer science, IT, cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
This senior technical leadership position is focused on the development and deployment of advanced threat detection capabilities specifically for Operational Technology (OT) environments. As part of CPX's hybrid Security Operations Centers (SOCs), the role involves engineering detection methods, integrating OT telemetry, and improving visibility of Industrial Control Systems (ICS) and SCADA infrastructure. The ideal candidate must have in-depth knowledge of OT cybersecurity, skilled threat hunting capabilities, SOC operational experience, and a strong grasp of regional industrial sectors and compliance frameworks.
Key Responsibilities
- Engineer tailored detection logic, use cases, and correlation rules within SIEM solutions to boost threat detection accuracy and reduce false alarms in OT environments.
- Develop and enhance SOAR playbooks to automate workflow processes for investigating and responding to both OT and IT security incidents.
- Create, refine, and document SOC alert mechanisms ensuring precise detection and efficient operational handoff to security analysts.
- Implement and fine-tune OT security tools such as Dragos, Claroty, and Nozomi to increase system monitoring and asset visibility.
- Onboard diverse OT telemetry sources including PLC log data, historian systems, network telemetry, and asset inventories into SIEM and SOAR platforms to support SOC operations.
- Collaborate closely with SOC analysts and IT/OT teams to validate detection mechanisms, improve incident triage, and foster smooth integration of OT security monitoring.
- Ensure detection and incident response procedures comply with applicable standards and regulations like NESA, SAMA, NIST 800-82, and IEC 62443.
- Lead or support incident investigations on OT assets, bringing expert knowledge during response and post-incident analysis.
Required Expertise and Certifications
- Advanced skills in OT detection engineering, particularly for ICS/SCADA systems and protocols.
- Deep familiarity with OT/ICS communication protocols such as Modbus, DNP3, OPC, and IEC 61850, and their security considerations.
- Proven experience developing and tuning SIEM use cases tailored for OT, using platforms like QRadar or Splunk, focused on reducing false positives.
- Competency in integrating OT telemetry sources to support comprehensive security monitoring.
- Proficiency in programming languages such as Python and PowerShell for automation and custom alert development.
- Strong ability to coordinate and communicate with cross-functional teams including SOC analysts, OT engineers, and incident response units.
- Sound understanding of regional SOC operations and OT threat landscapes, especially in Middle Eastern industrial contexts.
- Certifications including CISSP, CISM, or equivalents for cybersecurity; OT-focused certifications like GICSP, GRID, ISA/IEC 62443, Dragos, or Nozomi; networking certifications such as CCNP/CCIE; and optionally SOAR or SIEM-related credentials.
Qualifications and Experience
- At least 8 to 10 years of experience working within SOC environments, with significant focus on OT cybersecurity.
- Demonstrated track record in a leadership engineering role within SOC or industrial cybersecurity domains.
- A bachelor's degree in computer science, IT, cybersecurity or related disciplines; a master's degree or equivalent professional cybersecurity certifications are preferred.