CPX

Lead SOC Engineer - OT Cybersecurity

CPX

Abu Dhabi, United Arab Emirates · Full Time

Be the first to apply

Experience
8–10 yrs
Salary
Openings
1
Posted
3 days ago
Work mode
In office
Education
Bachelor's degree in computer science, IT, cybersecurity or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Overview

This senior technical leadership position is focused on the development and deployment of advanced threat detection capabilities specifically for Operational Technology (OT) environments. As part of CPX's hybrid Security Operations Centers (SOCs), the role involves engineering detection methods, integrating OT telemetry, and improving visibility of Industrial Control Systems (ICS) and SCADA infrastructure. The ideal candidate must have in-depth knowledge of OT cybersecurity, skilled threat hunting capabilities, SOC operational experience, and a strong grasp of regional industrial sectors and compliance frameworks.

Key Responsibilities

  • Engineer tailored detection logic, use cases, and correlation rules within SIEM solutions to boost threat detection accuracy and reduce false alarms in OT environments.
  • Develop and enhance SOAR playbooks to automate workflow processes for investigating and responding to both OT and IT security incidents.
  • Create, refine, and document SOC alert mechanisms ensuring precise detection and efficient operational handoff to security analysts.
  • Implement and fine-tune OT security tools such as Dragos, Claroty, and Nozomi to increase system monitoring and asset visibility.
  • Onboard diverse OT telemetry sources including PLC log data, historian systems, network telemetry, and asset inventories into SIEM and SOAR platforms to support SOC operations.
  • Collaborate closely with SOC analysts and IT/OT teams to validate detection mechanisms, improve incident triage, and foster smooth integration of OT security monitoring.
  • Ensure detection and incident response procedures comply with applicable standards and regulations like NESA, SAMA, NIST 800-82, and IEC 62443.
  • Lead or support incident investigations on OT assets, bringing expert knowledge during response and post-incident analysis.

Required Expertise and Certifications

  • Advanced skills in OT detection engineering, particularly for ICS/SCADA systems and protocols.
  • Deep familiarity with OT/ICS communication protocols such as Modbus, DNP3, OPC, and IEC 61850, and their security considerations.
  • Proven experience developing and tuning SIEM use cases tailored for OT, using platforms like QRadar or Splunk, focused on reducing false positives.
  • Competency in integrating OT telemetry sources to support comprehensive security monitoring.
  • Proficiency in programming languages such as Python and PowerShell for automation and custom alert development.
  • Strong ability to coordinate and communicate with cross-functional teams including SOC analysts, OT engineers, and incident response units.
  • Sound understanding of regional SOC operations and OT threat landscapes, especially in Middle Eastern industrial contexts.
  • Certifications including CISSP, CISM, or equivalents for cybersecurity; OT-focused certifications like GICSP, GRID, ISA/IEC 62443, Dragos, or Nozomi; networking certifications such as CCNP/CCIE; and optionally SOAR or SIEM-related credentials.

Qualifications and Experience

  • At least 8 to 10 years of experience working within SOC environments, with significant focus on OT cybersecurity.
  • Demonstrated track record in a leadership engineering role within SOC or industrial cybersecurity domains.
  • A bachelor's degree in computer science, IT, cybersecurity or related disciplines; a master's degree or equivalent professional cybersecurity certifications are preferred.

Level

Lead

Minimum education

Bachelor's Degree

Industry

Cybersecurity

How they work

Communication Teamwork & Collaboration Leadership

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer