OT Incident Response Analyst
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 6–10 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity or Engineering
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The OT SOC Level 3 Analyst serves as the lead technical authority within the Operational Technology Security Operations Center, overseeing sophisticated threat hunting, digital forensics and incident response tailored for OT environments, detection engineering, and mentoring junior analysts. This role orchestrates the handling of intricate, high-impact OT incidents, enhances detection capabilities, and acts as the escalation point and subject-matter expert in industrial threat scenarios. They transform OT threat intelligence into actionable detection rules and advocate for continuous enhancement of OT cybersecurity defenses.
Key Responsibilities
- Lead investigations and response efforts for complex and severe attacks targeting OT and ICS environments.
- Conduct proactive threat hunts based on hypotheses across OT assets and networks, designing and executing hunt campaigns.
- Perform OT-specific digital forensics acquisitions and analyses on ICS hosts, engineering workstations, HMIs, controllers, and network traffic ensuring process safety and evidence preservation.
- Develop, implement, and fine-tune detection content and correlation rules, managing the detection engineering lifecycle within the OT SOC.
- Integrate OT threat intelligence (including threat actors like ELECTRUM, Sandworm, XENOTIME and malware such as TRITON, Industroyer, PIPEDREAM) with the MITRE ATT&CK for ICS framework to guide detections.
- Create and continuously refine OT incident response playbooks and runbooks.
- Act as a senior escalation resource and provide mentorship for Level 1 and Level 2 analysts, delivering technical coaching and investigative quality assurance.
- Lead OT tabletop scenarios and purple team exercises simulating adversary tactics.
- Offer consultancy on OT network design, segmentation, and sensor placement to address detection deficiencies.
- Prepare comprehensive executive and technical incident reports, briefing stakeholders on root cause, impact, and remediation steps.
- Assist with compliance and audit reporting aligned with NCA OTCC-1:2022, ECC, and ISA/IEC 62443 standards, including incident notification protocols to the NCA.
Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Electrical/Instrumentation Engineering, or equivalent; Master’s degree is advantageous.
- 6 to 10 years of cybersecurity experience with at least 4 years focused on OT/ICS security operations, threat hunting, or DFIR.
- In-depth knowledge of OT protocols, ICS architectures such as DCS, SCADA, PLC, SIS, and the Purdue reference model.
- Proven track record in leading OT/ICS incident response and forensic investigations.
- Expertise with OT monitoring solutions including Nozomi, Claroty, Dragos, Tenable OT, and Defender for IoT, plus SIEM detection engineering tools like Splunk, QRadar, and Sentinel.
- Strong understanding of frameworks like MITRE ATT&CK for ICS, NIST SP 800-82, ISA/IEC 62443, and NCA OTCC standards.
Preferred Certifications
- Certifications such as GRID, GCIP, GICSP, GCFA, or GREM from GIAC are highly desired.
- High-level vendor certifications from Dragos, Claroty, or Nozomi are a plus.
Skills and Personal Attributes
- Advanced analytical skills including forensic investigation and malware reverse engineering within operational technology contexts.
- Strong leadership capabilities with effective mentoring and stakeholder engagement skills.
- Ability to make well-informed decisions balancing cybersecurity actions with process safety and operational continuity.
- Exceptional proficiency in English communication, both written and oral; Arabic is strongly preferred for engaging with regulatory bodies and executives.
- Willingness to support on-call incident escalation and leadership responsibilities beyond regular working hours.
Minimum education
Bachelor's Degree
Industry
Management Consulting