OT Cybersecurity Data Engineer focusing on SIEM solutions for OT environments. Collaborating on security measures and optimizing monitoring for industrial infrastructure.
Responsibilities
Design, implement, and test SIEM and SOAR solutions tailored for OT environments, considering the unique challenges and protocols involved.
Integrate various OT data sources (e.g., IDS, EDR, control system logs, network traffic from industrial protocols) into the SIEM platform.
Develop and maintain custom parsers, normalizers, and correlation rules to effectively analyze OT-specific logs and events within the SIEM.
Collaborate with OT operations and engineering teams to understand their systems, data sources, and security monitoring requirements.
Configure and optimize the SIEM platform for performance, scalability, and stability in an OT context.
Develop and maintain OT-focused dashboards and reports within the SIEM to provide actionable insights into security posture and potential threats.
Tune and optimize SIEM rules and alerts to minimize false positives and ensure high-fidelity detection of OT security incidents.
Develop and maintain documentation for the OT SIEM architecture, data sources, rules, and operational procedures.
Collaborate with IT security teams to ensure seamless integration and correlation of security events across both IT and OT environments.
Stay up-to-date on the latest OT cybersecurity threats, vulnerabilities, and SIEM capabilities relevant to industrial control systems.
Evaluate and recommend new SIEM features, integrations, and related security technologies for enhancing OT security monitoring.
Provide training and support to security analysts and other stakeholders on the use of the OT SIEM.
Requirements
Demonstrated experience working with SIEM platforms (e.g., Sumo Logic, Palo Alto Cortex XSOAR) and a strong understanding of their architecture, configuration, and rule development.
Understanding of OT protocols (e.g., Modbus, DNP3, IEC 61850), industrial control systems (e.g., PLC, SCADA, DCS), and their logging mechanisms.
Experienced in parsing and normalizing complex log formats, including those specific to OT devices and applications.
5+ years of experience integrating OT data sources with enterprise SIEM platforms.
Knowledge of security frameworks and standards relevant to OT (e.g., NIST SP 800-82, IEC 62443).
Experienced in scripting languages (e.g., Python, PowerShell) for SIEM automation and data manipulation.
Relevant certifications such as GICSP, GRID, CISSP, or SIEM-specific certifications.
Familiarity with threat intelligence platforms and their integration with SIEM for OT threat detection.
Willing to work with shift timings: 12:00 PM to 09:00 PM.
Benefits
Comprehensive mindfulness programmes with a premium membership to Calm.
Volunteer Paid Time off available after 6 months of employment for eligible employees.
Company volunteer and donation matching programme – Your volunteer hours or personal cash donations to an eligible charity can be matched with a charitable donation.
Employee Assistance Program.
Personalised wellbeing programs through our OnTrack programme.
On-demand digital course library for professional development.
Data Security Software Engineer developing common security software for Dell’s server and storage products. Collaborating on cryptography security - related software/services and encryption algorithms implementation.
Principal Data Security Software Engineer focused on developing security software for Dell’s server and storage products. Collaborating with top engineers to design and implement cryptography solutions.
Information Security Officer ensuring compliance with security standards at Xecuro GmbH. Focused on enhancing security measures and consulting on information security issues for internal and external clients in Bonn.
Manager, IT Project Security leading large cybersecurity projects for Royal Caribbean Group. Ensuring delivery of strategic security programs while managing risk and compliance across environments.
Analista de Redes e Segurança Pleno responsável pela implantação e sustentação de infraestruturas de rede e segurança. Atuando em ambientes corporativos e projetos governamentais com soluções Fortinet.
Security Managed Services Engineer responsible for troubleshooting incidents and managing firewall configurations at NTT DATA, a global technology services leader.
Técnico de Segurança Jr na Reckitt, responsável por apoiar o desenvolvimento da cultura de segurança e saúde. Implementando procedimentos e processos para garantir a eficiência e qualidade na operação.
Security Operations Engineer protecting cloud infrastructure and enhancing the software development lifecycle. Join a leading healthcare AI company dedicated to transforming workforce productivity.
Cloud Security Engineer at Fiserv implementing cybersecurity measures to safeguard sensitive data. Collaborating with teams to design security solutions and maintain compliance in the fintech sector.
Intern role focusing on collaborative security testing engagements at Assurity Trusted Solutions. Gaining hands - on experience in cybersecurity assessment activities with guidance from senior professionals.