Назад
Company hidden
7 дней назад

IT/OT L2 Cybersecurity Monitoring Specialist (ICS/OT)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT/OT L2 Cybersecurity Monitoring Specialist (ICS/OT): Monitoring, investigating, and responding to security threats across enterprise IT and industrial OT environments supporting HVDC stations, with an accent on SIEM, EDR/XDR, NDR, and ICS/SCADA security. Focus on analyzing complex alerts, threat hunting, tuning detection content, and driving incidents toward containment while preserving operational continuity and safety.

Location: Bucharest, Romania; hybrid remote/office

Company

hirify.global develops energy technologies for reliable, sustainable, and digital power infrastructure across more than 90 countries.

What you will do

  • Monitor, triage, prioritize, and investigate security alerts across enterprise IT and industrial OT environments supporting HVDC stations.
  • Perform L2 analysis of complex alerts, determine scope and impact, distinguish true positives from false positives, and drive incidents toward containment and resolution.
  • Correlate endpoint, network, SIEM, EDR/XDR, NDR, and ICS/OT data to reconstruct event timelines and identify root causes.
  • Develop and tune detection content, correlation rules, analytics, alerts, SOC playbooks, runbooks, and escalation procedures.
  • Conduct threat hunting, document investigations, maintain case records, and provide clear incident handovers.
  • Collaborate with OT engineering and operations teams while ensuring security actions preserve operational continuity and safety.

Requirements

  • At least 3 years of hands-on cybersecurity experience, including SOC, incident response, monitoring, or detection work at an L2 level.
  • Strong knowledge of endpoint, network, identity, infrastructure, operating system, and network traffic security across Windows and Linux.
  • Practical experience with SIEM, EDR/XDR, and NDR tools; Splunk experience is strongly preferred.
  • Knowledge of attack techniques, incident lifecycle, log analysis, cybersecurity frameworks, and standards including IEC 62443, NIST CSF, ISO 27001, and NIS2.
  • Exposure to ICS/OT environments such as PLC, HMI, SCADA, DCS, and industrial networking; knowledge of Modbus, PROFINET, DNP3, IEC 60870-5-104, OPC UA, or EtherNet/IP is beneficial.
  • Fluent English required. Strong analytical, communication, documentation, and incident-response skills are expected.

Nice to have

  • Direct experience with OT, HVDC, power transmission, or electrical grid environments.
  • German language skills.

Culture & Benefits

  • Hybrid work from the Bucharest office and remotely.
  • Training opportunities and professional development.
  • Meal tickets, medical subscription, private pension, wellbeing initiatives, and Bookster access.
  • Inclusive, international environment with colleagues from more than 130 nationalities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →