Назад
Company hidden
6 дней назад

Cybersecurity Monitoring Lead (OT/ICS)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Monitoring Lead (OT/ICS): Building and leading a hybrid SOC in Bucharest to monitor and respond to threats across enterprise IT and industrial environments supporting HVDC and FACTS stations, with an accent on detection engineering, incident response, and SOC operating-model design. Focus on leading analysts, optimizing Splunk-based SIEM and related monitoring technologies, and balancing cybersecurity, operational continuity, and safety requirements.

Location: Hybrid role based in the Bucharest office, Romania

Company

hirify.global develops energy technologies and grid solutions, including HVDC transmission, grid stabilization, storage, high-voltage equipment, and digital grid technologies.

What you will do

  • Establish and lead a new Security Operations Center in Bucharest covering enterprise IT and OT security monitoring for HVDC and FACTS stations.
  • Build, mentor, and manage the SOC analyst team, including roles, shift models, on-call rotations, and development paths.
  • Define SOC operating models, processes, use cases, playbooks, escalation procedures, metrics, KPIs, and SLAs.
  • Act as the senior escalation point for security incidents, coordinating triage, investigation, containment, recovery, and major incident response.
  • Lead detection strategy and content development across Splunk SIEM, EDR/XDR, NDR, and specialized OT/ICS monitoring technologies.
  • Coordinate with cybersecurity, OT engineering, automation, IT, operations, and client-facing service teams while aligning activities with IEC 62443, NIST CSF, ISO 27001, and NIS2.

Requirements

  • At least 5 years of cybersecurity experience, including SOC, incident response, detection engineering, or threat hunting, with 2–3 years in a lead or team management role.
  • Experience building or operationalizing SOC capabilities across enterprise IT and preferably OT, industrial, energy, utilities, grid, or critical infrastructure environments.
  • Strong knowledge of IT security, ICS/OT architectures, PLC, HMI, SCADA, DCS, industrial networking, and protocols such as Modbus, PROFINET, DNP3, IEC 60870-5-104, OPC UA, and EtherNet/IP.
  • Advanced knowledge of SIEM, EDR/XDR, NDR, detection engineering, correlation rules, threat hunting, and detection tuning; hands-on Splunk experience is strongly preferred.
  • Experience leading incident response, investigations, forensic analysis, people management, stakeholder communication, and SOC maturity initiatives.
  • Fluent English is required. Willingness to travel internationally occasionally is expected.

Nice to have

  • Experience with HVDC, FACTS, power transmission, or grid environments.
  • German language skills.

Culture & Benefits

  • Hybrid work from the Bucharest office in One Cotroceni Park.
  • Training opportunities and professional development support.
  • Meal tickets, medical subscription, private pension, wellbeing initiatives, and Bookster access.
  • Work within a cross-border organization focused on sustainable, reliable, and affordable energy.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →