обновлено 2 месяца назад
Lead SOC Engineer (OT Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead SOC Engineer (OT Cybersecurity) (ICS/SCADA, SIEM, SOAR): Designing and implementing advanced threat detection capabilities for OT environments, integrating industrial telemetry, and improving visibility across ICS/SCADA systems with an accent on detection engineering, threat hunting, and SOC operations. Focus on building OT-specific SIEM use cases and SOAR playbooks, integrating Dragos, Claroty, and Nozomi platforms, and supporting incident investigations across industrial environments.
Location: MBZ City, Abu Dhabi, United Arab Emirates
Company
operates in technology and cybersecurity, with this role supporting CPX’s hybrid Security Operations Centers.
What you will do
- Design, develop, and fine-tune OT-specific detection use cases, correlation rules, and analytics in SIEM platforms.
- Build, maintain, and optimize SOAR playbooks for automated investigation and response workflows.
- Create and document high-fidelity SOC alert logic and support operational handover to analysts.
- Deploy and optimize OT security platforms including Dragos, Claroty, and Nozomi.
- Integrate PLC logs, historian data, network telemetry, and asset inventories into SIEM, SOAR, and SOC workflows.
- Lead or support technical investigations involving OT assets and contribute to post-incident reviews.
Requirements
- 8–10 years of experience in SOC operations, including significant OT cybersecurity experience.
- Prior experience in a lead engineering role within a SOC or industrial cybersecurity environment.
- Advanced experience designing OT detection logic for ICS/SCADA systems and industrial protocols.
- Hands-on expertise with Modbus, DNP3, OPC, and IEC 61850.
- Experience developing SIEM use cases in platforms such as QRadar or Splunk and integrating OT telemetry.
- Proficiency in Python and PowerShell, plus a bachelor’s degree in computer science, IT, cybersecurity, or a related field.
Nice to have
- CISSP, CISM, GICSP, GRID, ISA/IEC 62443, Dragos, Nozomi, CCNP, or CCIE certifications.
- Master’s degree or equivalent recognized cybersecurity certifications.
- Additional certifications related to SOAR or SIEM solutions.
Culture & Benefits
- Work within CPX’s hybrid Security Operations Centers.
- Collaborate with SOC analysts, OT engineers, IT/OT teams, and incident response specialists.
- Align detection and response strategies with NESA, SAMA, NIST 800-82, and IEC 62443 frameworks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →