Senior OT Security Analyst
Quick Summary
3–5 years of experience in network security, ideally including hands-on experience investigating real-world threats and suspicious network activity. Strong understanding of core networking concepts,
This senior cybersecurity role supports frontline monitoring and threat detection across customer operational technology environments. You’ll investigate suspicious network activity, validate detection triggers, and help identify potential threats affecting industrial systems and critical infrastructure. Working alongside threat hunters, incident responders, platform engineers, and detection specialists, you’ll turn technical findings into clear, actionable escalations. The role also includes maintaining customer OT security environments, tuning detections, managing vulnerabilities, and improving asset visibility and protection. You’ll provide technical guidance to other analysts while continuously expanding your expertise in ICS/OT protocols, adversary behavior, and industrial threat intelligence. This is a remote, mission-driven environment suited to cybersecurity professionals who want hands-on experience defending operational systems where security has real-world consequences.
- Lead frontline shift operations, guiding analysts as they triage alerts and network telemetry across customer OT environments and stepping into regional shift-lead responsibilities when required.
- Conduct senior-level investigations into suspicious activity, identifying network anomalies, configuration issues, and potential malicious behavior within industrial environments.
- Analyze and escalate findings to incident responders and threat hunters with clear, detailed, and actionable documentation that supports effective investigation and response.
- Collaborate across cybersecurity teams, including analysts, threat hunters, incident responders, platform engineers, and Detection Engineering, to improve detection logic, reduce false positives, and develop new detections and playbooks.
- Prepare incident summaries and operational reports that clearly communicate security findings, trends, and environmental activity to internal stakeholders and customers.
- Support the broader OT security service, including asset classification, vulnerability management, hardening recommendations, customer information requests, and ongoing platform operations.
- Mentor and support junior analysts, sharing investigative techniques, operational knowledge, and best practices for OT security monitoring.
- Continuously develop industrial security expertise, staying current with ICS/OT protocols, adversary tradecraft, threat intelligence, and emerging techniques relevant to industrial environments.
Requirements
~2 min read- 3–5 years of experience in network security, ideally including hands-on experience investigating real-world threats and suspicious network activity.
- Strong understanding of core networking concepts, including TCP/IP, firewalls, DNS, and packet analysis.
- Hands-on experience with security monitoring technologies, such as IDS/IPS, SIEM platforms, network traffic analysis tools, or comparable security operations technologies.
- Strong written and verbal communication skills, with excellent attention to detail and the ability to translate technical findings for both cybersecurity professionals and customers.
- Genuine interest in ICS/OT cybersecurity and critical infrastructure protection, combined with the ability to quickly understand complex industrial environments.
- Ability to work independently in a remote environment while coordinating effectively with distributed, cross-functional teams.
- Willingness to participate in shift-based coverage, weekend, and on-call responsibilities as required.
- Initial schedule is Monday–Friday, 8:00 a.m.–5:00 p.m., with weekend on-call coverage. The schedule is expected to transition to a four-day, 10-hour shift model, with employees choosing either Sunday–Wednesday or Wednesday–Saturday.
- Experience working within a Security Operations Center (SOC) is preferred.
- Familiarity with OT/ICS protocols such as Modbus, DNP3, and EtherNet/IP is preferred.
- Applied knowledge of OT-relevant adversary tactics and frameworks, including MITRE ATT&CK for ICS, is a plus.
- Hands-on laboratory, internship, threat hunting, digital forensics, or cybersecurity operations experience is valued.
- Experience with PCAP analysis or basic scripting using Python, Bash, or similar tools is a plus.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- September 29, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.