- Company Name
- Prudent Technologies and Consulting, Inc.
- Job Title
- ICS/OT Cybersecurity
- Job Description
-
Job Title: OT Cybersecurity Analyst
Role Summary:
Provide continuous monitoring, triage, and investigation of security alerts in industrial control system (ICS) and operational technology (OT) environments. Contribute to detection rule refinement, runbook development, and incident response activities within a 24/7 SOC.
Expectations:
- Operate on a shift‑based rotation with occasional after‑hours coverage.
- Meet SOC Service Level Agreements (SLAs) for alert handling and incident resolution.
- Reduce Mean Time to Detect (MTTD) and Mean Time to Resolve (MTTR).
- Keep documentation current and maintain knowledge of relevant OT security frameworks.
Key Responsibilities:
- Monitor SIEM, SOAR, and IIDS alerts; investigate potential OT incidents.
- Analyze SCADA/ICS logs for indicators of compromise.
- Validate and prioritize alerts; distinguish true positives, false positives, and benign events.
- Collaborate with shift leads to tune detection rules and reduce false positives.
- Develop and maintain runbooks, SOPs, and incident response playbooks.
- Document all investigations, findings, and actions in the SOC ticketing system.
- Participate in tabletop exercises, simulations, and ongoing training.
- Stay current on NERC‑CIP (2/3), NIST CSF, Purdue Model, ISO 27001, and related frameworks.
Required Skills:
- 2‑4 years of cybersecurity experience, with 1‑2 years in OT/SCADA environments.
- Proficiency with SIEM, SOAR, and IIDS platforms.
- Foundational knowledge of industrial protocols (DNP3, Modbus, IEC 104).
- Strong analytical, written, and verbal communication skills.
- Ability to work effectively in a 24/7, shift‑based SOC.
- Expertise in alert prioritization, triage, and SOC SLAs.
- Collaboration with cross‑functional teams to strengthen OT security posture.
Required Education & Certifications:
- High school diploma required; bachelor’s degree in IT, Computer Science, Cybersecurity, or related field preferred.
- Certifications such as Network+, Security+, or CYSA+ are a plus.