OT SOC Analyst L2
Core
L2 analyst in an OT Security Operations Center performing advanced monitoring, incident triage, investigation, and support for safety-critical industrial environments.
Role type
OT SOC Analyst L2
Builds
OT security monitoring platforms (Nozomi, SIEMs) and incident response capabilities for industrial clients
Domain
Industrial Cybersecurity (OT/ICS/SCADA)
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
OT/ICS cybersecurity monitoring, incident investigation, SIEM administration, packet analysis, industrial protocol analysis, deployment support, customer troubleshooting, reporting
Preferred skills
SOAR workflows, OT vulnerability management, Purdue Model knowledge, industrial sector customer support
Technologies
Splunk, QRadar, Sentinel, FortiSIEM, Elastic, Nozomi Guardian, Wireshark, Linux, Windows, PowerShell, Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET
Responsibilities
Monitor OT/IT security alerts and validate suspicious activities; investigate OT security incidents and malware indicators; support SIEM and Nozomi administration; assist in OT solution deployments and integrations; analyze OT logs and industrial protocols; provide remote customer troubleshooting; prepare SOC reports and documentation; collaborate with L1/L3 teams and escalate complex incidents
Seniority
Mid-level, hands-on IC