Bengaluru, Karnataka
Job Summary
An OT Security professional protects industrial control systems (ICS), SCADA, and operational technology from cyber threats to ensure safety, reliability, and uptime. Key roles include designing secure network architectures, implementing segmentation, monitoring for anomalies, and managing vulnerabilities in legacy systems, bridging the gap between IT security and operational engineering.
This role is responsible for expert-level oversight and strategic leadership of vulnerability management operations within OT/ICS and IIoT environments. The position drives continuous improvement, ensures robust risk mitigation, and empowers teams to meet client expectations for large-scale, complex projects. They play a critical role in advancing operational excellence, fostering innovation, and ensuring secure, compliant, and resilient industrial systems.
Key Responsibilities
Security Architecture Design: Create resilient OT/ICS architectures, implementing network segmentation (e.g., Purdue Model), firewalls, and access controls to protect critical infrastructure.\r\n• Threat Monitoring & Incident Response: Continuously monitor OT networks for anomalies, investigate security breaches, and execute rapid incident response to maintain operational continuity.\r\n• Vulnerability Management & Risk Assessment: Identify, analyze, and mitigate security weaknesses in industrial devices (PLCs, RTUs, HMIs) and conduct regular assessments to ensure safety.\r\n• Policy Development & Compliance: Establish security policies based on standards like IEC 62443 and NIST CSF, ensuring compliance with industrial regulations.\r\n• Vendor & Asset Management: Maintain an accurate inventory of OT assets and ensure secure remote access for third-party vendors. \r\nKey Job Titles in OT Security\r\n• OT Security Analyst/Specialist: Focuses on monitoring and detecting anomalies.\r\n• OT Security Engineer: Implements and maintains security controls.\r\n• OT Security Architect/Lead: Designs secure OT infrastructure and bridges IT/OT teams.\r\n• Operational Technology Security Manager: Oversees the entire OT security program. \r\n\r\n\r\n\r\nSkills Required 4+ years’ for L2 8+ years for L3: Hands-on experience in 2 or more of the SIEM Analysis and SIEM content management areas\r\n
1. Lead vulnerability management operations using OT/ICS/IIoT security tools to identify, assess, and prioritize vulnerabilities in complex industrial environments, ensuring alignment with industry standards and regulatory requirements.
2. Oversee end-to-end remediation processes by coordinating with internal teams and leveraging vulnerability management platforms to ensure timely resolution and minimize operational risk.
3. Develop and implement advanced operational processes using vulnerability assessment technologies to optimize workflow efficiency, reporting, and compliance within the OT/ICS security domain.
4. Provide expert guidance and mentorship to the vulnerability management team, fostering knowledge sharing and continuous upskilling in the use of OT/ICS security solutions.
5. Drive innovation by evaluating and integrating emerging security tools, methodologies, and automation into vulnerability management processes to enhance detection and response capabilities.
6. Ensure client requirements are thoroughly understood and met by translating business needs into actionable security solutions within OT/ICS/IIoT environments.
7. Deliver comprehensive management reporting and actionable insights using vulnerability analytics platforms, supporting organizational planning and informed decision-making.
Skill Requirements
Technical Knowledge: Deep understanding of ICS/SCADA systems, industrial protocols (e.g., Modbus, OPC UA), and network infrastructure.\r\n• Frameworks: Knowledge of IEC 62443, NIST SP 800-82, and CIS Controls.\r\n• Certifications: Commonly sought certifications include GICSP, GRID, ISA/IEC 62443 Security Certificate, and CISSP.\r\n• Soft Skills: Strong communication skills are essential to bridge the gap between IT security teams and operational engineers. \r\n
1. Excellent Understanding Of Industrial Network Protocols, Asset Discovery, And Risk Assessment Methodologies.
2. Advanced Proficiency In Implementing Vulnerability Scanning, Risk Prioritization, And Patch Management Within Ot/Ics Environments.
3. Excellent Skills In Incident Response, Remediation Coordination, And Compliance Reporting Specific To Industrial Systems.
4. Strong Knowledge Of Regulatory Frameworks And Standards For Ot/Ics Security (E.G., Iec 62443, Nerc Cip).
5. Expert Ability To Lead Teams, Mentor Technical Staff, And Drive Continuous Process Improvement In Security Operations.
Other Requirements
OT security prioritizes safety and availability (uptime) over data confidentiality, whereas IT security prioritizes data confidentiality and integrity. OT environments often involve legacy systems that cannot be easily updated or patched. \r\nSoft skills\r\n• Shall have good verbal/written communication skills\r\n• Should be willing to work in 24x7 environments\r\n• From time to time travel opportunities may be assigned\r\n• Incumbent should carry continual system improvement mindset and able to demonstrate in work.\r\n• Client facing technical analysis report and presentation skills\r\n
Managed Threat Detection & Response (MTDR)\\\\r\\\\n\\\\r\\\\nCloud & OT Security Monitoring\\\\r\\\\nThreat Intelligence, Digital Risk & Malware Analysis
1. Certified Information Systems Security Professional (CISSP) � optional but valuable.
2. Global Industrial Cyber Security Professional (GICSP) � optional but valuable.
3. ISA/IEC 62443 Cybersecurity Certificate � optional but valuable
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-