
SeniorAdministrator - Security Information And Event Management (SIEM)
포지션 소개
Job Summary
The OT SOC Level 2 Analyst is responsible for advanced security monitoring, investigation, and incident response within Operational Technology (OT) environments using Nozomi Networks and** Microsoft Sentinel**. The role acts as an escalation point for Level 1 analysts and contributes to continuous improvement of OT SOC operations through detection fine-tuning, SOP and playbook development, and team enablement—while ensuring security actions align with OT safety, availability, and operational constraints.
.
Key Responsibilities
Responsibilities
-
Perform Level 2 triage and investigation of OT security alerts generated by Nozomi Networks.
-
Validate and analyse alerts using OT context such as asset criticality, industrial processes, site topology, and maintenance activities.
-
Determine incident scope, root cause, impacted assets, and potential operational or safety impact.
-
Lead and coordinate OT incident response activities in collaboration with SOC, OT engineers, and IT security teams.
-
Escalate confirmed or high-risk incidents according to SOC and OT incident response procedures.
-
Investigate OT-related incidents in Microsoft Sentinel by correlating Nozomi alerts with IT, network, and security telemetry.
-
Support development and refinement of OT-specific detection use cases and alert logic.
-
Perform detection fine-tuning to improve signal quality and reduce false positives based on operational feedback.
-
Contribute investigation logic and response steps for SOC playbooks and runbooks.
-
Create, maintain, and improve OT SOC SOPs, incident response procedures, and investigation guides.
-
Support post-incident reviews and incorporate lessons learned into procedures and detection improvements.
-
Act as an escalation and mentoring point for Level 1 OT SOC analysts.
-
Provide training and knowledge transfer on OT threats, Nozomi alert interpretation, and investigation techniques.
-
Support continuous improvement of OT SOC processes, reporting, and operational maturity.
Skill Requirements
- Advanced Proficiency In Security Incident Response And Technical Solution Implementation Using Siem Tools.
- Strong Knowledge Of Incident Management Processes And Security Best Practices.
- Excellent Analytical And Problem-Solving Skills For Complex Incident Resolution.
- Proficient In Knowledge Management And Training Methodologies.
Other Requirements
Technical Skills Hands-on experience using Nozomi Networks for OT alert triage, investigation, and anomaly analysis. Experience investigating incidents using Microsoft Sentinel as a SIEM. Strong understanding of OT/ICS architectures, including Purdue Model, zones and conduits
복지 및 혜택
•교육비 지원
필수 스킬
Systems administration
Troubleshooting
Service operations
HCL Technologies 소개
Chennai
본사 위치