
Operational Technology (OT) Incident Response Consultant
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in Romania.
• Investigate and address critical OT security incidents.
• Execute root cause analysis to identify the source of threats, the extent of attacks, and the assets impacted.
• Conduct threat assessments within industrial settings.
• Evaluate network traffic, system logs, and security events to detect malicious activities and attack patterns.
• Research emerging threat actors, attack campaigns, and tactics, techniques, and procedures specific to OT.
• Create and improve detection use cases and threat detection protocols tailored to OT.
• Adjust and enhance alerts produced by OT security mechanisms.
• Integrate data from security platforms, threat intelligence feeds, network telemetry, and other information sources.
• Assist in the development of SIEM monitoring strategies, escalation processes, and alerting systems.
• Act as a subject matter expert during OT cybersecurity incidents and security operations.
• Offer technical advice for remediation, mitigation, and risk reduction.
• Aid customers in strengthening their OT cybersecurity frameworks, processes, and operational practices.
• Support the design and implementation of proactive OT security measures and monitoring capabilities.
• Contribute to the development of new security features, tools, and automation projects.
• Keep up to date with OT security trends, vulnerabilities, defensive technologies, and industry best practices.
• Collaborate closely with customers to identify threats, minimize risks, and enhance operational resilience.
• Assist organizations in ensuring the safety, reliability, and security of operational environments while improving their cyber defense posture.
• Proven experience in cybersecurity, incident response, security operations, or threat detection environments.
• A minimum of 2 years' experience supporting industrial control systems such as PLCs, RTUs, DCS, SIS, SCADA, HMI, MES, or historians is preferred.
• Understanding of OT and ICS architectures and their operational environments.
• Experience in investigating security incidents and conducting root cause analysis.
• Practical experience with SIEM technologies, event monitoring, detection use cases, alert tuning, escalation workflows, and threat intelligence.
• Familiarity with analyzing firewall logs, IDS/IPS events, system logs, network telemetry, and security events.
• Strong grasp of TCP/IP and UDP network protocols.
• Knowledge of industrial communication protocols like Modbus and DNP3.
• Understanding of the Purdue Enterprise Reference Architecture model.
• Capability to perform network traffic analysis and identify indicators of compromise within OT environments.
• Awareness of cyber threat actor tactics, techniques, and procedures (TTPs).
• Experience in vulnerability analysis, threat research, and security investigations.
• Proficiency in English communication.
• Willingness to engage in shift work, including nights, weekends, and holidays.
• Legal authorization to work in Romania without requiring employer sponsorship.
• Remote-first working model, prioritizing remote work for most employees.
• Employee-led networks for diversity and inclusion.
• Annual charity and fundraising events.
• Volunteer days available.
• Global initiatives focused on employee sustainability.
• Participation in global fitness and trivia competitions.
• Global wellbeing days are recognized.
• Monthly webinars and training sessions focused on wellbeing.
• Commitment to an equal-opportunity and inclusive workplace.
• Adjustments to recruitment and selection processes to support applicants with disabilities or other needs.
Fidelity Investments
The Ohio State University, Main Campus
International Luxury Hotel Association
Clarvida
Get handpicked remote jobs straight to your inbox weekly.