Aktiviere Job-Benachrichtigungen per E-Mail!

OT Security Analyst d/f/m

RWE AG

Essen

Hybrid

EUR 55.000 - 75.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden

Zusammenfassung

An energy company in Nordrhein-Westfalen seeks a cybersecurity expert to monitor and respond to security incidents in OT environments. The ideal candidate has a degree in Cybersecurity and experience with NSM tools and incident response. This hybrid role offers competitive rewards and flexible working arrangements. Join a dynamic team committed to creating a safe and skilled workforce.

Leistungen

Flexible Work Options
Growth and Development opportunities
Competitive Rewards

Qualifikationen

  • Experience with NSM tools and log/security analysis platforms.
  • Hands-on experience with incident response.
  • Familiarity with OT/ICS protocols.

Aufgaben

  • Monitor and analyze security events and alerts.
  • Respond to incidents in real time.
  • Develop detection use cases for OT/ICS threats.

Kenntnisse

Security monitoring
Incident response
Communication skills
Analysis
Team collaboration

Ausbildung

Degree in Cybersecurity or related field

Tools

NSM tools
SIEM platforms
Elastic
Tenable
Splunk
Jobbeschreibung
About the role

Join our Operational Technology (OT) Security Services team and play a key role in monitoring, analysing and responding to security threats and incidents. You will also help improve our detection capabilities and knowledge base, protecting the OT environments that are critical for RWE Generation’s flexible power generation and hydrogen (H₂) production. We are an international, hybrid team across Germany, the Netherlands and the UK, working with transparency, respect, collaboration and a healthy sense of fun. At the heart of our work is the OT Security Operations Center (OT SOC), where we provide network monitoring, threat and vulnerability management, asset and configuration support, as well as security assessments, system hardening and red/purple team activities.

Your tasks in this role:

  • Monitor and analyse security events and alerts using SIEM, NSM and related tools.
  • Respond to incidents in real time, from containment and recovery to reporting and follow-up.
  • Develop and maintain detection use cases and incident response playbooks for OT/ICS threats.
  • Assess and improve visibility by identifying and closing monitoring and logging gaps.
  • Investigate incidents thoroughly, performing root cause analysis and sharing lessons learned.
  • Document clearly and consistently all findings, incidents and improvements.
  • Contribute to continuous improvement of processes, tooling, documentation, audits and knowledge sharing.

This role includes on-call duties and occasional travel to sites and team meetings in Germany, the Netherlands, the UK and Turkey.

Your profile
  • A completed degree in Cybersecurity, IT, Engineering, Computer Science or comparable field, or equivalent work experience.
  • Experience with NSM tools (e.g. Dragos, Claroty, Tenable) and log/security analysis platforms (Elastic, Splunk, Wazuh, Graylog, Zeek, Suricata); Solid knowledge of SIEM, SOAR, IDS/IPS and endpoint security.
  • Hands-on experience with incident response and familiarity with the MITRE ATT&CK for ICS framework.
  • Familiarity with OT/ICS protocols such as Modbus, DNP3, OPC, PROFINET, S7Comm, IEC 60870-5-104, MMS.
  • Strong communication skills in English and German.
Advantageous, but not essential
  • Skills in scripting/automation (Python, PowerShell) and security in virtualisation (VMware, KVM, KubeVirt) and container environments (Kubernetes, Docker).
  • Experience at a SOC Managed Service Provider or in industrial/OT environments (energy, manufacturing, telecom or critical infrastructure).

RWE is committed to creating a diverse and inclusive environment – we value your passion, your willingness to learn and your desire to thrive. So, if you don’t display all the skills above but think this is the job for you, need flexible working arrangements or adjustments which aren’t outlined already, we would still like to hear from you.

What we offer
  • Meaningful Work – Make a real impact by contributing to a safe and skilled workforce and directly supporting our organization’s success.
  • Inspiring and Dynamic Environment – Collaborate on exciting projects within a motivated and expert team.
  • Flexible Work Options – Hybrid working opportunities and flexible hours.
  • Growth and Development – Comprehensive training programs, leadership development, and clear career progression opportunities.
  • Competitive Rewards – A competitive salary along with a range of additional benefits.

Apply with just a few clicks: ad code 90785, application period:02.10.2025
Any questions? Contact HR: Nuria Hetschel, +49 172 8605977

We look forward to meeting you. You can also find us on LinkedIn, Instagram, Facebook, YouTube and Xing.

We value diversity and therefore welcome all applications - regardless of gender, disability, nationality, ethnic and social origin, religion/belief, age, sexual orientation, and identity. #inclusionmatters

RWE Generation is Europe’s second biggest gas company. Its approximately 3,500 employees - among them many specialist technicians and engineers - operate power plants in Germany, the UK, the Netherlands and Turkey and are moving with purpose towards our vision for a clean future. With hydropower and biomass plants already online, they blend conventional energy expertise with renewables innovation. We are bridging the gap to the age of renewables by focusing on hydrogen, biomass and battery storage. By converting our power plant fleets to carbon-neutral fuels such as hydrogen and biomass, and successfully developing new storage technologies RWE Generation is making a key contribution to our ambitious goals. You'll discover we are continuously challenging ourselves creating a team that’s built on trust and respect.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
eine PDF-, DOC-, DOCX-, ODT- oder PAGES-Datei bis zu 5 MB per Drag & Drop ablegen.