OT Security Engineer, Cyber Risk

Kroll

Bengaluru

On-site

INR 1,800,000 - 3,800,000

Full time

1 hour ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kroll is seeking an OT Security Engineer to drive OT security engagements from India. You will design OT architectures, deploy and support asset visibility platforms, and coordinate with network, controls, SOC, and vendor teams across time zones.

Ideal candidates have 5–8 years in network/security delivery, hands-on OT platform experience (Nozomi, Claroty, Armis), and knowledge of ISA/IEC 62443; strong documentation and stakeholder communication are essential.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS, Electronics, Engineering, or related field.
  • 5–8 years of relevant experience in network engineering, network security, or OT/ICS security.
  • Strong networking fundamentals: TCP/IP, subnetting, switching, routing, VLANs, VPNs, DNS, DHCP.
  • Hands-on with OT monitoring/asset visibility platforms: Nozomi, Claroty, Armis.
  • Experience with OT segmentation or firewall migrations including traffic-flow analysis.
  • Industrial protocols: Modbus TCP, DNP3, OPC/OPC UA, EtherNet/IP, PROFINET, BACnet, IEC 60870-5-104.
  • Knowledge of ISA/IEC 62443 and NIST SP 800-82.

Responsibilities

  • Design OT architectures, Purdue-model zones, industrial DMZs, and IT/OT interconnections.
  • Support OT segmentation projects from discovery to validation and design.
  • Deploy and troubleshoot OT asset visibility and security platforms.
  • Plan sensor placement, SPAN/TAP, and SIEM/SOC/MDR integrations.
  • Analyze OT traffic to identify assets, dependencies, and segmentation needs.
  • Configure switches, routers, VLANs, ACLs, VPNs, NAT, and high availability in OT/enterprise.
  • Develop low-level designs, runbooks, test plans, and as-built docs.
  • Support client workshops, PoCs, and vendor coordination.
  • Contribute to OT Zero Trust and micro-segmentation initiatives.

Skills

Networking fundamentals
OT/ICS security
Root-cause analysis
Documentation & diagrams
Stakeholder communication

Education

Bachelor's degree in Cybersecurity or related field

Tools

Nozomi Networks
Claroty
Armis

Job description

Kroll is seeking an OT Security Engineer to support the delivery of Operational Technology Security engagements from India. The role requires a strong foundation in enterprise and industrial networking, combined with hands-on experience deploying and supporting OT asset visibility and threat monitoring platforms such as Nozomi Networks, Claroty, or Armis.

Day-to-Day Responsibilities
  • Design, review, and document OT architectures, including Purdue-model zones and conduits, industrial DMZs, secure remote access, and IT/OT interconnections.
  • Support OT network segmentation projects from discovery and current-state assessment through target-state design, firewall rule definition, implementation planning, testing, and validation.
  • Deploy, configure, tune, upgrade, and troubleshoot OT asset visibility and security monitoring platforms such as Nozomi Networks, Claroty, or Armis.
  • Plan sensor and collector placement, configure SPAN/TAP connectivity, validate packet visibility, and integrate monitoring platforms with SIEM, SOC, MDR, ticketing, and identity systems.
  • Perform network discovery and traffic analysis to identify assets, protocols, communication paths, dependencies, and segmentation requirements across industrial environments.
  • Configure and troubleshoot network technologies including switching, routing, VLANs, VRFs, ACLs, firewalls, VPNs, NAT, redundancy, and high-availability designs in enterprise and OT environments.
  • Develop network diagrams, low-level designs, firewall rule matrices, implementation runbooks, test plans, rollback plans, and as-built documentation.
  • Support client workshops, technical discussions, Proofs of Concept, solution demonstrations, and coordination with network, controls, engineering, SOC, and vendor teams.
  • Contribute to OT Zero Trust and micro-segmentation initiatives; experience with solutions such as Zscaler or ColorTokens is an advantage.
Essential Traits
  • Strong hands-on networking mindset with a structured approach to troubleshooting and root-cause analysis.
  • Ability to translate discovered OT traffic flows and operational dependencies into practical segmentation designs and implementation plans.
  • Delivery-focused approach that balances cybersecurity objectives with safety, availability, and production requirements.
  • Confidence working with client network, engineering, controls, security operations, and technology vendor teams.
  • Clear communication style and the ability to explain network and security issues to both technical and non-technical stakeholders.
  • Strong ownership, attention to detail, and disciplined creation of diagrams, runbooks, rule matrices, and as-built documentation.
Prerequisites
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Electronics, Engineering, or a related field.
  • Approximately 5-8 years of relevant experience in network engineering, network security, or OT/ICS security, with meaningful hands-on delivery experience.
  • Strong networking fundamentals, including TCP/IP, subnetting, switching, routing, VLANs, STP, HSRP/VRRP, OSPF/BGP, DNS, DHCP, NAT, VPNs, and packet analysis.
  • Hands-on experience with enterprise firewalls, switches, routers, and network management or troubleshooting tools; experience with major vendors such as Cisco, Palo Alto Networks, Fortinet, or Check Point is preferred.
  • Hands-on deployment or operational support experience with at least one OT monitoring or asset visibility platform: Nozomi Networks, Claroty, or Armis.
  • Experience supporting network segmentation or firewall migration projects, including traffic-flow analysis, rule-base development, implementation coordination, and post-change validation.
  • Working knowledge of industrial protocols such as Modbus TCP, DNP3, OPC/OPC UA, EtherNet/IP, PROFINET, BACnet, and IEC 60870-5-104.
  • Understanding of OT security standards and guidance such as ISA/IEC 62443 and NIST SP 800-82.
  • Experience with OT Zero Trust, software-defined segmentation, or micro-segmentation solutions such as Zscaler or ColorTokens is preferred.
  • Experience integrating OT monitoring solutions with SIEM, SOC, MDR, identity, vulnerability management, or ticketing platforms.
  • Relevant certifications such as CCNA/CCNP, PCNSE, NSE/FCP, GICSP, GRID, or ISA/IEC 62443 are advantageous.

Strong analytical, troubleshooting, documentation, and client communication skills, with the ability to work independently and collaboratively across time zones.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Platform Engineer
Security Platform Engineer

NTT DATA BUSINESS SOLUTIONS • Hyderabad, Bengaluru

Hybrid
INR 3,500,000 - 5,500,000
Senior Manager-OT
Senior Manager-OT

Adani Group • Vidisha

On-site
INR 3,000,000 - 4,500,000
OT Network Security Engineer (5-7 Years ) Bengaluru/ Chennai
OT Network Security Engineer (5-7 Years ) Bengaluru/ Chennai

HypTechie • Chennai

On-site
INR 1,000,000 - 1,500,000
OT Security Operations Manager
OT Security Operations Manager

Diageo • Bengaluru

On-site
INR 400,000 - 700,000
OT Security Engineer
OT Security Engineer

ofi Cameroon • Bengaluru

On-site
INR 1,800,000 - 3,000,000
OT Network Engineer
OT Network Engineer

Tata Consultancy Services • Pune District

On-site
INR 900,000 - 1,500,000
OT Security Analyst
OT Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
OT & IT Security Consultant
OT & IT Security Consultant

Fluidech • Gurugram District

On-site
INR 1,200,000 - 2,000,000
OT Security Engineer - Pune
OT Security Engineer - Pune

Tribastion Technologies Pvt. Ltd. • Pune District

On-site
INR 1,500,000 - 2,100,000
Analyst - OT Security
Analyst - OT Security

GRAMAX • Chennai District

On-site
INR 1,800,000 - 2,800,000