OT Security Engineer L3

Gruve

Pune District

On-site

INR 2,600,000 - 3,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gruve seeks an experienced OT Security Engineer L3 to lead design, deployment, and optimization of OT security monitoring across ICs, SCADA, DCS, and IIoT environments. You will drive threat hunting, incident response, and detection engineering while mentoring junior staff.

The role requires 6–10 years of OT cybersecurity experience and hands‑on expertise with Nozomi Guardian, Splunk, IBM QRadar, and other OT security tools.

Qualifications

  • 6–10 years of experience in OT cybersecurity and related security engineering roles.
  • Hands‑on expertise with OT monitoring and SIEM platforms including Nozomi Guardian, Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, Elastic Security.
  • Strong understanding of ICs, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial switches, and asset visibility concepts.
  • Deep knowledge of industrial protocols such as Modbus, DNP3, IEC 60870‑5‑104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.

Responsibilities

  • Lead deployment and configuration of OT monitoring solutions including Nozomi Guardian and related collectors, sensors, and network infrastructure.
  • Design OT monitoring architecture for asset visibility, protocol decoding, and secure telemetry collection.
  • Install and configure OT SIEM platforms for OT use cases.
  • Integrate OT monitoring technologies with SIEM, SOAR, EDR, and ticketing systems.
  • Lead incident investigations and act as escalation point for OT security incidents.
  • Perform proactive threat hunting across OT/IT environments to identify anomalous asset behavior and unsafe protocol usage.
  • Develop and optimize detection rules, dashboards, and OT‑specific use cases to reduce false positives.
  • Review OT alerts and correlate with enterprise SIEM telemetry; guide evidence collection for investigations.
  • Mentor L1/L2 analysts and share knowledge through workshops and documentation.

Skills

OT cybersecurity
Industrial networking
SOC operations
Threat hunting
Incident response
Windows Server
REST APIs
PowerShell
Wireshark

Education

Bachelor's degree

Tools

Nozomi Guardian
Splunk
IBM QRadar
Microsoft Sentinel
FortiSIEM
Elastic Security

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well‑funded early‑stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position Summary

We are seeking an experienced OT Security Engineer L3 to lead the design, deployment, integration, support, and optimization of OT security monitoring solutions across ICs, SCADA, DCS, and IIoT environments. The ideal candidate will bring 6–10 years of experience in OT cybersecurity and industrial network defense, act as the highest technical escalation point within the OT SOC, and drive implementation, threat hunting, incident response, detection engineering, customer engagement, and continuous improvement for complex industrial environments.

Key Roles & Responsibilities
1. OT Security Architecture, Deployment, and Implementation

Lead the deployment and configuration of OT monitoring solutions including Nozomi Guardian and related collectors, sensors, packet brokers, TAPs, SPAN ports, and syslog infrastructure.

Design OT monitoring architecture for industrial environments covering asset visibility, protocol decoding, segmentation‑aware telemetry collection, and secure integration patterns.

Install and configure SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security for OT use cases.

2. Integration and Automation

Integrate OT monitoring technologies with SIEM, SOAR, EDR, threat intelligence platforms, CMDBs, ticketing systems, and reporting solutions.

Configure Syslog, REST APIs, STIX/TAXII feeds, automation workflows, and custom integrations for OT firewalls, switches, historians, HMIs, PLCs, and engineering workstations.

3. Incident Response and Technical Escalation

Lead the investigation of high‑severity OT security incidents and act as the final escalation point for complex issues raised by L1 and L2 analysts.

Coordinate containment, eradication, recovery, root‑cause analysis, and technical communication with customer incident response teams and internal stakeholders.

4. Threat Hunting and Detection Engineering

Perform proactive threat hunting across OT and converged OT/IT environments to identify abnormal asset behavior, unsafe protocol usage, lateral movement, persistence mechanisms, and industrial attack techniques.

Develop and optimize detection rules, dashboards, correlation logic, and OT‑specific use cases to improve fidelity and reduce false positives.

5. Security Monitoring, Packet Analysis, and Forensics

Review OT alerts and correlate them with enterprise SIEM telemetry, asset context, and industrial communication patterns.

Perform advanced packet analysis using Wireshark, support forensic triage, validate malware indicators, and guide evidence collection for OT investigations.

6. Customer Engagement and Technical Leadership

Lead onsite and remote implementation activities, conduct customer workshops, deliver technical presentations, and provide expert troubleshooting during upgrades, migrations, and health checks.

Serve as the senior technical SME for OT SOC operations and provide strategic guidance during architecture reviews, escalations, and service improvement planning.

7. Engineering, Optimization, and Playbooks

Create custom parsers, integrations, playbooks, SOPs, and knowledge artifacts that improve OT visibility, response consistency, and service quality.

Optimize detection logic, data onboarding, alert tuning, and reporting workflows to improve MTTR, response quality, and customer outcomes.

8. OT Domain, Protocol, and Asset Expertise

Apply deep working knowledge of OT/ICS components including ICs, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial Ethernet, and IIoT‑connected assets.

Demonstrate strong command of industrial protocols such as Modbus, DNP3, IEC 60870‑5‑104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.

9. Reporting and Documentation

Produce executive dashboards, weekly and monthly SOC reports, compliance reporting, threat intelligence summaries, deployment status updates, and detailed root‑cause analyses.

Maintain high‑quality technical documentation for deployments, incidents, integrations, customer environments, and engineering changes.

10. Compliance, Risk, and Assessments

Support OT cybersecurity assessments, vulnerability management activities, and control validation aligned to standards such as ISA/IEC 62443, NIST CSF, and customer‑specific governance requirements.

Ensure delivery quality, SLA adherence, audit readiness, and operational alignment with plant safety and production constraints.

11. Mentoring and Knowledge Transfer

Mentor L1 and L2 analysts, guide implementation engineers, review technical deliverables, and conduct knowledge transfer sessions for customers and internal teams.

Drive continuous learning around OT attack techniques, threat intelligence, use‑case maturity, and industrial cybersecurity best practices.

12. Report deviations and concerns to the SOC Manager
Basic Qualifications
  • Bachelor's degree in computer science, Information Technology, Cybersecurity, Electronics, Instrumentation, Industrial Automation, or a related field.
  • 6–10 years of experience in OT cybersecurity, ICs/SCADA security monitoring, industrial network engineering, SOC operations, or related security engineering roles.
  • Hands‑on expertise with OT monitoring and SIEM platforms such as Nozomi Guardian, Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security.
  • Strong understanding of ICs, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial switches, and asset visibility concepts.
  • Deep knowledge of industrial protocols including Modbus, DNP3, IEC 60870‑5‑104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.
  • Strong OT/industrial networking fundamentals covering TCP/IP, VLANs, routing, switching, firewall policies, VPNs, IDS/IPS, packet capture, and secure remote access.
  • Experience with Wireshark, Nmap, PowerShell, Linux, Windows Server, REST APIs, troubleshooting, deployment documentation, and RCA preparation.
  • Excellent customer communication, presentation, technical leadership, problem‑solving, and mentoring skills.
Preferred Qualifications
  • Certifications such as GICSP, ISA/IEC 62443 Cybersecurity Expert, CISSP, CEH, CompTIA Security+, Nozomi Certified Engineer, Microsoft SC-200, Splunk Certified Consultant, or equivalent.
  • Experience designing OT visibility architectures, deploying collectors/sensors, validating TAP/SPAN strategies, and integrating packet, log, and asset telemetry.
  • Exposure to threat intelligence platforms, SOAR orchestration, CMDB/ticketing integrations, custom parser development, and OT‑specific detection engineering.
  • Working knowledge of Purdue Model, zones and conduits, industrial segmentation, change management in plant environments, and maintenance‑window‑aware deployment practices.
  • Experience supporting industrial sectors such as manufacturing, energy, utilities, pharma, chemicals, transportation, or other critical infrastructure domains.
Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

OT Security Engineer L3
OT Security Engineer L3

Gruve • Maharashtra

On-site
INR 1,800,000 - 3,200,000
OT SOC Analyst L2
OT SOC Analyst L2

Gruve • Maharashtra

On-site
INR 1,200,000 - 2,400,000
OT Security Engineer, Cyber Risk
OT Security Engineer, Cyber Risk

Kroll • Bengaluru

On-site
INR 1,800,000 - 3,800,000
Security Platform Engineer
Security Platform Engineer

NTT DATA BUSINESS SOLUTIONS • Hyderabad, Bengaluru

Hybrid
INR 3,500,000 - 5,500,000
OT Security Analyst
OT Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior Manager-OT
Senior Manager-OT

Adani Group • Vidisha

On-site
INR 3,000,000 - 4,500,000
OT Security Operations Manager
OT Security Operations Manager

Diageo • Bengaluru

On-site
INR 400,000 - 700,000
OT Cybersecurity Engineer
OT Cybersecurity Engineer

Mold-Masters DME India Private Limited, Coimbatore • Coimbatore District

On-site
INR 4,000,000 - 6,000,000
OT Security Principal Consultant
OT Security Principal Consultant

Infosys • Bengaluru

On-site
INR 900,000 - 1,300,000
Lead OT Cyber Security Engineer
Lead OT Cyber Security Engineer

GE Vernova • Chennai District

On-site
INR 1,200,000 - 2,000,000
Relocation assistance