Role Overview
Location: Bengaluru/Mumbai | Hybrid, with travel to customer and industrial sites as required
Experience: 6-10 years
We are seeking an experienced OT Threat Hunter and Detection Engineer to identify suspicious activity, investigate anomalies and improve threat-detection capabilities across Operational Technology and Industrial Control System environments.
The role will focus on analysing OT network traffic, security alerts, logs, asset inventories and communication baselines to identify unauthorised activity, lateral movement, protocol misuse and potential signs of compromise.
The specialist will work closely with OT SOC teams, plant engineers, incident-response teams and security stakeholders to develop threat-hunting hypotheses, detection use cases, investigation playbooks and practical containment recommendations.
Key Responsibilities
- OT Threat Hunting
- Conduct proactive threat hunting across OT and IC environments.
- Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
- Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
- Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
- Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
- Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
- Map findings to MITRE ATT&CK for IC and MITRE ATT&CK Enterprise where applicable. Detection Engineering.
- Develop and validate OT-specific detection use cases and analytics.
- Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
- Review existing OT monitoring coverage and identify detection gaps.
- Tune security alerts to improve detection quality and reduce unnecessary false positives.
- Establish baseline communication patterns for critical industrial assets and network zones.
- Develop detection logic for: o Unauthorised asset connections o Unexpected protocol usage o New or abnormal communication paths o Suspicious remote access o Credential misuse o Lateral movement o Engineering-workstation anomalies o Changes to PLC or controller communication
- Support purple-team exercises by validating whether simulated attack activity is detected and investigated effectively. Alert Investigation and Incident Support
- Analyse and triage alerts generated by OT IDS, NDR, SIEM and endpoint-security platforms.
- Correlate alerts across IT and OT systems to identify potential attack paths.
- Conduct initial compromise assessments and support incident scoping.
- Gather, preserve and document relevant investigation evidence.
- Work with incident-response teams to recommend containment, monitoring and recovery actions.
- Support post-incident reviews and convert lessons learned into improved detection content.
- Escalate critical findings in accordance with agreed incident and operational procedures. OT Visibility and Monitoring
- Review OT asset inventories and identify unknown, unmanaged or unauthorised devices.
- Assess the quality and coverage of network sensors, packet collection and log sources.
- Validate asset classification, communication baselines and criticality information.
- Identify monitoring gaps across industrial zones and conduits.
- Support the onboarding of relevant OT data sources into SIEM, SOC and detection platforms.
- Work with plant teams to ensure monitoring activities do not affect operational availability
- Reporting and Stakeholder Engagement
- Prepare clear threat-hunting and investigation reports containing: o Investigation scope o Hunting hypothesis o Data sources reviewed o Findings and supporting evidence o Affected ass