Business Unit: Cubic Transportation Systems Company Details: EXECUTIVE SUMMARY Cubic Transportation Systems (CTS) is establishing a centralized, 24 hour by 7 day (24x7) global Network Operations Center (NOC) to monitor 35+ customer program implementations spanning regional field-service data centers and Microsoft Azure and Amazon Web Services (AWS) cloud tenants that support Payment Card Industry Data Security Standard (PCI DSS) v4.x scoped fare and payment processing. Tier 2 (T2) NOC Technicians sit between frontline Tier 1 (T1) monitoring and Tier 3 (T3) engineering, and perform two co-equal essential duties: validated-incident remediation using defined runbooks and playbooks (escalating to T3 only when no playbook exists or deeper technical guidance is required), and driving patching operations across each assigned program's environments. Operations must comply with the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 27001:2022 standard, follow Information Technology Infrastructure Library (ITIL) 4 practices, support PCI DSS v4.x, and support National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 outcomes. This document describes the detailed roles and responsibilities of the T2 NOC Technician role and the standards basis for that operating model.
Scope and Operating Context
The NOC monitors 35+ global program implementations, each a distinct Cubic customer, managed day-to-day by regional field service operations in customer-site data centers and/or in Azure or AWS cloud tenants. Monitored elements include network, systems, services, and internal processes critical to operations, as well as an array of Operational Technology (OT) devices including fare gates, ticket vending machines, point-of-sale (POS) devices, and mobile applications. The NOC also ensures processes for backup, log management, and operational security remain fully operational. Patching operations are a significant and growing share of T2 workload. Each program averages 5 or more environments, and each environment averages approximately 150 Linux and Windows assets, located in a physical customer-site data center and/or an Azure cloud tenant. Two T2 NOC engineers are dedicated to each program to support this effort, and it consumes the majority of their time. DevOps automation intended to make patch orchestration more efficient is in progress but not yet mature; until it matures, a significant amount of hands‑on T2 time is required.
Tier Model and Escalation Path
- Tier 1 (T1) staff perform 24x7 monitoring; once they have identified a validated issue, they elevate to Tier 2 (T2) staff for remediation.
- Operations issues route to NOC T2 staff; security issues route to Security Operations Center (SOC) T2 staff.
- If the issue has a known remediation path with a defined playbook, T2 staff resolve it directly.
- If there is no defined playbook, or deeper technical guidance is needed, T2 staff engage Tier 3 (T3) engineers.
- T2 NOC Technician
Monitoring, Event Correlation, and Incident Remediation
- Perform deeper technical triage on incidents escalated from Tier 1, correlating events across regions, sites, and cloud tenants.
- Execute approved remediation runbooks and playbooks to restore service, consistent with ITIL 4 Incident Management practice.
- Engage Tier 3 engineers when no defined playbook exists or when the issue requires deeper technical guidance.
- Lead or support major incident coordination for assigned programs, including stakeholder communications and resolution validation.
Patching Operations (Co-Equal Essential Duty)
- Drive patch execution across the 5 or more environments of each assigned program, covering an average of 150 Linux and Windows assets per environment.
- Coordinate patch windows and maintenance schedules with regional field service operations and customer stakeholders.
- Apply patches and remediations cleared by engineering and tested prior to release, maintaining process and records compliance.
- Support ongoing DevOps automation of patch orchestration as tooling matures, and flag environments not yet covered by automation.
Incident Management and Major Incident Support
- Validate alerts, identify impacted services and sites, and set incident priority based on impact and urgency.
- Apply containment-first mitigations within the first 15 to 30 minutes of a declared incident (reroute traffic, failover, isolate a site segment, stop a bad deployment).
- Support the incident commander role for major incidents affecting an assigned program.
- Produce post‑incident documentation: timeline, root‑cause hypothesis, mitigation, residual risk, and follow‑up actions.
Change and Configuration Management
- Ensure every production change has a ticket, risk assessment, test evidence, rollback plan, and required approvals before implementation.
- Monitor configuration baselines for network devices, operating system hardening, and cloud security posture; raise incidents for drift affecting availability or security.
- Execute pre‑approved emergency change procedures when required, with after‑the‑fact Change Advisory Board review and evidence capture.
Log Management (Operational Review)
- Verify log source coverage for network devices, operating systems, identity and access management, database audit logs, and application logs.
- Validate Network Time Protocol (NTP) health across sites and cloud tenants so that logs remain forensically useful.
- Perform operational review of logs for availability and performance signals; elevate security‑relevant alerts to the SOC.
Backup and Recovery Verification
- Perform daily verification of backup job success, failure, duration anomalies, and missed schedules.
- Participate in periodic restore validation, including file‑level and full service‑level restores.
Business Continuity and Disaster Recovery Support
- Maintain and help exercise failover and failback runbooks for assigned programs' cloud regions and customer‑site data centers.
- Track disaster recovery readiness gaps as risk items and support remediation change requests.
Security Monitoring at the Operational Layer (NOC‑to‑SOC Interface)
- Monitor for operational anomalies that may be security‑significant and elevate to the SOC with enriched context.
- Support containment under pre‑approved playbooks (network isolation, account lock, traffic throttling) while the SOC leads investigation when security‑incident criteria are met.
Documentation and Reporting
- Maintain and review runbooks, standard operating procedures (SOPs), service maps, and escalation paths for assigned programs.
- Produce daily operations summaries and contribute to weekly service level agreement (SLA) and key performance indicator (KPI) dashboards.
- Participate in post‑mortems and problem‑record analysis to reduce recurring incidents.
Compliance and Standards Cross‑Reference
- 1) NOC Task Area : 24x7 monitoring, event correlation, alert tuning ITIL 4 Practice : Monitoring and Event Management; Incident Management ISO/IEC 27001:2022 : A.8.16 Monitoring Activities; A.8.15 Logging PCI DSS v4.x : Req 10 Log/Monitor; Req 11 Test Security NIST CSF 2.0 : Detect; Respond
- 2) NOC Task Area : Incident triage, escalation, major incident coordination ITIL 4 Practice : Incident Management ISO/IEC 27001:2022 : A.8.15/A.8.16 evidence PCI DSS v4.x : Req 12 security program; 12.10 Incident Response NIST CSF 2.0 : Respond
- 3) NOC Task Area : Patching, config drift detection, emergency change evidence ITIL 4 Practice : Change Enablement; Service Configuration ISO/IEC 27001:2022 : A.8.32 Change Management PCI DSS v4.x : Req 2 secure configurations; Req 6 secure systems/software NIST CSF 2.0 : Protect; Govern
- 4) NOC Task Area : Log onboarding, integrity, retention checks ITIL 4 Practice : Monitoring and Event Management; Information Security Management ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities PCI DSS v4.x : Req 10 logging and monitoring NIST CSF 2.0 : Detect; Respond
- 5) NOC Task Area : Backup job verification, restore tests ITIL 4 Practice : Service Continuity Management; Availability Management ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities PCI DSS v4.x : Req 3/4 data protection posture supported NIST CSF 2.0 : Protect; Recover
- 6) NOC Task Area : Operational security anomaly monitoring; escalation to SOC ITIL 4 Practice : Information Security Management; Monitoring and Event Management ISO/IEC 27001:2022 : A.8.16 monitoring anomalies; A.8.15 logging PCI DSS v4.x : Req 10 monitoring; Req 12.10 24x7 readiness NIST CSF 2.0 : Protect; Recover
Worker Type: Employee
We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
Cubic creates and delivers technology solutions in transportation that make people’s lives easier by simplifying their daily journeys, and defense capabilities that help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global challenges through innovation and service to our customers and partners. We have a top‑tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). CTS is an industry‑leading integrator of payment and information solutions and related services for intelligent travel applications. CTS delivers integrated systems for transportation and traffic management, delivering tools for travelers to choose the smartest and easiest way to travel and pay for their journeys, and enabling transportation authorities and agencies to manage demand across the entire transportation network.
Cubic Defense provides networked Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance and Reconnaissance (C5ISR) solutions, and live, virtual, constructive and game‑based training solutions for both U.S. and Allied Fires. These mission‑inspired capabilities enable assured multi‑domain access; converged digital intelligence; and superior readiness for defense, intelligence, security and commercial missions. Cubic is proud to have a presence in over 60 countries and employ over 5,000 people worldwide. We are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action-Employer.
We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, or national origin, military or veteran status, and any other basis protected by applicable law.
For more information on Equal Employment please visit: http://www.cubic.com/Careers/Applicant-Help To learn more, visit Cubic.com. Follow us on LinkedIn!