Senior SOC Engineer

Black & Grey | People Advisory, Executive Search & Employer Branding

Doha

On-site

QAR 240,000 - 420,000

Full time

23 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Black & Grey HR is recruiting for an established technology solutions and services provider in Doha, Qatar. We seek an experienced Senior SOC Engineer – OT Security to lead monitoring, threat detection, incident response, and threat hunting across OT/ICS environments to protect mission-critical industrial operations.

The role requires 8+ years in cybersecurity with OT/ICS expertise and certifications such as GICSP, ISA/IEC 62443, GRID, or IACS.

Qualifications

  • 8+ years of experience in cybersecurity, SOC operations, OT security, ICS security, or information security.
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field.
  • Mandatory certification – any one: GICSP, ISA/IEC 62443, GRID or IACS.

Responsibilities

  • Lead security monitoring, threat detection, incident response, and threat hunting across OT/ICS environments.
  • Develop OT-specific detection rules; align use cases with MITRE ATT&CK for ICs.
  • Maintain OT asset visibility and support network segmentation in Purdue Model contexts.
  • Collaborate with OT engineering to implement containment actions safely in live environments.
  • Prepare security reports, dashboards, and compliance evidence for stakeholders.

Skills

OT/ICS security
SOC operations
Threat hunting
Incident response
MITRE ATT&CK for ICs
Nozomi
Forescout
Microsoft Sentinel
OT network segmentation

Education

Bachelor’s degree in Cybersecurity / Information Security / Computer Science

Tools

Nozomi
Forescout
Microsoft Sentinel
SIEM platforms

Job description

Black & Grey HR is recruiting for an established technology solutions and services provider in Doha, Qatar. Our client is seeking an experienced Senior SOC Engineer – OT Security to lead advanced security monitoring, threat detection, incident response, and threat hunting across Operational Technology (OT) and Industrial Control System (ICS) environments. The role is critical in strengthening OT cyber resilience while ensuring security controls are implemented without disrupting high-availability, mission-critical industrial operations.

Key Responsibilities
Security Monitoring & Threat Detection
  • Administer, manage, support deployment, and tune OT security monitoring tools such as Nozomi and Forescout.
  • Monitor OT/ICS environments using SIEM and specialized OT security monitoring platforms.
  • Detect, investigate, analyze, and respond to cyber threats targeting industrial control systems.
  • Maintain OT asset visibility and establish network behavior baselines.
  • Support micro-segmentation strategies across OT network zones in alignment with the Purdue Model.
  • Collaborate with OT engineering teams to safely implement containment actions in live industrial environments.
  • Handle OT cyber incidents while minimizing operational disruption.
  • Work with industrial firewalls, IDS/IPS, NAC, and network segmentation technologies.
Detection Engineering & Use Case Management
  • Develop and continuously tune OT-specific detection rules and correlation logic within SIEM platforms.
  • Align detection use cases with the MITRE ATT&CK for ICs framework.
  • Reduce false positives while improving detection accuracy, coverage, and operational effectiveness.
  • Periodically review and optimize alert thresholds and detection logic.
  • Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation technologies.
  • Assist with onboarding OT log sources, parser development, and data normalization.
  • Optimize dashboards, alerts, and reporting to improve OT security visibility.
OT Network Visibility, Packet Analysis & Traffic Engineering
  • Operate and support packet brokers, network TAPs, SPAN infrastructure, and related technologies to enable comprehensive OT network visibility.
  • Perform deep packet inspection and traffic analysis across industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
  • Analyze east-west and north-south traffic to identify suspicious activity, lateral movement, and unauthorized communications.
  • Identify protocol anomalies and deviations from established OT network behavior.
  • Support network telemetry collection and traffic visibility across industrial environments.
Asset Visibility, Threat Hunting & Compliance
  • Maintain accurate OT asset inventories and network topology visibility.
  • Identify unauthorized devices, rogue connections, and shadow OT assets.
  • Conduct proactive threat hunting using security logs, network telemetry, behavioral analytics, and threat intelligence.
  • Correlate threat intelligence with OT vulnerabilities, assets, and operational risks.
  • Support OT risk assessments and initiatives to improve overall security posture.
  • Ensure compliance with IEC 62443, NIST ICs, ISO standards, and internal cybersecurity policies.
  • Support internal and external audits by preparing security evidence and compliance documentation.
Reporting & Stakeholder Management
  • Prepare and present OT security reports covering incidents, vulnerabilities, risks, trends, and overall security posture.
  • Maintain dashboards covering threats, vulnerabilities, assets, compliance, and remediation status.
  • Communicate critical incidents, security risks, and recommended actions to SOC, OT engineering, and business stakeholders.
  • Provide executive-level reporting on OT security exposure, threat posture, and remediation progress.
  • Track remediation activities, SLAs, and outstanding security risks.
  • Support audit, regulatory, and compliance reporting requirements.
Requirements
Experience & Education
  • 8+ years of experience in cybersecurity, SOC operations, OT security, ICs security, or information security.
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field.
Mandatory Certification – Any One:
  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • ISA/IEC 62443 Cybersecurity Certificate
  • GIAC Response and Industrial Defense (GRID)
  • ISA Certified Automation Cybersecurity Specialist (IACS)
Required OT/ICS Technical Skills
  • Strong hands‑on experience with OT/ICS environments, including SCADA, DCS, PLC, and industrial control systems.
  • Strong understanding of OT network architecture, Purdue Model, OT DMZ, network segmentation, and secure zones/conduits.
  • Practical experience with micro‑segmentation and Zero Trust principles for OT environments.
  • Hands‑on experience with Nozomi and/or Forescout OT security platforms.
  • Experience with SIEM platforms such as Microsoft Sentinel and OT security monitoring technologies.
  • Strong knowledge of packet analysis, Deep Packet Inspection (DPI), packet brokers, TAP, SPAN, and network telemetry.
  • Experience analyzing industrial protocols such as Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
  • Strong understanding of OT threat detection, anomaly detection, threat hunting, and incident response.
  • Experience with industrial firewalling, IDS/IPS, NAC, segmentation, and secure remote access.
  • Knowledge of OT vulnerability management, asset discovery, asset inventory, and network visibility.
  • Ability to develop and tune SIEM detection rules and OT‑specific security use cases.
  • Strong knowledge of MITRE ATT&CK for ICs, IEC 62443, and NIST ICs security principles.
  • Experience supporting security architecture involving SIEM, IDS/IPS, packet brokers, and OT segmentation technologies.
  • Strong analytical, incident investigation, reporting, documentation, and stakeholder management skills.
Preferred Experience
  • Experience working within critical infrastructure, energy, utilities, oil & gas, manufacturing, or other industrial environments.
  • Experience operating security controls within high-availability OT environments where operational continuity is critical.
  • Experience with OT security architecture, risk assessments, security audits, and regulatory compliance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Engineer
Senior SOC Engineer

Tanqeeb • Doha

On-site
QAR 180,000 - 240,000
Senior SOC Engineer – OT Security
Senior SOC Engineer – OT Security

Black & Grey HR • Doha

On-site
QAR 240,000 - 360,000
Senior SOC Engineer
Senior SOC Engineer

Experience • Doha

On-site
QAR 240,000 - 420,000
None
Senior SOC Engineer – OT/ICS Cybersecurity | Doha, Qatar
Senior SOC Engineer – OT/ICS Cybersecurity | Doha, Qatar

WorkWavez • Qatar

On-site
QAR 300,000 - 420,000
Senior OT SOC Engineer — Industrial Cyber Resilience Lead
Senior OT SOC Engineer — Industrial Cyber Resilience Lead

Black & Grey HR • Doha

On-site
QAR 240,000 - 360,000
Senior OT Security Engineer — ICS Threat Hunting
Senior OT Security Engineer — ICS Threat Hunting

Black & Grey | People Advisory, Executive Search & Employer Branding • Doha

On-site
QAR 240,000 - 420,000
Senior SOC Engineer
Senior SOC Engineer

Employment • Doha

On-site
QAR 250,000 - 350,000
Senior OT Security Engineer - Threat Hunting for ICS/SCADA
Senior OT Security Engineer - Threat Hunting for ICS/SCADA

Tanqeeb • Doha

On-site
QAR 180,000 - 240,000
Senior OT/ICS Cyber SOC Engineer
Senior OT/ICS Cyber SOC Engineer

WorkWavez • Qatar

On-site
QAR 300,000 - 420,000
Senior OT Cyber Security Engineer – Qatar
Senior OT Cyber Security Engineer – Qatar

Brunel Oil and Gas Services WLL Qatar • Doha

On-site
QAR 279,000 - 446,000