Senior SOC Engineer – OT Security

Black & Grey HR

Doha

On-site

QAR 240,000 - 360,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Black & Grey HR in Doha, Qatar, seeks an experienced Senior SOC Engineer – OT Security to lead advanced security monitoring, threat detection, incident response, and threat hunting across OT/ICS environments. You will work with Nozomi, Forescout, and SIEM platforms to strengthen cyber resilience without disrupting critical operations.

The role requires 8+ years in cybersecurity, OT security, and ICs, with a strong grasp of MITRE ATT&CK for ICs, IEC 62443, and NIST ICs.

Qualifications

  • 8+ years of experience in cybersecurity, SOC operations, OT security, ICs security, or information security.
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field.

Responsibilities

  • Administer, manage, support deployment, and tune OT security monitoring tools such as Nozomi and Forescout.
  • Monitor OT/ICS environments using SIEM and specialized OT security monitoring platforms.
  • Detect, investigate, analyze, and respond to cyber threats targeting industrial control systems.
  • Maintain OT asset visibility and establish network behavior baselines.
  • Support micro-segmentation strategies across OT network zones in alignment with the Purdue Model.
  • Collaborate with OT engineering teams to safely implement containment actions in live industrial environments.
  • Handle OT cyber incidents while minimizing operational disruption.
  • Work with industrial firewalls, IDS/IPS, NAC, and network segmentation technologies.
  • Develop and continuously tune OT-specific detection rules and correlation logic within SIEM platforms.
  • Align detection use cases with the MITRE ATT&CK for ICs framework.
  • Reduce false positives while improving detection accuracy, coverage, and operational effectiveness.
  • Periodically review and optimize alert thresholds and detection logic.
  • Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation technologies.
  • Assist with onboarding OT log sources, parser development, and data normalization.
  • Optimize dashboards, alerts, and reporting to improve OT security visibility.
  • Operate and support packet brokers, network TAPs, SPAN infrastructure, and related technologies to enable comprehensive OT network visibility.
  • Perform deep packet inspection and traffic analysis across industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
  • Analyze east-west and north-south traffic to identify suspicious activity, lateral movement, and unauthorized communications.
  • Identify protocol anomalies and deviations from established OT network behavior.
  • Support network telemetry collection and traffic visibility across industrial environments.
  • Maintain accurate OT asset inventories and network topology visibility.
  • Identify unauthorized devices, rogue connections, and shadow OT assets.
  • Conduct proactive threat hunting using security logs, network telemetry, behavioral analytics, and threat intelligence.
  • Correlate threat intelligence with OT vulnerabilities, assets, and operational risks.
  • Support OT risk assessments and initiatives to improve overall security posture.
  • Ensure compliance with IEC 62443, NIST ICs, ISO standards, and internal cybersecurity policies.
  • Support internal and external audits by preparing security evidence and compliance documentation.
  • Prepare and present OT security reports covering incidents, vulnerabilities, risks, trends, and overall security posture.
  • Maintain dashboards covering threats, vulnerabilities, assets, compliance, and remediation status.
  • Communicate critical incidents, security risks, and recommended actions to SOC, OT engineering, and business stakeholders.
  • Provide executive-level reporting on OT security exposure, threat posture, and remediation progress.
  • Track remediation activities, SLAs, and outstanding security risks.
  • Support audit, regulatory, and compliance reporting requirements.

Skills

OT security
SOC operations
Threat hunting
Incident response
Asset visibility
MITRE ATT&CK for ICs
IEC 62443
NIST ICs

Education

Bachelor's degree in Cybersecurity/Information Security/CS

Tools

Nozomi
Forescout
Microsoft Sentinel
SIEM

Job description

Black & Grey HR is recruiting for an established technology solutions and services provider in Doha, Qatar. Our client is seeking an experienced Senior SOC Engineer – OT Security to lead advanced security monitoring, threat detection, incident response, and threat hunting across Operational Technology (OT) and Industrial Control System (ICS) environments. The role is critical in strengthening OT cyber resilience while ensuring security controls are implemented without disrupting high-availability, mission-critical industrial operations.

Key Responsibilities
Security Monitoring & Threat Detection
  • Administer, manage, support deployment, and tune OT security monitoring tools such as Nozomi and Forescout.
  • Monitor OT/ICS environments using SIEM and specialized OT security monitoring platforms.
  • Detect, investigate, analyze, and respond to cyber threats targeting industrial control systems.
  • Maintain OT asset visibility and establish network behavior baselines.
  • Support micro-segmentation strategies across OT network zones in alignment with the Purdue Model.
  • Collaborate with OT engineering teams to safely implement containment actions in live industrial environments.
  • Handle OT cyber incidents while minimizing operational disruption.
  • Work with industrial firewalls, IDS/IPS, NAC, and network segmentation technologies.
Detection Engineering & Use Case Management
  • Develop and continuously tune OT-specific detection rules and correlation logic within SIEM platforms.
  • Align detection use cases with the MITRE ATT&CK for ICs framework.
  • Reduce false positives while improving detection accuracy, coverage, and operational effectiveness.
  • Periodically review and optimize alert thresholds and detection logic.
  • Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation technologies.
  • Assist with onboarding OT log sources, parser development, and data normalization.
  • Optimize dashboards, alerts, and reporting to improve OT security visibility.
OT Network Visibility, Packet Analysis & Traffic Engineering
  • Operate and support packet brokers, network TAPs, SPAN infrastructure, and related technologies to enable comprehensive OT network visibility.
  • Perform deep packet inspection and traffic analysis across industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
  • Analyze east-west and north-south traffic to identify suspicious activity, lateral movement, and unauthorized communications.
  • Identify protocol anomalies and deviations from established OT network behavior.
  • Support network telemetry collection and traffic visibility across industrial environments.
Asset Visibility, Threat Hunting & Compliance
  • Maintain accurate OT asset inventories and network topology visibility.
  • Identify unauthorized devices, rogue connections, and shadow OT assets.
  • Conduct proactive threat hunting using security logs, network telemetry, behavioral analytics, and threat intelligence.
  • Correlate threat intelligence with OT vulnerabilities, assets, and operational risks.
  • Support OT risk assessments and initiatives to improve overall security posture.
  • Ensure compliance with IEC 62443, NIST ICs, ISO standards, and internal cybersecurity policies.
  • Support internal and external audits by preparing security evidence and compliance documentation.
Reporting & Stakeholder Management
  • Prepare and present OT security reports covering incidents, vulnerabilities, risks, trends, and overall security posture.
  • Maintain dashboards covering threats, vulnerabilities, assets, compliance, and remediation status.
  • Communicate critical incidents, security risks, and recommended actions to SOC, OT engineering, and business stakeholders.
  • Provide executive-level reporting on OT security exposure, threat posture, and remediation progress.
  • Track remediation activities, SLAs, and outstanding security risks.
  • Support audit, regulatory, and compliance reporting requirements.
Requirements
Requirements
  • 8+ years of experience in cybersecurity, SOC operations, OT security, ICs security, or information security.
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field.
Mandatory Certification – Any One:
  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • ISA/IEC 62443 Cybersecurity Certificate
  • GIAC Response and Industrial Defense (GRID)
  • ISA Certified Automation Cybersecurity Specialist (IACS)
Required OT/ICS Technical Skills
  • Strong hands-on experience with OT/ICS environments, including SCADA, DCS, PLC, and industrial control systems.
  • Strong understanding of OT network architecture, Purdue Model, OT DMZ, network segmentation, and secure zones/conduits.
  • Practical experience with micro-segmentation and Zero Trust principles for OT environments.
  • Hands-on experience with Nozomi and/or Forescout OT security platforms.
  • Experience with SIEM platforms such as Microsoft Sentinel and OT security monitoring technologies.
  • Strong knowledge of packet analysis, Deep Packet Inspection (DPI), packet brokers, TAP, SPAN, and network telemetry.
  • Experience analyzing industrial protocols such as Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP.
  • Strong understanding of OT threat detection, anomaly detection, threat hunting, and incident response.
  • Experience with industrial firewalling, IDS/IPS, NAC, segmentation, and secure remote access.
  • Knowledge of OT vulnerability management, asset discovery, asset inventory, and network visibility.
  • Ability to develop and tune SIEM detection rules and OT-specific security use cases.
  • Strong knowledge of MITRE ATT&CK for ICs, IEC 62443, and NIST ICs security principles.
  • Experience supporting security architecture involving SIEM, IDS/IPS, packet brokers, and OT segmentation technologies.
  • Strong analytical, incident investigation, reporting, documentation, and stakeholder management skills.
Preferred Experience
  • Experience working within critical infrastructure, energy, utilities, oil & gas, manufacturing, or other industrial environments.
  • Experience operating security controls within high-availability OT environments where operational continuity is critical.
  • Experience with OT security architecture, risk assessments, security audits, and regulatory compliance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Engineer
Senior SOC Engineer

Experience • Doha

On-site
QAR 240,000 - 420,000
None
Senior OT SOC Engineer — Industrial Cyber Resilience Lead
Senior OT SOC Engineer — Industrial Cyber Resilience Lead

Black & Grey HR • Doha

On-site
QAR 240,000 - 360,000
Cybersecurity Specialist
Cybersecurity Specialist

Salary • Al Khor

On-site
QAR 250,000 - 420,000
Assistant Manager - OT Cyber Security - Technology Consulting
Assistant Manager - OT Cyber Security - Technology Consulting

Ernst & Young AE • Qatar

On-site
QAR 300,000 - 600,000
Cyber Security Specialist
Cyber Security Specialist

Employment • Doha

On-site
QAR 180,000 - 240,000
Senior ICS/OT Cybersecurity Engineer
Senior ICS/OT Cybersecurity Engineer

Salary • Al Khor

On-site
QAR 250,000 - 420,000
Specialist - Cybersecurity (OT & Cyber Physical)
Specialist - Cybersecurity (OT & Cyber Physical)

Milaha • Doha

On-site
QAR 360,000 - 540,000
Cybersecurity Specialist
Cybersecurity Specialist

Employment • Al Khor and Al Thakhira

On-site
QAR 210,000 - 420,000
Senior SOC Engineer
Senior SOC Engineer

Employment • Doha

On-site
QAR 250,000 - 350,000
ICS/OT Cybersecurity Specialist: Secure Industrial Systems
ICS/OT Cybersecurity Specialist: Secure Industrial Systems

Employment • Doha

On-site
QAR 180,000 - 240,000