Stand out for this role — generate a tailored resume and cover letter in about a minute.
Starlink WLL is looking for a professional specializing in Security Monitoring & Threat Detection for OT environments in Doha, Qatar. The role involves deploying security tools and conducting threat hunting while ensuring compliance with IEC 62443 and NIST standards.
Ideal candidates will have a Bachelor’s degree in related fields and certifications such as GICSP. Responsibilities also include incident response, risk assessments, and preparing security reports. Join Starlink WLL to enhance the security posture of industrial control systems.
Deployment and tuning of OT security tools (Nozomi, Forescout) for monitoring OT/ICS environments with SIEM and OT security monitoring platforms. Detect, analyze, and respond to cyber threats targeting industrial control systems.
Support and ensure microsegmentation strategies for OT network zones aligning with the Purdue Model. Collaborate with engineering teams to safely implement containment actions within live OT environments. Conduct threat hunting across industrial environments using network and log data.
Handle and support incident response for OT cyber events with minimal operational disruption. Maintain OT asset visibility and network behavior baselines. Ensure compliance with IEC 62443, NIST IC, and organizational security standards.
Develop and tune OT-specific detection rules and correlation logic within SIEM platforms. Align detection use cases with MITRE ATT&CK for the Industrial Control Systems framework. Reduce false positives and improve detection accuracy and coverage.
Periodically review and optimize alert thresholds and detection logic. Support OT security architecture by integrating SIEM, IDS, IPS, packet brokers, and segmentation tools. Assist in onboarding log sources, parser development, and normalization of OT data. Optimize dashboards, alerts, and reporting for operational visibility.
Operate packet brokers and TAP infrastructure to enable full OT network visibility. Perform deep packet inspection of industrial protocols (Modbus, DNP3, OPC-UA, IEC 104, Ethernet/IP). Analyze east-west and north-south traffic for suspicious activity and lateral movement.
Identify unauthorized communications and protocol anomalies. Support network telemetry collection for OT environments.
Maintain complete OT asset inventory and network topology visibility. Identify unauthorized devices, rogue connections, and shadow OT assets. Conduct proactive threat hunting using logs, network telemetry, and behavioral analytics.
Correlate threat intelligence with OT environment risks and vulnerabilities. Ensure compliance with IEC 62443, NIST IC, ISO standards, and internal security policies. Support internal and external audits and provide security evidence for compliance reporting. Contribute to risk assessments and OT security posture improvement initiatives.
Prepare and present OT security reports, incidents, risks, and trends. Maintain dashboards for vulnerabilities, threats, and compliance status. Communicate critical incidents and risks to SOC, OT, and business stakeholders. Provide executive-level reporting on OT security posture and exposure.
Track remediation status and SLA. Support audit and regulatory reporting requirements (IEC 62443, NIST IC).