SOC Engineer

Starlink WLL

Doha

On-site

QAR 180,000 - 240,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Starlink WLL is looking for a professional specializing in Security Monitoring & Threat Detection for OT environments in Doha, Qatar. The role involves deploying security tools and conducting threat hunting while ensuring compliance with IEC 62443 and NIST standards.

Ideal candidates will have a Bachelor’s degree in related fields and certifications such as GICSP. Responsibilities also include incident response, risk assessments, and preparing security reports. Join Starlink WLL to enhance the security posture of industrial control systems.

Qualifications

  • Experience with OT/ICS systems like SCADA, DCS, and PLC.
  • Proficient in microsegmentation and Zero Trust principles in OT.
  • Strong knowledge in using SIEM and OT monitoring tools.

Responsibilities

  • Deploy and tune OT security tools to monitor OT/ICS environments.
  • Conduct threat hunting and incident response for OT cyber events.
  • Develop and tune detection rules and correlations within SIEM.

Skills

OT/ICS systems (SCADA, DCS, PLC)
OT network architecture (Purdue Model, DMZ, segmentation)
Microsegmentation & Zero Trust for OT
Packet analysis & Deep Packet Inspection (DPI)
Packet brokers & TAP/SPAN technologies
SIEM & OT monitoring tools (Sentinel, Nozomi, Forcescout)
Incident response in OT environments
OT threat hunting & anomaly detection
Threat detection & analysis
Industrial firewalling & remote access security
OT vulnerability management & asset visibility
Compliance (IEC 62443, NIST IC)

Education

Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field
GIAC Global Industrial Cyber Security Professional (GICSP) or equivalent

Job description

Security Monitoring & Threat Detection

Deployment and tuning of OT security tools (Nozomi, Forescout) for monitoring OT/ICS environments with SIEM and OT security monitoring platforms. Detect, analyze, and respond to cyber threats targeting industrial control systems.

Support and ensure microsegmentation strategies for OT network zones aligning with the Purdue Model. Collaborate with engineering teams to safely implement containment actions within live OT environments. Conduct threat hunting across industrial environments using network and log data.

Handle and support incident response for OT cyber events with minimal operational disruption. Maintain OT asset visibility and network behavior baselines. Ensure compliance with IEC 62443, NIST IC, and organizational security standards.

Detection Engineering & Use Case Management

Develop and tune OT-specific detection rules and correlation logic within SIEM platforms. Align detection use cases with MITRE ATT&CK for the Industrial Control Systems framework. Reduce false positives and improve detection accuracy and coverage.

Periodically review and optimize alert thresholds and detection logic. Support OT security architecture by integrating SIEM, IDS, IPS, packet brokers, and segmentation tools. Assist in onboarding log sources, parser development, and normalization of OT data. Optimize dashboards, alerts, and reporting for operational visibility.

OT Network Visibility, Packet Analysis, and Traffic Engineering

Operate packet brokers and TAP infrastructure to enable full OT network visibility. Perform deep packet inspection of industrial protocols (Modbus, DNP3, OPC-UA, IEC 104, Ethernet/IP). Analyze east-west and north-south traffic for suspicious activity and lateral movement.

Identify unauthorized communications and protocol anomalies. Support network telemetry collection for OT environments.

Asset Visibility, Threat Hunting, and Compliance Management

Maintain complete OT asset inventory and network topology visibility. Identify unauthorized devices, rogue connections, and shadow OT assets. Conduct proactive threat hunting using logs, network telemetry, and behavioral analytics.

Correlate threat intelligence with OT environment risks and vulnerabilities. Ensure compliance with IEC 62443, NIST IC, ISO standards, and internal security policies. Support internal and external audits and provide security evidence for compliance reporting. Contribute to risk assessments and OT security posture improvement initiatives.

Reporting & Stakeholder Management

Prepare and present OT security reports, incidents, risks, and trends. Maintain dashboards for vulnerabilities, threats, and compliance status. Communicate critical incidents and risks to SOC, OT, and business stakeholders. Provide executive-level reporting on OT security posture and exposure.

Track remediation status and SLA. Support audit and regulatory reporting requirements (IEC 62443, NIST IC).

Education and Certification Requirements
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field.
  • Certification any one mandatory:
    • GIAC Global Industrial Cyber Security Professional (GICSP)
    • ISA/IEC 62443 Cybersecurity Certificate
    • GIAC Response and Industrial Defense (GRID)
    • ISA Certified Automation Cybersecurity Specialist (IACS)
Job Specific Technical Skills
  • OT/ICS systems (SCADA, DCS, PLC)
  • OT network architecture (Purdue Model, DMZ, segmentation)
  • Microsegmentation & Zero Trust for OT
  • Packet analysis & Deep Packet Inspection (DPI)
  • Packet brokers & TAP/SPAN technologies
  • SIEM & OT monitoring tools (Sentinel, Nozomi, Forcescout)
  • Incident response in OT environments
  • OT threat hunting & anomaly detection
  • Threat detection & analysis
  • Industrial firewalling & remote access security
  • OT vulnerability management & asset visibility
  • Compliance (IEC 62443, NIST IC)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. SOC Engineer - Up to 26k QAR
Sr. SOC Engineer - Up to 26k QAR

Edison Smart® • Doha

On-site
QAR 150,000 - 230,000
Senior OT Security Engineer — ICS Threat Hunting & SIEM
Senior OT Security Engineer — ICS Threat Hunting & SIEM

Edison Smart® • Doha

On-site
QAR 150,000 - 230,000
SOC Engineer
SOC Engineer

Employment • Doha

On-site
QAR 300,000 - 500,000
Cyber Security Specialist
Cyber Security Specialist

Employment • Doha

On-site
QAR 180,000 - 240,000
Cybersecurity Specialist
Cybersecurity Specialist

Salary • Al Khor

On-site
QAR 250,000 - 420,000
ICS/OT Cybersecurity Specialist: Secure Industrial Systems
ICS/OT Cybersecurity Specialist: Secure Industrial Systems

Employment • Doha

On-site
QAR 180,000 - 240,000
SOC Thread Specialist
SOC Thread Specialist

Employment • Doha

On-site
QAR 350,000 - 700,000
Cyber Security Specialist
Cyber Security Specialist

Gulf Drilling International • Doha

On-site
QAR 150,000 - 210,000
SCADA Cyber Security Engineer
SCADA Cyber Security Engineer

Burjline Builders • Doha

On-site
QAR 400,000 - 750,000
SR. INDUSTRIAL CONTROL SYS SECURITY ENGR
SR. INDUSTRIAL CONTROL SYS SECURITY ENGR

QatarEnergy • Mesaieed

On-site
QAR 180,000 - 300,000