Lead OT SOC Architect

Jacobs

Baton Rouge (LA)

On-site

USD 145,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jacobs seeks an experienced Lead OT SOC Architect to design and lead a productized, multi-tenant OT Security Operations Center delivered as a managed service. You will architect the SIEM and detection-engineering platform, define triage/workflows, and guide SOC engineers and analysts as the top escalation authority.

You will translate deep Security Operations expertise into an OT defense capability, collaborating with controls, instrumentation, and systems teams to ensure OT telemetry is

Qualifications

  • Extensive experience designing, building, and operationalizing a Security Operations Center (SOC) from the ground up.

Responsibilities

  • Architect the OT SOC platform, SIEM, detection workflows, and multi-tenant service delivery.

Skills

SOC architecture
SIEM design
OT/ICS security
MITRE ATT&CK
Leadership
Threat hunting
Networking fundamentals
Security governance
Documentation

Tools

Elastic
Splunk
Purdue Model

Job description

At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.

Your impact

Are you a proven Security Operations Center architect ready to design and lead the defense of the world's most critical infrastructure? Have you built a SOC from the ground up — the platform, the detection content, the team — and are you ready to bring that mastery to the operational technology systems that keep water flowing, power on, and communities running? Are you ready to take your career in Security Operations to its technical peak with one of the largest technology and engineering firms in the world? As the Lead OT SOC Architect, you'll be the architect and technical leader of Jacobs' managed OT Security Operations Center — designing the platform, defining what good looks like, and leading the engineers and analysts who protect our clients' most consequential systems. Jacobs designs and builds the world's infrastructure, and you'll play the central role in defending the industrial control systems at its heart.

As the Lead OT SOC Architect, you will own the design and technical direction of a productized, multi-tenant OT Security Operations Center delivered as a managed service. You'll architect the SIEM and detection-engineering platform, design the triage and response workflows, and establish the standards your team operates by. You will lead, mentor, and set direction for SOC engineers and analysts, and you'll serve as the top-tier technical escalation point — the lead authority who resolves the hardest SOC issues before they reach the OT SOC Manager. From detection strategy and platform architecture through continuous operational assurance, you'll translate deep Security Operations expertise into a defense capability tuned to the unique realities of OT where a cyber event is not a data event but a physical one, with consequences that can include operational disruption, environmental impact, and loss of life. You'll work across sales and delivery to embed this capability into new and active client programs, and you'll partner closely with controls, instrumentation, and systems teams across critical infrastructure OT control systems to ensure OT telemetry is visible, meaningful, and defended.

Are you ready to lead the technical heart of a next-generation OT SOC? At Jacobs, we are building a more connected and sustainable world. Come join us as we engineer and defend the networks at the core of today's global infrastructure.

Responsibilities

Primary responsibilities center on architecting the OT SOC platform and service, leading its detection-engineering and operations design, supervising the SOC team, and serving as the lead technical escalation authority — with additional responsibilities supporting client engagements and business development.

  • Architect the end-to-end OT SOC platform — SIEM, detection pipeline, data model, enrichment, and multi-tenant service architecture — designing every decision for a scalable, productized managed-service end state
  • Own the detection-engineering strategy and lifecycle design, build, test, version-control, and continuously improve detection content mapped to MITRE ATT&CK for ICs, treating detections as code with change control and measurable coverage
  • Design the SOC operational workflows — alert triage, severity routing, case management, escalation paths, and response playbooks — and codify the standards the team operates by
  • Serve as the top-tier technical escalation point for all SOC issues, resolving the most complex and high-severity investigations before they require the OT SOC Manager's involvement
  • Lead, mentor, and develop SOC engineers and analysts; set investigation standards, triage thresholds, and escalation criteria that drive consistency, quality, and analyst growth
  • Establish and own "continuous operational assurance" — defining what good looks like for each client environment, continuously verifying reality matches that model, and surfacing deviations before they become incidents
  • Design consequence-driven detection layer engineering and control-system context onto OT platform data so alerts reflect physical-process impact, not just network anomalies
  • Own the health and direction of the security technology stack — SIEM, OT monitoring platforms, log collection, enrichment, and integrations — ensuring telemetry is complete, parsed, and detection-ready
  • Architect secure, multi-tenant data collection and segregation across client environments aligned to Purdue Model zones and IEC 62443 zones and conduits
  • Partner with sales and delivery teams to scope, design, and embed OT SOC capabilities into new contract opportunities and active client programs
  • Coordinate closely with controls, instrumentation, and systems engineering teams to integrate critical infrastructure OT control systems and network telemetry into the SOC's detection and monitoring architecture
  • Produce leadership- and client-facing reporting on SOC posture, coverage, and operational assurance; support compliance evidence for OT-relevant regulatory and audit requirements
  • Participate in and lead escalation support during high-severity incidents, including after-hours response depending on client contract requirements
Here’s what you'll need
  • Extensive experience designing, building, and operationalizing a Security Operations Center (SOC) from the ground up — platform, detection content, workflows, and team
  • 10+ years in cybersecurity with deep Security Operations expertise, including 5+ years in a lead, architect, or senior technical role directing SOC design and operations
  • Extensive experience applying the SOC-CMM (SOC Capability Maturity Model) to assess, benchmark, and continuously mature a SOC function — driving measurable growth across the people, process, and technology capabilities required to advance SOC maturity over time
  • Expert-level hands-on SIEM architecture and detection-engineering experience (Elastic strongly preferred; equivalent enterprise SIEM experience such as Splunk, Sentinel, QRadar, Stellar Cyber, or AlienVault applicable)
  • Demonstrated experience leading and mentoring SOC analysts and engineers, and serving as a lead escalation point for advanced (Tier 3/Tier 4) investigations and threat hunting
  • Proven detection-engineering depth authoring, tuning, and lifecycle-managing detection content, with expertise in the MITRE ATT&CK framework (and the ability to apply ATT&CK for ICT to OT environments)
  • Strong understanding of networking fundamentals — routing, switching, VLANs, segmentation, and firewall policy management — with the ability to apply network segmentation to Purdue Model architectures
  • Working knowledge of the Purdue Enterprise Reference Architecture and IEC 62443, or demonstrated ability to rapidly apply deep IT-SOC and security-architecture expertise to OT/ICS environments
  • Experience designing SOC operational processes alert triage, case management, incident response, escalation, and playbook development
  • Experience with security architecture and engineering firewalls, IDS/IPS, secure remote access (VPN and modern alternatives such as ZTNA), IAM/PAM, and Zero Trust Architecture
  • Experience designing or delivering managed security services (Managed SOC, MDR/MXDR, or equivalent), including productized, multi-client service models
  • Strong governance and framework grounding NIST CSF, NIST 800-53, CIS Controls, and the ability to extend into OT frameworks (IEC 62443, NIST SP 800-82)
  • Hands‑on systems and infrastructure depth Active Directory, Linux administration, and virtualization platforms (VMware, Hyper‑V, Proxmox, Nutanix, or equivalent)
  • Excellent written and verbal communication, with the ability to translate technical risk into operational and business impact for both engineers and executives
Preferred
  • Direct OT/ICS security experience OT network monitoring platforms (Dragos, Claroty, Nozomi, Nomic), OT-safe operations, and industrial environments
  • IAT Level II or equivalent certification (Security+, GICSP); GIAC GRID, GCIP, or CISSP
  • Expertise in MITRE ATT&CK for ICs specifically, including ICs technique-mapped detection content
  • Knowledge of OT/ICS protocols — Modbus, DNP3, IEC 61850, SEL, PROFINET — serial and IP-based
  • Working knowledge of NIST SP 800-82 and OT-specific regulatory context (NERC CIP, AWIA, CIRCIA)
  • Hands‑on experience with critical infrastructure OT control systems and ICS components — PLCs, HMIs, RTUs, controllers — and the consequence analysis that ties control-system knowledge to detection
  • Cisco (CCNP Security, CCNA), Fortinet NSE, or equivalent network/security certifications
  • Experience in water/wastewater, power generation, or other critical-infrastructure verticals
  • Experience with SOAR and detection automation (Swimlane, Siemplify, or equivalent), and threat‑intelligence platforms (MISP, OpenCTI)
  • Experience in 24x7 managed-services or operational support environments, and familiarity with IT/OT service management (incident, change, problem management)
  • Experience balancing operational SOC leadership with project-based design and assessment work

Our health and welfare benefits are designed to invest in you, and in the things you care about. Your health. Your well-being. Your security. Your future. Employees have access to medical, dental, vision, and basic life insurance, a 401(k) plan, paid time off, and the ability to purchase company stock at a discount. Eligible employees may also enroll in a deferred compensation plan or the Executive Deferral Plan. And certain roles may be eligible for additional rewards, including merit increases, performance discretionary bonus, and stock.

The base salary range for this position is $145,000.00 to $180,000.00. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. Job posted on August 24, 2026. This position will be open for at least 3 days.

Your application experience is important to us, and we’re keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead OT SOC Architect
Lead OT SOC Architect

Jacobs • Houston (TX)

On-site
USD 180,000 - 240,000
Senior OT Cybersecurity Engineer
Senior OT Cybersecurity Engineer

Jacobs • Fort Lauderdale (FL)

On-site
USD 140,000 - 165,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior OT Cybersecurity Engineer
Senior OT Cybersecurity Engineer

Jacobs • Atlanta (GA)

On-site
USD 140,000 - 165,000
Medical insurance
401(k) plan
Stock purchase plan
Lead OT SOC Architect: Build & Defend Critical Infra
Lead OT SOC Architect: Build & Defend Critical Infra

Jacobs • Houston (TX)

On-site
USD 180,000 - 240,000
Senior OT Cybersecurity Specialist - NERC CIP
Senior OT Cybersecurity Specialist - NERC CIP

Jacobs Engineering Group Inc. • Houston (TX), Northern (KY)

Hybrid
USD 150,000 - 175,000
Health benefits
401(k) plan
Stock purchase plan
Senior Security Consultant, Operational Technologies (OT)
Senior Security Consultant, Operational Technologies (OT)

IOActive, Inc. • Seattle (WA)

Hybrid
GBP 100,000 - 175,000
Flexibility to work remotely or from the office
Opportunities for travel
Competitive compensation
+1
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Lead Operational Technology (OT) Cybersecurit
Lead Operational Technology (OT) Cybersecurit

Applied Digital • Dallas (TX)

Hybrid
USD 120,000 - 150,000
Senior Information Security Engineer - OT/IoT & Operational Technology (OT) Security
Senior Information Security Engineer - OT/IoT & Operational Technology (OT) Security

QTS Data Centers • Suwanee (GA)

On-site
USD 100,000 - 140,000
Competitive compensation and bonus eligibility
Comprehensive benefits package
401(k) with company match
+1
OT Systems Network Engineer
OT Systems Network Engineer

Enterprise Automation • Irvine (CA)

On-site
USD 110,000 - 140,000