OT Security Analyst

Pyramid Consulting, Inc

Dallas (TX)

On-site

USD 62,000 - 69,000

Full time

12 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid sick leave

Job summary

Pyramid Consulting, Inc. is seeking a Senior SOC Analyst to oversee OT/ICS security operations in a 24/7 SOC in Dallas. You will lead incident response and coordinate with cross-functional teams to ensure timely containment.

The role requires 5–7 years in cybersecurity with OT/ICS experience, advanced certifications, and the ability to mentor junior analysts. On-site interviews are required; parking arrangements will be discussed.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field required.
  • Advanced certifications such as CySA+, CEH, OSCP, GICSP, CCNA Security or OT security certs preferred.
  • 3+ years working with OT/ICS environments including SCADA, PLCs, RTUs, HMIs.

Responsibilities

  • Oversee SOC operations during assigned shifts with SLA adherence.
  • Lead investigations and incident response for OT/ICS security events.
  • Analyze security alerts and logs in ICS/SCADA environments to identify IOCs.
  • Make real-time decisions on incident severity, containment, and escalation.
  • Evaluate and optimize detection rules and security technologies (SIEM, SOAR, IIDS/IPS).
  • Develop, test, and implement OT-focused detection rules and playbooks.
  • Proactively search for IOCs and misconfigurations in OT networks.
  • Document actions and create management reports on incidents and trends.
  • Provide guidance and mentorship to Tier 1–2 analysts and conduct trainings.
  • Stay current on NERC-CIP, NIST CSF, Purdue, ISO 27001 and OT security practices.

Skills

SOC operations
OT/ICS security
Incident response
Threat analysis
Mentoring

Education

Bachelor's in IT/CS/Cybersecurity
Master's degree preferred

Tools

SIEM/SOAR
IIDS/IPS
EDR tools
Network analysis

Job description

Pay Range: $45/hr - $50/hour. Employee benefits include, but are not limited to, health insurance (medical, dental, vision), 401(k) plan, and paid sick leave (depending on work location).

Key Responsibilities
  • In-person interview required.
  • Also, If any candidate is selected for this position, The candidate is responsible for the Parking for his daily commute to office.
  • This has to be confirmed with the candidate before submitting the profiles.
  • Oversee SOC operations during assigned shifts, ensuring efficient workflow, proper escalation procedures, adherence to SLAs, and effective communication between analysts.
  • Lead investigations and response to complex security incidents impacting OT systems, networks, and applications. This includes coordinating efforts with other teams and business units (e.g. Networking, Architecture, CIP Compliance).
  • Perform in-depth analysis of security alerts and logs common inICS/SCADA systems to identify indicators of compromise (IOCs).
  • Make real-time decisions on incident severity, containment strategies, and escalation paths and actions taken by Tier 1 & 2 analysts for incidents.
  • Evaluate and provide feedback on the performance of security technologies (e.g. SIEM, SOAR, IIDS/IPS) used in the SOC. Identify and oversee the optimization of detection rules to reduce false positives.
  • Develop, test, and implement custom detection rules, correlation searches, baseline drift and use cases within the toolset to improve threat detection capabilities specifically tailored to OT protocols and environments.
  • Proactively search for IOCs and misconfigurations within the OT environment using threat intelligence, anomaly detection techniques, and knowledge of attacker tactics, techniques, and procedures (TTPs) relevant toICS/SCADA systems.
  • Create, maintain, and refine incident response playbooks, standard operating procedures (SOPs), and runbooks based on lessons learned from incidents, threat intelligence, and industry best practices.
  • Ensure all actions, findings, and decisions made during incident handling are thoroughly documented in the SOC’s ticketing system. Prepare clear and concise reports for management on security incidents and trends.
  • Provide guidance, training, and mentorship to Tier 1 & 2 analysts on incident handling, analysis techniques, tools, and OT security concepts.
  • Participate in training sessions and simulations to stay current on cyber threats, OT security best practices, and monitoring tools.
  • Stay current on NERC-CIP standards (specifically 2/3), NIST CSF, Purdue Model for Industrial Control Systems, ISO 27001 frameworks, and other relevant OT security regulations.
Key Requirements and Technology Experience
  • Bachelor’s Degree in Information Technology, Computer Science, Cybersecurity, or a related field required. Master's degree preferred.
  • Minimum of 5-7 years of experience in a cybersecurity-focused role; SOC experience strongly preferred.
  • 3+ years of direct experience working with Operational Technology (OT) / Industrial Control Systems (ICS) environments – including hands‑on knowledge of SCADA systems, PLCs, RTUs, HMIs, and industrial networks.
  • Advanced certifications strongly desired. Examples include: CySA+, CEH, OSCP, GICSP, CCNA Security, or relevant OT security certifications (e.g., ISA/IEC 62443).
  • Deep understanding of cybersecurity fundamentals such as networking protocols (TCP/IP, UDP, DNS), operating systems (Windows, Linux), and security architecture principles.
  • Strong knowledge of OT Protocols such as DNP3, Modbus, IEC 104, OPC UA, including packet analysis and understanding protocol vulnerabilities.
  • Experienced with Security Technologies such as SIEM, SOAR, IIDS/IPS, endpoint detection solutions, network traffic analysis tools.
  • Exceptional analytical mindset and attention to detail. Ability to analyze complex data sets, identify patterns, and draw meaningful conclusions.
  • Excellent verbal and written communication skills to effectively communicate technical information to both technical and non‑technical stakeholders. Ability to create clear and concise reports.
  • Demonstrated ability to lead and mentor junior analysts.
  • Ability to work in a 24/7 shift-based SOC environment, including covering for teammates and occasional after‑hours support.
  • Measures of Success
  • Demonstrates leadership in handling complex security incidents and coordinating response efforts.
  • Significant improvement in key performance indicators (e.g., reduction in mean time to detect (MTTD), mean time to respond (MTTR), false positive rate).
  • Successful development and implementation of new detection rules and use cases that improve threat coverage.
  • Ensures Oncor’s timelines, budgets, and deliverable objectives are met.
  • Ensures the DGM SOC’s SLAs are met or exceeded.
  • Works closely with multiple business units to improve cross-functional communication and efficiencies.
  • Demonstrates skills in prioritization and multi-tasking, and success in adapting to change in a fast‑paced environment.
  • Demonstrates ability to interface with internal and external business partners in a professional manner.

Our client is a leading IT Industry, and we are currently interviewing to fill this and other similar contract positions.

Pyramid Consulting, Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Prin Cybersecurity Specialist - Exempt
Prin Cybersecurity Specialist - Exempt

TALENT Software Services • Town of Texas (WI)

On-site
USD 95,000 - 120,000
OT Cybersecurity Analyst
OT Cybersecurity Analyst

Attractivate Consulting Solutions • Houston (TX)

On-site
USD 90,000 - 130,000
Full benefits
Certification support
OT Cybersecurity Architect
OT Cybersecurity Architect

Plexus Corp. • Neenah (WI)

Hybrid
USD 129,000 - 195,000
Medical, dental, and vision insurance
Paid time off
Retirement savings
+2
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • New Cumberland

On-site
USD 90,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with company matching
Paid time off
+1
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Battle Creek (MI)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+3
Lead OT SOC Architect
Lead OT SOC Architect

Jacobs • Baton Rouge (LA)

On-site
USD 145,000 - 180,000
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Pennsylvania

On-site
USD 120,000 - 180,000
Medical, dental, vision insurance
401(k) with company matching
Paid time off
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Dayton (OH)

On-site
USD 80,000 - 100,000
Medical insurance
401(k) plan with matching
Paid time off
Operational Technology Security Engineer
Operational Technology Security Engineer

Nisga'a Tek, LLC • New Cumberland

On-site
USD 110,000 - 150,000
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Ogden (UT)

On-site
USD 90,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with company matching
Paid time off