Security Operations IR/OT

aep

Columbus (OH)

On-site

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

American Electric Power is seeking a cybersecurity leader to oversee enterprise-wide initiatives focused on protecting OT/ICS and critical infrastructure. You will mentor the team, guide evaluations of emerging technologies, and lead security incidents to strengthen the organization’s security posture.

Applicants must be eligible for a US security clearance and have deep knowledge of cyber threats, incident response, and malware reverse engineering in industrial environments.

Qualifications

  • Bachelor's degree or associate degree with 2 years relevant experience in IT security or system administration.
  • HS diploma with 4 years relevant IT security experience accepted.
  • Cybersecurity program graduate is acceptable.

Responsibilities

  • Lead the Cyber Intelligence & Response Center (CIRC) in prevention, identification, and response of cyber threats across IT, OT, and cloud environments.
  • Analyze logs, network traffic, endpoint telemetry and other data sources to support investigations.
  • Execute containment, eradication, and recovery steps with stakeholders to maintain operations.
  • Investigate incidents and produce concise response plans and after-action reports.
  • Contribute to tabletop exercises, simulations, and readiness activities focused on cyber events affecting operations.
  • Develop and refine playbooks, runbooks, and response procedures.
  • Analyze cyber threat intelligence to assess impacts on critical infrastructure.
  • Coordinate incident response with U.S. government agencies and industry peers.
  • Collaborate on best practices with government and industry partners.
  • Maintain expertise in OT protocols, ICs, and SCADA systems for threat detection.
  • Familiar with SIEM and OT-relevant network analysis tools.
  • Conduct forensic analysis of host and network events to support investigations.
  • Prepare engaging cyber threat briefings for diverse audiences.
  • Reverse engineer malware to understand threats targeting industrial control systems.
  • Communicate security challenges to senior leadership.
  • Promote team diversity and training for skill development.
  • Create presentations on cybersecurity topics.
  • Formulate solutions for advanced security challenges and process improvements.
  • Motivate the team to learn about security trends.

Skills

Incident Response
Threat Intelligence
Malware Reverse Engineering
OT/ICS Security
Security Leadership

Education

Bachelor's/Associate degree in IT/Security
Cybersecurity program graduate
HS diploma with IT security experience

Tools

SIEM platforms
Network analysis tools
Digital forensics tools

Job description

Job Posting End Date

08-30-2026 Please note the job posting will close on the day before the posting end date.

Job Summary

Responsible for moderate-scale security assignments with limited direction from senior team members. Develops and maintains necessary documentation of security systems, projects, and/or processes to ensure unified understanding of system details. Performs and analyzes security controls assessments (internal and third party) through application security testing, penetration testing or other means to ensure controls effectiveness. Identifies and documents potential mitigations/remediations and creates reports of findings with identified risk response. Participates in the review, evaluation, and recommendation of emerging security technologies. More involved in advanced level implementation, support, and/or usage of technical solutions. Assists with problem solving, decision-making, and functional area knowledge.

Job Description

Responsible for enterprise-wide cybersecurity initiatives focused on protecting industrial control systems and operational technology. Provide direction to team members and lead efforts in the review, evaluation, and recommendation of emerging security technologies relevant to critical infrastructure. Lead and participate in security incidents and projects, directing assignments that enhance the security posture of the organization. Demonstrate advanced problem-solving and decision-making skills, along with deep knowledge of the cybersecurity landscape, particularly in industrial environments. Frequently involved in the implementation, support, and utilization of technical solutions tailored to safeguard operational technology. Mentor team members and provide functional and technical guidance to ensure effective security practices are upheld.

* Applicants must be eligible to obtain a US security clearance*

What you'll do:
Essential Job Functions & Tasks
  • Lead the Cyber Intelligence & Response Center (CIRC) in the prevention, identification, and response of cyber threats across IT, OT, and cloud environments.
  • Analyze logs, network traffic, endpoint telemetry and various other data sources to support investigations.
  • Execute containment, eradication, and recovery steps in coordination with stakeholders while balancing the safety and operational continuity in industrial systems.
  • Investigate incidents and produce concise response plans and after action reports covering containment, eradication, recovery, evidence preservation, remediation, and root cause analysis.
  • Contribute to tabletop exercises, simulations and readiness activities focused on cyber events affecting operations.
  • Participate in the development and refinement of playbooks, runbooks, and response procedures.
  • Analyze cyber threat intelligence products to assess impacts on critical infrastructure.
  • Coordinate incident response efforts with U.S. government agencies and industry peers.
  • Collaborate on cyber threat and security best practices with government and industry partners.
  • Maintain expertise in OT protocols, ICs, and SCADA systems for comprehensive threat detection.
  • Familiar with SIEM platforms and network analysis tools used in OT environments.
  • Conduct forensic analysis of host and network events to support investigations.
  • Prepare and deliver engaging cyber threat briefings to diverse audiences.
  • Reverse engineer malware to understand threats targeting industrial control systems.
  • Communicate security challenges effectively to senior leadership.
  • Promote diversity and ensure team members receive training for skill development.
  • Create presentations on cybersecurity topics and simplify complex concepts.
  • Formulate solutions for advanced security challenges and identify process improvements.
  • Motivate the team to learn about security trends and foster professional growth.
Nice to Have:

Demonstrable experience in one or more of the following disciplines:

  • Incident Response Analyst
  • CIRC/SOC Lead
  • Threat Intelligence or Counterintelligence Analyst
  • Cyber Threat Hunting Analyst
  • Malware Reverse Engineer
  • Operational Technology Specialist, particularly in securing industrial control systems and related environments.
Certifications:
  • CSFA, GCCC, GCDA, GCED, GCFA, GCFE, GCIA, GCIH, GCIP, GCTI, GDAT, GICSP, GMON, GOSI, GREM, GRID, GSOM, GXPN
  • OSCP, OSEE
  • CERT Incident Response Process Professional
  • CREST Certified Host Intrusion Analyst
  • CREST Certified Incident Manager
  • CREST Certified Malware Reverse Engineer
  • CREST Certified Network Intrusion Analyst
What We’re Looking For:

Education requirements are listed below: Bachelor's degree or associate degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cybersecurity Program; alternatively, may have non-degree qualifications (such as hands-

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Vivos Holdings • Smyrna (TN)

On-site
USD 120,000 - 190,000
ICS Threat Intelligence Strategist (OT/SCADA)
ICS Threat Intelligence Strategist (OT/SCADA)

Peraton • Arlington (VA)

On-site
USD 100,000 - 130,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Signature Federal Systems , LLC • Aurora (CO)

On-site
USD 110,000 - 150,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Analyst, Security
Analyst, Security

Socket.dev • Owensboro (KY)

On-site
USD 55,000 - 75,000
Medical
Vision
Dental
+11
OT Cybersecurity Architect (ICS / Mfg Security)
OT Cybersecurity Architect (ICS / Mfg Security)

Bull City Talent Group • Georgia

Hybrid
USD 150,000 - 230,000
Sr Industrial Control System Cyber Threat Intelligence Analyst with OT/CTI/Threat Hunt experience
Sr Industrial Control System Cyber Threat Intelligence Analyst with OT/CTI/Threat Hunt experience

Peraton • Arlington (VA)

On-site
USD 100,000 - 130,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
OT Cybersecurity Engineer
OT Cybersecurity Engineer

LVI Associates • Baltimore (MD)

On-site
USD 110,000 - 150,000
Prin Cybersecurity Specialist - Exempt
Prin Cybersecurity Specialist - Exempt

TALENT Software Services • Town of Texas (WI)

On-site
USD 95,000 - 120,000