11 Sep
|
apptoza
|
Calgary
HIRING: OT SOC Lead – Operational Technology Security Operations Center ?
We are looking for an experienced OT SOC Lead (Operational Technology Security Operations Center Lead) with strong expertise in OT SOC Operations, Microsoft Sentinel, Azure Cloud Security, KQL, Logic Apps/Playbooks, and Industrial Control Systems (ICS/OT).
Role: Must-Have:(Ideally should have more than or approx. 5-6 Years) Microsoft Sentinel, EDR, Automate/Logic Apps for automation, OT SOC
Good-to-Have: PowerShell scripting
SN Responsibility of / Expectations from the Role
1 Proven experience leading and managing OT SOC operations, including monitoring, triage, investigation, escalation, and response to OT security incidents
2 Administer and maintain Microsoft Sentinel workspaces across multi‑cloud environments.
3 Automate incident response workflows using Logic Apps and Sentinel playbooks.
4 Develop and optimize KQL queries for log analytics and threat hunting.
5 Implement custom rules, alerts, and analytics for proactive detection.
6 Ensure seamless ingestion of telemetry from diverse cloud services.
7 Automate repetitive OT SOC tasks to enhance operational efficiency.
8 Manage Sentinel dashboards and reporting for OT SOC visibility.
9 Troubleshoot connector issues and optimize ingestion pipelines.
10 Strong knowledge of Industrial Control Systems (ICS) and OT technologies such as SCADA, DCS, PLCs, HMI, OPC, Modbus, and Purdue Model architecture.
11 Document automation processes, playbooks, and connector configurations.
12 Provide guidance on Sentinel best practices and cloud security posture.
13 Contribute to continuous improvement of SOC automation and administration processes.
14 Resolves customer issues through problem solving, collaboration,
and research. May take escalated issues as needed. Documents technical work and research.
15 Performs in-depth product troubleshooting and remediation when needed.
16 Collaborates on cross-team and cross-product technical issues by working with resources from other groups as needed to resolve moderately complex customer issues
17 Excellent stakeholder management, leadership, and communication skills with experience collaborating with OT operations, engineering teams, incident response teams, and executive leadership on cybersecurity initiatives
18 Expertise in Detection Engineering, including development, tuning, and optimization of security analytics aligned to MITRE ATT&CK; for ICS/OT environments
Focus: OT SOC Operations | ICS/OT Cybersecurity | Microsoft Sentinel | Azure Security
Environment: Industrial Control Systems / Operational Technology
Must-Have:(Ideally should have more than or approx. 5-6 Years) Microsoft Sentinel, EDR, Automate/Logic Apps for automation, OT SOC
Good-to-Have: PowerShell scripting
SN Responsibility of / Expectations from the Role
1 Proven experience leading and managing OT SOC operations, including monitoring, triage, investigation, escalation, and response to OT security incidents
2 Administer and maintain Microsoft Sentinel workspaces across multi‑cloud environments.
3 Automate incident response workflows using Logic Apps and Sentinel playbooks.
4 Develop and optimize KQL queries for log analytics and threat hunting.
5 Implement custom rules, alerts, and analytics for proactive detection.
6 Ensure seamless ingestion of telemetry from diverse cloud services.
7 Automate repetitive OT SOC tasks to enhance operational efficiency.
8 Manage Sentinel dashboards and reporting for OT SOC visibility.
9 Troubleshoot connector issues and optimize ingestion pipelines.
10 Robust knowledge of Industrial Control Systems (ICS) and OT technologies such as SCADA, DCS, PLCs, HMI, OPC, Modbus, and Purdue Model architecture.
11 Document automation processes, playbooks, and connector configurations.
12 Provide guidance on Sentinel best practices and cloud security posture.
13 Contribute to continuous improvement of SOC automation and administration processes.
14 Resolves customer issues through problem solving, collaboration, and research. May take escalated issues as needed. Documents technical work and research.
15 Performs in-depth product troubleshooting and remediation when needed.
16 Collaborates on cross-team and cross-product technical issues by working with resources from other groups as needed to resolve moderately complex customer issues
17 Excellent stakeholder management, leadership, and communication skills with experience collaborating with OT operations, engineering teams, incident response teams, and executive leadership on cybersecurity initiatives
18 Expertise in Detection Engineering, including development, tuning, and optimization of security analytics aligned to MITRE ATT&CK; for ICS/OT environments.
📌 OT SOC Lead – Operational Technology Security Operations Center ( Calgary)
🏢 apptoza
📍 Calgary