Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
NC

OT Threat Hunter & Detection

NR Consulting - India
๐Ÿ‡ฎ๐Ÿ‡ณ India
On-site
2 weeks ago
  • Threat Intelligence
  • HMI
  • triage
  • PLC
  • SIEM
  • Incident Response
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Title: OT Threat Hunter & Detection
Location: Mumbai / Bangalore
Exp: 8-16 Yrs

Job Description:

Key Responsibilities
  • OT Threat Hunting
  • Conduct proactive threat hunting across OT and ICS environments.
  • Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
  • Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
  • Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
  • Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
  • Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
  • Map findings to MITRE Telecommunication&CK for ICS and MITRE Telecommunication&CK Enterprise where applicable. Detection Engineering.
  • Develop and validate OT-specific detection use cases and analytics.
  • Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
  • Review existing OT monitoring coverage and identify detection gaps.
  • Tune security alerts to improve detection quality and reduce unnecessary false positives.
  • Establish baseline communication patterns for critical industrial assets and network zones.
  • Develop detection logic for: o Unauthorised asset connections o Unexpected protocol usage o New or abnormal communication paths o Suspicious remote access o Credential misuse o Lateral movement o Engineering-workstation anomalies o Changes to PLC or controller communication โ€ข
  • Support purple-team exercises by validating whether simulated attack activity is detected and investigated effectively. Alert Investigation and Incident Support
  • Analyse and triage alerts generated by OT IDS, NDR, SIEM and endpoint-security platforms.
  • Correlate alerts across IT and OT systems to identify potential attack paths.
  • Conduct initial compromise assessments and support incident scoping.
  • Gather, preserve and document relevant investigation evidence.
  • Work with incident-response teams to recommend containment, monitoring and recovery actions.
  • Support post-incident reviews and convert lessons learned into improved detection content.
  • Escalate critical findings in accordance with agreed incident and operational procedures. OT Visibility and Monitoring
  • Review OT asset inventories and identify unknown, unmanaged or unauthorised devices.
  • Assess the quality and coverage of network sensors, packet collection and log sources.
  • Validate asset classification, communication baselines and criticality information.
  • Identify monitoring gaps across industrial zones and conduits.
  • Support the onboarding of relevant OT data sources into SIEM, SOC and detection platforms.
  • Work with plant teams to ensure monitoring activities do not affect operational availability
  • Reporting and Stakeholder Engagement
  • Prepare clear threat-hunting and investigation reports containing: o Investigation scope o Hunting hypothesis o Data sources reviewed o Findings and supporting evidence o Affected ass.

OT Threat Hunter & Detection ยท NR Consulting - India

Auto apply with Likeremote