All roles

OT Security Operations Engineer

Deploy and tune network monitoring for control systems at grid operators, and turn alerts into actionable detections. You work between the client SOC and the engineers who run the substations.

Apply nowTakes about 3 minutes

About the role

Operators of critical energy infrastructure in Germany must run attack detection systems under §8a BSIG, and NIS2 widens similar duties. Detection only works if someone understands both the alerts and the process behind them. In this role you install passive OT monitoring sensors, baseline normal behaviour of substation and control centre networks, and write detection rules. You work with client SOC analysts, our OT security consultants and substation engineers. The role is based in our Frankfurt lab with regular site visits.

What you will do

  • Deploy OT network monitoring sensors and integrate them with SIEM platforms
  • Baseline traffic for IEC 61850, IEC 60870-5-104 and Modbus networks and reduce false positives
  • Write and test detection use cases mapped to MITRE ATT&CK for ICS
  • Support incident triage with client SOC teams and plant engineers
  • Maintain our test lab with real protection relays, RTUs and gateways

What you bring

  • 3+ years in security operations, network security or industrial automation
  • Experience with at least one OT monitoring product or with Zeek/Suricata
  • Good understanding of TCP/IP and packet analysis with Wireshark
  • Familiarity with SIEM platforms such as Splunk, Microsoft Sentinel or Elastic
  • Willingness to work on site at substations and control centres

Good to have

  • GICSP or GRID certification
  • Experience with the BSI guidance on attack detection systems

Languages

English (C1), German (B1) an advantage

Skills

  • OT monitoring
  • SIEM
  • MITRE ATT&CK for ICS
  • Wireshark
  • Zeek
  • IEC 60870-5-104