Operational Technology (OT) Incident Response Consultant

🔥 17 hours ago

🇷🇴 Romania – Remote

⏰ Full Time

🟢 Junior

🟡 Mid-level

💼 Consultant

🚫👨‍🎓 No degree required

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sophos

Sophos

1001 - 5000 employees

Founded 1985

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

💰 Post-IPO Equity on 2021-08

Consulting • Healthcare • Manufacturing

Sophos is a leading cybersecurity company that specializes in protecting businesses against advanced cyber threats. The company offers a comprehensive suite of security solutions, including endpoint protection, managed detection and response (MDR), network security, and cloud security. With a prevention-first approach, Sophos aims to stop ransomware and other cyber threats before they cause harm. Sophos provides services such as threat research, security training, and operational support to ensure robust defense against cyberattacks. Their solutions cater to various industries including finance, healthcare, government, manufacturing, and retail. The Sophos Central platform delivers centralized security management, integrating seamlessly with existing IT infrastructure to enhance security posture.

📋 Description

• Investigate and respond to high-severity OT security incidents • Perform root cause analysis to determine threat origin, attack scope, and affected assets • Conduct threat analysis across industrial environments • Analyze network traffic, system logs, and security events to identify malicious activity and attack patterns • Research emerging threat actors, attack campaigns, and OT-specific tactics, techniques, and procedures • Develop and enhance OT-specific detection use cases and threat detection procedures • Tune and optimize alerts generated by OT security controls • Correlate information from security platforms, threat intelligence feeds, network telemetry, and other data sources • Support SIEM monitoring strategies, escalation workflows, and alerting mechanisms • Serve as a subject matter expert during OT cybersecurity incidents and security engagements • Provide technical recommendations for remediation, mitigation, and risk reduction • Support customers in strengthening OT cybersecurity programs, processes, and operational procedures • Assist with designing and implementing proactive OT security controls and monitoring capabilities • Contribute to new security capabilities, tools, and automation initiatives • Stay current with OT security trends, vulnerabilities, defensive technologies, and industry best practices • Work closely with customers to identify threats, reduce risk, and improve operational resilience • Help organizations maintain the safety, reliability, and security of operational environments while enhancing cyber defense posture

🎯 Requirements

• Experience working in cybersecurity, incident response, security operations, or threat detection environments • Desirable minimum 2 years of experience supporting industrial control systems such as PLCs, RTUs, DCS, SIS, SCADA, HMI, MES, or Historians • Understanding of OT and ICS architectures and operational environments • Experience investigating security incidents and performing root cause analysis • Hands-on experience with SIEM technologies, event monitoring, detection use cases, alert tuning, escalation workflows, and threat intelligence • Experience analyzing firewall logs, IDS/IPS events, system logs, network telemetry, and security events • Solid understanding of TCP/IP and UDP network protocols • Familiarity with industrial communication protocols such as Modbus and DNP3 • Understanding of the Purdue Enterprise Reference Architecture model • Ability to conduct network traffic analysis and identify indicators of compromise in OT environments • Understanding of cyber threat actor tactics, techniques, and procedures (TTPs) • Experience with vulnerability analysis, threat research, and security investigations • Ability to communicate in English • Willingness to participate in shift work including nights, weekends, and holidays • Legal authorization to work in Romania without employer sponsorship

🏖️ Benefits

• Remote-first working model, with remote work as the primary option for most employees • Employee-led diversity and inclusion networks • Annual charity and fundraising initiatives • Volunteer days • Global employee sustainability initiatives • Global fitness and trivia competitions • Global wellbeing days • Monthly wellbeing webinars and training • Equal-opportunity and inclusive workplace commitment • Recruitment and selection process adjustments to support applicants with disabilities or other needs

Apply Now

Similar Jobs

🕒 September 10

Manning Global AG

501 - 1000

💼 Consulting

🏥 Healthcare

📦 Logistics

NOC Consultant supporting Core CS network operations for Manning Global’s managed services project. Leading complex incidents, changes, projects, and 24/7 second-line support.

🕒 July 21

Brainlab

1001 - 5000

💼 Consulting

📦 Logistics

🏭 Manufacturing

Application Consultant supporting Sales Team in Image Guided Surgery for a health technology company. Educating and assisting medical staff in the usage of advanced digital solutions.

🇷🇴 Romania – Remote

💰 Private Equity Round on 2018-09

⏰ Full Time

🟡 Mid-level

🟠 Senior

💼 Consultant

🗣️🇷🇴 Romanian Required

🕒 July 10

Suvoda

501 - 1000

🏥 Healthcare

📦 Logistics

💼 Consulting

Technical Consultant maintaining Suvoda’s clinical-trial IRT systems for randomization and drug supply management. Supporting system changes, integrations, training, troubleshooting, and client delivery.

🇷🇴 Romania – Remote

💰 $40M Venture Round on 2019-12

⏰ Full Time

🟢 Junior

🟡 Mid-level

💼 Consultant

🕒 June 3

E.ON

10,000+ employees

⚡ Energy

👥 B2C

🤝 B2B

IT Consultant for FSMS providing consultancy and support for system management. Collaborate with a global team to enhance system performance and user experience.

🗣️🇷🇴 Romanian Required