img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role: OT Incident Response Lead

Accenture Middle East is seeking an OT Incident Response professional to join their team in Riyadh, Saudi Arabia. This full-time role serves as the senior technical authority within the Operational Technology (OT) Security Operations Center (SOC), focusing on advanced threat hunting, OT-aware digital forensics and incident response (DFIR), and detection engineering. The successful candidate will lead responses to complex and high-severity OT incidents and mentor L1/L2 analysts, driving continuous improvement of the SOC's OT defenses.

Key Responsibilities

  • Lead investigation and response for complex, high-severity, and suspected targeted attacks against OT/ICS environments.
  • Perform proactive, hypothesis-driven threat hunting across OT networks and assets, including designing and running hunt campaigns.
  • Conduct OT-aware DFIR forensic acquisition and analysis of ICS hosts, engineering workstations, HMIs, controllers, and network captures, ensuring process safety and evidence integrity.
  • Design, build, and tune detection content and correlation rules, owning the detection engineering lifecycle for the OT SOC.
  • Operationalize OT threat intelligence (*, threat groups like ELECTRUM/Sandworm and XENOTIME; malware such as TRITON/TRISIS, Industroyer, and PIPEDREAM) and map it to detections via MITRE ATT&CK for ICS.
  • Define, document, and continuously improve OT incident-response playbooks and runbooks.
  • Serve as a senior escalation point and mentor for L1/L2 analysts, providing technical coaching and quality review of investigations.
  • Lead and support OT tabletop exercises and purple team/adversary-emulation activities.
  • Advise on OT network architecture, segmentation, and monitoring placement to address detection gaps.
  • Produce executive and technical incident reports, briefing stakeholders on root cause, impact, and remediation.
  • Support compliance, audit, and regulatory reporting aligned to NCA OTCC-1:2022, ECC, and ISA/IEC 62443, including incident-notification expectations to the NCA.

Required Qualifications and Experience

  • Bachelor's degree in Cybersecurity, Computer/Electrical/Instrumentation Engineering, or a related field; a Master's degree is a plus.
  • 6–10+ years of cybersecurity experience, with a minimum of 4 years specifically in OT/ICS security operations, DFIR, or threat hunting.
  • Deep expertise in OT protocols and ICS architectures (DCS, SCADA, PLC, SIS) and the Purdue model.
  • Proven experience leading OT/ICS incident response and forensic investigations.

Technical Expertise and Certifications

  • Strong command of OT monitoring platforms such as Nozomi, Claroty, Dragos, Tenable OT, and Defender for IoT.
  • Proficiency in SIEM detection engineering platforms including Splunk, QRadar, and Sentinel.
  • Advanced working knowledge of MITRE ATT&CK for ICS, NIST SP 800-82, ISA/IEC 62443, and NCA OTCC.
  • Preferred certifications include GRID, GCIP, GICSP, GCFA, or GREM (GIAC).
  • Vendor expert-level certifications from Dragos, Claroty, or Nozomi are also preferred.

Skills and Attributes

  • Expert analytical, forensic, and reverse-engineering/malware-analysis aptitude within an OT context.
  • Strong leadership, mentoring, and stakeholder-management skills.
  • Sound judgment in balancing cybersecurity response with process safety and operational availability.
  • Excellent written and verbal communication skills in English; Arabic is strongly preferred for regulator and executive engagement.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia. The role requires availability for on-call escalation and incident leadership outside normal business hours.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة