img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Accenture Saudi Arabia is seeking an OT Incident Response professional to join its team in Riyadh. This full-time role serves as a senior OT SOC L3 Analyst, responsible for advanced threat hunting, OT-aware digital forensics and incident response (DFIR), and detection engineering within Operational Technology (OT) environments. The position requires 6-10+ years of cybersecurity experience, with a significant focus on industrial threat scenarios and continuous improvement of OT defenses.

Key Responsibilities

  • Lead investigations and response for complex, high-severity, and suspected targeted attacks against OT/ICS environments.
  • Perform proactive, hypothesis-driven threat hunting across OT networks and assets, including designing and running hunt campaigns.
  • Conduct OT-aware DFIR, including forensic acquisition and analysis of ICS hosts, engineering workstations, HMIs, controllers, and network captures, ensuring process safety and evidence integrity.
  • Design, build, and tune detection content and correlation rules, owning the detection engineering lifecycle for the OT SOC.
  • Operationalize OT threat intelligence (*, threat groups such as ELECTRUM/Sandworm and XENOTIME; malware such as TRITON/TRISIS, Industroyer, and PIPEDREAM) and map it to detections via MITRE ATT&CK for ICS.
  • Define, document, and continuously improve OT incident-response playbooks and runbooks.
  • Serve as a senior escalation point and mentor for L1/L2 analysts, providing technical coaching and quality review of investigations.
  • Lead and support OT tabletop exercises and purple team/adversary-emulation activities.
  • Advise on OT network architecture, segmentation, and monitoring placement to close detection gaps.
  • Produce executive and technical incident reports, briefing stakeholders on root cause, impact, and remediation.
  • Support compliance, audit, and regulatory reporting aligned to NCA OTCC-1:2022, ECC, and ISA/IEC 62443, including incident-notification expectations to the NCA.

Required Qualifications and Experience

  • Bachelor's degree in Cybersecurity, Computer/Electrical/Instrumentation Engineering, or a related field; a Master's degree is a plus.
  • 6–10+ years of cybersecurity experience, with a minimum of 4 years specifically in OT/ICS security operations, DFIR, or threat hunting.
  • Deep expertise in OT protocols and ICS architectures (DCS, SCADA, PLC, SIS) and the Purdue model.
  • Proven experience leading OT/ICS incident response and forensic investigations.

Essential Technical Skills

  • Strong command of OT monitoring platforms such as Nozomi, Claroty, Dragos, Tenable OT, and Defender for IoT.
  • Proficiency in SIEM detection engineering platforms including Splunk, QRadar, and Sentinel.
  • Advanced working knowledge of MITRE ATT&CK for ICS, NIST SP 800-82, ISA/IEC 62443, and NCA OTCC.
  • Expert analytical, forensic, and reverse-engineering/malware-analysis aptitude in an OT context.

Preferred Certifications

  • GIAC certifications such as GRID, GCIP, GICSP, GCFA, or GREM are strongly preferred.
  • Vendor expert-level certifications from Dragos, Claroty, or Nozomi.

Additional Requirements

  • Strong leadership, mentoring, and stakeholder-management skills.
  • Sound judgment in balancing cybersecurity response against process safety and operational availability.
  • Excellent written and verbal communication in English; Arabic is strongly preferred for regulator and executive engagement.
  • Availability for on-call escalation and incident leadership outside normal hours.

Requirements

  • Requires 5-10 Years experience

Similar Jobs