img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

أكسنتشر is seeking an OT Incident Response professional to join our team in Riyadh. This full-time position is designed for individuals with 0-1 years of experience who are ready to contribute to advanced operational technology (OT) security operations.

Role Overview and Context

The OT SOC L3 Analyst functions as the senior technical authority within the OT Security Operations Center. This role is central to advanced threat hunting, OT-aware digital forensics and incident response (DFIR), and detection engineering. The analyst also plays a key part in mentoring L1/L2 analysts, leading responses to complex OT incidents, and enhancing the SOC's OT detection capabilities. This position serves as an escalation point and subject matter expert for industrial threat scenarios, translating OT threat intelligence into actionable detections and driving continuous improvement in OT defenses.

Key Responsibilities

  • Lead investigations and response efforts for complex, high-severity, and suspected targeted attacks within OT/ICS environments.
  • Perform proactive, hypothesis-driven threat hunting across OT networks and assets, including designing and executing hunt campaigns.
  • Conduct OT-aware DFIR, including forensic acquisition and analysis of ICS hosts, engineering workstations, HMIs, controllers, and network captures, ensuring process safety and evidence integrity.
  • Design, build, and tune detection content and correlation rules, managing the detection engineering lifecycle for the OT SOC.
  • Operationalize OT threat intelligence, such as information on threat groups (*, ELECTRUM/Sandworm, XENOTIME) and malware (*, TRITON/TRISIS, Industroyer, PIPEDREAM), mapping it to detections using MITRE ATT&CK for ICS.
  • Define, document, and continuously improve OT incident-response playbooks and runbooks.
  • Serve as a senior escalation point and mentor for L1/L2 analysts, providing technical coaching and quality review of investigations.
  • Lead and support OT tabletop exercises and purple team/adversary-emulation activities.
  • Advise on OT network architecture, segmentation, and monitoring placement to address detection gaps.
  • Produce executive and technical incident reports, briefing stakeholders on root cause, impact, and remediation.

Required Experience and Expertise

This role requires 0-1 years of experience, indicating a foundational understanding and eagerness to develop expertise in operational technology security. Candidates should possess or be prepared to rapidly acquire knowledge in:

  • Advanced threat hunting methodologies specific to OT environments.
  • Digital forensics and incident response (DFIR) techniques for industrial control systems (ICS).
  • Designing and implementing detection content and correlation rules.
  • Understanding and applying OT threat intelligence, including specific threat groups and malware.
  • Developing and refining incident response playbooks.
  • Mentoring and providing technical guidance to junior analysts.
  • Knowledge of OT network architecture and security best practices.

Compliance and Reporting

The role involves supporting compliance, audit, and regulatory reporting aligned with standards such as NCA OTCC-1:2022, ECC, and ISA/IEC 62443. This includes adhering to incident-notification expectations set by the NCA.

Work Environment

This is a full-time position based in Riyadh, where you will contribute to a specialized team focused on enhancing OT security defenses.


Requirements

  • No experience required

Similar Jobs