Senior SOC Engineer – OT Security

Apply Now ↗
📍 Doha, Ad Dawhah, QatarFull time
IT Services

About this role

Black & Grey HR is recruiting for an established technology solutions and services provider in Doha, Qatar. Our client is seeking an experienced Senior SOC Engineer – OT Security to lead advanced security monitoring, threat detection, incident response, and threat hunting across Operational Technology (OT) and Industrial Control System (ICS) environments. The role is critical in strengthening OT cyber resilience while ensuring security controls are implemented without disrupting high-availability, mission-critical industrial operations. Key Responsibilities Security Monitoring & Threat Detection - Administer, manage, support deployment, and tune OT security monitoring tools such as Nozomi and Forescout. - Monitor OT/ICS environments using SIEM and specialized OT security monitoring platforms. - Detect, investigate, analyze, and respond to cyber threats targeting industrial control systems. - Maintain OT asset visibility and establish network behavior baselines. - Support micro-segmentation strategies across OT network zones in alignment with the Purdue Model. - Collaborate with OT engineering teams to safely implement containment actions in live industrial environments. - Handle OT cyber incidents while minimizing operational disruption. - Work with industrial firewalls, IDS/IPS, NAC, and network segmentation technologies. Detection Engineering & Use Case Management - Develop and continuously tune OT-specific detection rules and correlation logic within SIEM platforms. - Align detection use cases with the MITRE ATT&CK for ICS framework. - Reduce false positives while improving detection accuracy, coverage, and operational effectiveness. - Periodically review and optimize alert thresholds and detection logic. - Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation technologies. - Assist with onboarding OT log sources, parser development, and data normalization. - Optimize dashboards, alerts, and reporting to improve OT security visibility. OT Network Visibility, Packet Analysis & Traffic Engineering - Operate and support packet brokers, network TAPs, SPAN infrastructure, and related technologies to enable comprehensive OT network visibility. - Perform deep packet inspection and traffic analysis across industrial protocols including Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP. - Analyze east-west and north-south traffic to identify suspicious activity, lateral movement, and unauthorized communications. - Identify protocol anomalies and deviations from established OT network behavior. - Support network telemetry collection and traffic visibility across industrial environments. Asset Visibility, Threat Hunting & Compliance - Maintain accurate OT asset inventories and network topology visibility. - Identify unauthorized devices, rogue connections, and shadow OT assets. - Conduct proactive threat hunting using security logs, network telemetry, behavioral analytics, and threat intelligence. - Correlate threat intelligence with OT vulnerabilities, assets, and operational risks. - Support OT risk assessments and initiatives to improve overall security posture. - Ensure compliance with IEC 62443, NIST ICS, ISO standards, and internal cybersecurity policies. - Support internal and external audits by preparing security evidence and compliance documentation. Reporting & Stakeholder Management - Prepare and present OT security reports covering incidents, vulnerabilities, risks, trends, and overall security posture. - Maintain dashboards covering threats, vulnerabilities, assets, compliance, and remediation status. - Communicate critical incidents, security risks, and recommended actions to SOC, OT engineering, and business stakeholders. - Provide executive-level reporting on OT security exposure, threat posture, and remediation progress. - Track remediation activities, SLAs, and outstanding security risks. - Support audit, regulatory, and compliance reporting requirements. Requirements Requirements - 8+ years of experience in cybersecurity, SOC operations, OT security, ICS security, or information security. - Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field. Mandatory Certification – Any One: - GIAC Global Industrial Cyber Security Professional (GICSP) - ISA/IEC 62443 Cybersecurity Certificate - GIAC Response and Industrial Defense (GRID) - ISA Certified Automation Cybersecurity Specialist (IACS) Required OT/ICS Technical Skills - Strong hands-on experience with OT/ICS environments, including SCADA, DCS, PLC, and industrial control systems. - Strong understanding of OT network architecture, Purdue Model, OT DMZ, network segmentation, and secure zones/conduits. - Practical experience with micro-segmentation and Zero Trust principles for OT environments. - Hands-on experience with Nozomi and/or Forescout OT security platforms. - Experience with SIEM platforms such as Microsoft Sentinel and OT security monitoring technologies. - Strong knowledge of packet analysis, Deep Packet Inspection (DPI), packet brokers, TAP, SPAN, and network telemetry. - Experience analyzing industrial protocols such as Modbus, DNP3, OPC-UA, IEC 104, and Ethernet/IP. - Strong understanding of OT threat detection, anomaly detection, threat hunting, and incident response. - Experience with industrial firewalling, IDS/IPS, NAC, segmentation, and secure remote access. - Knowledge of OT vulnerability management, asset discovery, asset inventory, and network visibility. - Ability to develop and tune SIEM detection rules and OT-specific security use cases. - Strong knowledge of MITRE ATT&CK for ICS, IEC 62443, and NIST ICS security principles. - Experience supporting security architecture involving SIEM, IDS/IPS, packet brokers, and OT segmentation technologies. - Strong analytical, incident investigation, reporting, documentation, and stakeholder management skills. Preferred Experience - Experience working within critical infrastructure, energy, utilities, oil & gas, manufacturing, or other industrial environments. - Experience operating security controls within high-availability OT environments where operational continuity is critical. - Experience with OT security architecture, risk assessments, security audits, and regulatory compliance. Benefits - Competitive Salary + Benefits Package

Frequently Asked Questions

Is the salary disclosed for the Senior SOC Engineer – OT Security position at black-grey?
The salary for this Senior SOC Engineer – OT Security role at black-grey is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Senior SOC Engineer – OT Security position at black-grey located?
This Senior SOC Engineer – OT Security role at black-grey is based in Doha, Ad Dawhah, Qatar. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Senior SOC Engineer – OT Security role at black-grey full-time or part-time?
This is listed as a Full time position. It is posted as a Senior SOC Engineer – OT Security role at black-grey.
How do I apply for the Senior SOC Engineer – OT Security position at black-grey?
Click the "Apply Now" button on this page. You will be redirected to black-grey's official application portal hosted on zohorecruit where you can submit your application directly.
When was the Senior SOC Engineer – OT Security job at black-grey posted?
This Senior SOC Engineer – OT Security position at black-grey was posted on Sep 14, 2026. Apply as soon as possible — early applications are often reviewed first.
Senior SOC Engineer – OT Security
black-grey
Apply for this role ↗

You'll be redirected to black-grey's official application page on zohorecruit.