Remote job
Senior OT Security Analyst
Job details
About this role
Role overview A senior frontline role on an OT Watch Complete team that monitors operational technology environments for industrial customers, identifying potential adversary activity in critical infrastructure systems. The position combines hands-on investigation, mentorship of junior analysts, and cross-functional collaboration with threat hunters, incident responders, platform engineers, and detection engineers. It is a remote-first opportunity suited to cybersecurity professionals passionate about defending ICS/OT environments.
Responsibilities - Lead shift operations, guiding analysts through triage of detection alerts and network telemetry across customer OT environments and stepping in as regional shift leader when needed. - Investigate suspicious activity to identify misconfigurations, anomalies, and potential malicious behavior across industrial networks. - Escalate findings to incident responders and threat hunters with clear, actionable documentation. - Partner across teams to tune detection logic, reduce false positives, and shape new platform detections and playbooks. - Produce incident summaries and operational reports for internal stakeholders and customers. - Support asset classification, vulnerability management, hardening recommendations, and direct customer information requests. - Build continuous expertise in ICS/OT protocols, adversary tradecraft, and industrial threat intelligence.
Requirements - 3–5 years of experience in network security, with hands-on exposure to real-world threat investigation. - Solid understanding of core networking concepts including TCP/IP, firewalls, DNS, and packet analysis. - Hands-on experience with security monitoring tools such as IDS/IPS, SIEM platforms, or network traffic analyzers. - Strong written and verbal communication skills with close attention to detail, including translating technical findings for customers. - Genuine interest in ICS/OT cybersecurity and the ability to learn industrial-specific concepts quickly. - Comfort working independently in a remote environment while coordinating across distributed teams. - Flexibility for shift-based coverage and occasional weekend or on-call work; initial Monday–Friday 8am–5pm schedule with on-call weekends, later shifting to a 4-day, 10-hour shift model (Sunday–Wednesday or Wednesday–Saturday).
Nice to have - Prior SOC experience. - Familiarity with OT protocols such as Modbus, DNP3, and Ethernet/IP, plus ICS environments. - Applied knowledge of adversary tactics and frameworks relevant to OT, including MITRE ATT&CK for ICS. - Hands-on lab or internship experience in cybersecurity operations, threat hunting, or digital forensics. - Experience with PCAP analysis or basic scripting in Python or Bash.
Benefits and work setup - Base salary of $110,000 plus a competitive equity package and comprehensive benefits plan. - Remote-first team across North America, Europe, the Middle East, and APAC. - Shift-based schedule with structured on-call rotations as described above.