Job description
Role: OT Incident Response
Location: Riyadh, Saudi Arabia
Role Summary
The OT SOC L3 Analyst is the senior technical authority within the OT SOC, responsible for advanced threat hunting, OT aware digital forensics and incident response (DFIR), detection engineering, and mentoring of L1/L2 analysts. The role leads the response to complex and high-severity OT incidents, develops the SOC's OT detection capability, and serves as the escalation point and subject matter expert for industrial threat scenarios. The analyst translates OT threat intelligence into actionable detections and drives continuous improvement of the SOC's OT defenses.
Responsibilities
- Lead investigation and response for complex, high severity and suspected targeted attacks against OT/ICS environments.
- Perform proactive, hypothesis-driven threat hunting across OT networks and assets; design and run hunt campaigns.
- Conduct OT aware DFIR forensic acquisition and analysis of ICS hosts, engineering workstations, HMIs, controllers and network captures using methods that preserve process safety and evidence integrity.
- Design, build and tune detection content and correlation rules; own the detection engineering lifecycle for the OT SOC.
- Operationalize OT threat intelligence (e.g., threat groups such as ELECTRUM/Sandworm and XENOTIME; malware such as TRITON/TRISIS, Industroyer and PIPEDREAM) and map it to detections via MITRE ATT&CK for ICS.
- Define, document and continuously improve OT incident-response playbooks and runbooks.
- Serve as senior escalation point and mentor for L1/L2 analysts; provide technical coaching and quality review of investigations.
- Lead and support OT tabletop exercises and purple team / adversary-emulation activities.
- Advise on OT network architecture, segmentation and monitoring placement to close detection gaps.
- Produce executive and technical incident reports; brief stakeholders on root cause, impact and remediation.
- Support compliance, audit and regulatory reporting aligned to NCA OTCC-1:2022, ECC and ISA/IEC 62443, including incident-notification expectations to the NCA.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma
وصف الوظيفة
الدوار: OT Incident Response
الموقع: الرياض، المملكة العربية السعودية
ملخص الدور
المحلل من المستوى الثالث في OT SOC هو السلطة الفنية العليا داخل OT SOC، المسؤول عن الصيد المتقدم للتهديدات، وتحليل الأدلة الرقمية الواعية بالـ OT والاستجابة للحوادث (DFIR)، وهندسة الكشف، وتوجيه المحللين من المستويين L1/L2. يقود الدور الاستجابة للحوادث المعقدة والمرتفعة الشدة في OT، ويطور قدرة كشف الـ OT ضمن SOC، ويعمل كنقطة تصعيد وخبير موضوعي لسيناريوهات التهديد الصناعي. يقوم المحلل بترجمة معلومات تهديد OT إلى اكتشافات قابلة للتنفيذ ويدفع نحو تحسين مستمر للدفاعات الخاصة بـ OT في SOC.
المسؤوليات
- قيادة التحقيق والاستجابة للهجمات المعقدة والمرتفعة الشدة والمشتبه فيها والتي تستهدف بيئات OT/ICS.
- إجراء صيد تهديدي استباقي يقوده فرضية عبر شبكات OT والأصول؛ تصميم وتنفيذ حملات صيد.
- إجراء جمع وتحليل DFIR لادلة OT الواعية وموارد ICS، محطات الهندسة، واجهات HMI، المتحكمات والتقاطات الشبكة باستخدام طرق تحافظ على سلامة السلامة العملية وأصل الأدلة.
- تصميم وبناء وضبط محتوى الكشف وقواعد الترابط؛ امتلاك دورة حياة هندسة الكشف لـ OT SOC.
- تشغيل معلومات تهديد OT (مثلاً مجموعات التهديد مثل ELECTRUM/Sandworm وXENOTIME؛ البرمجيات الخبيثة مثل TRITON/TRISIS، Industroyer وPIPEDREAM) وربطها بالكشف عبر MITRE ATT&CK لـ ICS.
- تحديد وتوثيق وتحسين مستمر لـ playbooks وrunbooks لاستجابة حوادث OT.
- العمل كنقطة تصعيد عليا ومرشد للمحللين L1/L2؛ تقديم التوجيه الفني ومراجعة جودة التحقيقات.
- قيادة ودعم تمارين الطاولة OT وأنشطة الفريق البنفسجي / تقليد العدو.
- تقديم المشورة حول هندسة الشبكات OT وتقسيمها ومواقع المراقبة لسد ثغرات الكشف.
- إنتاج تقارير الحوادث التنفيذية والتقنية؛ إعلام أصحاب المصالح بجذر المشكلة والتأثير والتصحيح.
- دعم الامتثال والتدقيق والتقارير التنظيمية وفق NCA OTCC-1:2022 وECC وISA/IEC 62443، بما في ذلك توقعات الإخطار بالحوادث إلى NCA.
مرشح مفضل
سنوات الخبرة
لا يوجد خبرة مطلوبة
الدرجة
درجة البكالوريوس / دبلوم عالي