About this OT Security Engineer L3 role at Gruve
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position summary:
We are seeking an experienced OT Security Engineer L3 to lead the design, deployment, integration, support, and optimization of OT security monitoring solutions across ICS, SCADA, DCS, and IIoT environments. The ideal candidate will bring 6–10 years of experience in OT cybersecurity and industrial network defense, act as the highest technical escalation point within the OT SOC, and drive implementation, threat hunting, incident response, detection engineering, customer engagement, and continuous improvement for complex industrial environments.
Key Roles & Responsibilities:
1. OT Security Architecture, Deployment, and Implementation
Lead the deployment and configuration of OT monitoring solutions including Nozomi Guardian and related collectors, sensors, packet brokers, TAPs, SPAN ports, and syslog infrastructure.
Design OT monitoring architecture for industrial environments covering asset visibility, protocol decoding, segmentation-aware telemetry collection, and secure integration patterns.
Install and configure SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security for OT use cases.
2. Integration and Automation
Integrate OT monitoring technologies with SIEM, SOAR, EDR, threat intelligence platforms, CMDBs, ticketing systems, and reporting solutions.
Configure Syslog, REST APIs, STIX/TAXII feeds, automation workflows, and custom integrations for OT firewalls, switches, historians, HMIs, PLCs, and engineering workstations.
3. Incident Response and Technical Escalation
Lead the investigation of high-severity OT security incidents and act as the final escalation point for complex issues raised by L1 and L2 analysts.
Coordinate containment, eradication, recovery, root-cause analysis, and technical communication with customer incident response teams and internal stakeholders.
4. Threat Hunting and Detection Engineering
Perform proactive threat hunting across OT and converged OT/IT environments to identify abnormal asset behavior, unsafe protocol usage, lateral movement, persistence mechanisms, and industrial attack techniques.
Develop and optimize detection rules, dashboards, correlation logic, and OT-specific use cases to improve fidelity and reduce false positives.
5. Security Monitoring, Packet Analysis, and Forensics
Review OT alerts and correlate them with enterprise SIEM telemetry, asset context, and industrial communication patterns.
Perform advanced packet analysis using Wireshark, support forensic triage, validate malware indicators, and guide evidence collection for OT investigations.
6. Customer Engagement and Technical Leadership
Lead onsite and remote implementation activities, conduct customer workshops, deliver technical presentations, and provide expert troubleshooting during upgrades, migrations, and health checks.
Serve as the senior technical SME for OT SOC operations and provide strategic guidance during architecture reviews, escalations, and service improvement planning.
7. Engineering, Optimization, and Playbooks
Create custom parsers, integrations, playbooks, SOPs, and knowledge artifacts that improve OT visibility, response consistency, and service quality.
Optimize detection logic, data onboarding, alert tuning, and reporting workflows to improve MTTR, response quality, and customer outcomes.
8. OT Domain, Protocol, and Asset Expertise
Apply deep working knowledge of OT/ICS components including ICS, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial Ethernet, and IIoT-connected assets.
Demonstrate strong command of industrial protocols such as Modbus, DNP3, IEC 60870-5-104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.
9. Reporting and Documentation
Produce executive dashboards, weekly and monthly SOC reports, compliance reporting, threat intelligence summaries, deployment status updates, and detailed root-cause analyses.
Maintain high-quality technical documentation for deployments, incidents, integrations, customer environments, and engineering changes.
10. Compliance, Risk, and Assessments
Support OT cybersecurity assessments, vulnerability management activities, and control validation aligned to standards such as ISA/IEC 62443, NIST CSF, and customer-specific governance requirements.
Ensure delivery quality, SLA adherence, audit readiness, and operational alignment with plant safety and production constraints.
11. Mentoring and Knowledge Transfer
Mentor L1 and L2 analysts, guide implementation engineers, review technical deliverables, and conduct knowledge transfer sessions for customers and internal teams.
Drive continuous learning around OT attack techniques, threat intelligence, use-case maturity, and industrial cybersecurity best practices.
12. Report deviations and concerns to the SOC Manager
Basic Qualifications:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, Electronics, Instrumentation, Industrial Automation, or a related field.
- 6–10 years of experience in OT cybersecurity, ICS/SCADA security monitoring, industrial network engineering, SOC operations, or related security engineering roles.
- Hands-on expertise with OT monitoring and SIEM platforms such as Nozomi Guardian, Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security.
- Strong understanding of ICS, SCADA, DCS, PLC, RTU, HMI, historians, engineering workstations, industrial switches, and asset visibility concepts.
- Deep knowledge of industrial protocols including Modbus, DNP3, IEC 60870-5-104, IEC 61850, OPC UA, EtherNet/IP, PROFINET, BACnet, and MQTT.
- Strong OT/industrial networking fundamentals covering TCP/IP, VLANs, routing, switching, firewall policies, VPNs, IDS/IPS, packet capture, and secure remote access.
- Experience with Wireshark, Nmap, PowerShell, Linux, Windows Server, REST APIs, troubleshooting, deployment documentation, and RCA preparation.
- Excellent customer communication, presentation, technical leadership, problem-solving, and mentoring skills.
Preferred Qualifications:
- Certifications such as GICSP, ISA/IEC 62443 Cybersecurity Expert, CISSP, CEH, CompTIA Security+, Nozomi Certified Engineer, Microsoft SC-200, Splunk Certified Consultant, or equivalent.
- Experience designing OT visibility architectures, deploying collectors/sensors, validating TAP/SPAN strategies, and integrating packet, log, and asset telemetry.
- Exposure to threat intelligence platforms, SOAR orchestration, CMDB/ticketing integrations, custom parser development, and OT-specific detection engineering.
- Working knowledge of Purdue Model, zones and conduits, industrial segmentation, change management in plant environments, and maintenance-window-aware deployment practices.
- Experience supporting industrial sectors such as manufacturing, energy, utilities, pharma, chemicals, transportation, or other critical infrastructure domains.
Why Gruve
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.