Operational Technology (OT) Incident Response Consultant
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 5d ago
The date the source published, not the day we noticed it (2026-10-05). Last seen at its source 3h ago.
We have tracked this listing since 5 Oct 2026 (5 days). The employer's own board has carried it every time we have read it, most recently 3 hours ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Romania
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $96.2k–195.2k/yr
Middle 50% of 11 listings that do state pay — Consulting · all levels · Eastern Europe · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
Lever employer's own board first seen 5d ago · last seen 3h ago
The listing
Role Summary
As an Operational Technology (OT) Incident Response Consultant, you will play a critical role in protecting industrial environments from evolving cyber threats. You will lead the investigation and response to security incidents affecting industrial control systems (ICS) and OT networks, working closely with customers to identify threats, reduce risk, and improve operational resilience.
This role combines incident response, threat hunting, security monitoring, detection engineering, and advisory capabilities. You will serve as a trusted technical expert, helping organizations maintain the safety, reliability, and security of their operational environments while continuously enhancing their cyber defense posture.
What You Will Do
-
- Incident Response & Threat Investigation
- Investigate and response of high-severity OT security incidents.
- Perform root cause analysis to determine threat origin, attack scope, and affected assets.
- Conduct threat analysis across industrial environments.
- Analyze network traffic, system logs, and security events to identify malicious activity and attack patterns.
- Research emerging threat actors, attack campaigns, and OT-specific tactics, techniques, and procedures (TTPs).
-
- Detection Engineering & Security Monitoring
- Develop and enhance OT-specific detection use cases and threat detection procedures.
- Tune and optimize alerts generated by OT security controls to improve detection accuracy and reduce noise.
- Correlate information from security platforms, threat intelligence feeds, network telemetry, and other data sources.
- Support the implementation and continuous improvement of SIEM monitoring strategies, escalation workflows, and alerting mechanisms.
-
- OT Security Consulting & Advisory
- Serve as a Subject Matter Expert (SME) during OT cybersecurity incidents and security engagements.
- Provide technical recommendations for remediation, mitigation, and risk reduction.
- Support customers in strengthening their OT cyber security programs, processes, and operational procedures.
- Assist with the design and implementation of proactive OT security controls and monitoring capabilities.
- Contribute to the development of new security capabilities, tools, and automation initiatives.
- Stay current with OT security trends, vulnerabilities, defensive technologies, and industry best practices.
What You Will Bring
Technical Experience
- Experience working in cybersecurity, incident response, security operations or threat detection environments.
- Desirable to have a minimum 2 years of experience supporting industrial control systems such as PLCs, RTUs, DCS, SIS, SCADA, HMI, MES, or Historians.
- Understanding of OT and ICS architectures and operational environments.
- Experience investigating security incidents and performing root cause analysis.
- Hands-on experience with SIEM technologies, event monitoring, detection use cases, alert tuning, escalation workflows, and threat intelligence.
- Experience analyzing firewall logs, IDS/IPS events, system logs, network telemetry, and security events.
- Solid understanding of network protocols including TCP/IP and UDP.
- Familiarity with industrial communication protocols such as Modbus, DNP3 and other specific ICS protocols.
- Understanding of the Purdue Enterprise Reference Architecture model.
- Ability to conduct network traffic analysis and identify indicators of compromise in OT environments.
- Understanding of cyber threat actor tactics, techniques, and procedures (TTPs).
- Experience with vulnerability analysis, threat research, and security investigations.
- Ability to communicate in English.
Working Schedule
- Willingness to participate in shift work including nights, weekends and holidays (our MDR service is 24x7x365).