Jobgether
Senior OT Security Analyst
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Senior
- Posted
- 29 September 2026 (yesterday)
Checked yesterdayApplications go to the employer, never to RoleSprint
About this role
Accountabilities: • Lead frontline shift operations , guiding analysts as they triage alerts and network telemetry across customer OT environments and stepping into regional shift-lead responsibilities when required.
• Conduct senior-level investigations into suspicious activity, identifying network anomalies, configuration issues, and potential malicious behavior within industrial environments.
• Analyze and escalate findings to incident responders and threat hunters with clear, detailed, and actionable documentation that supports effective investigation and response.
• Collaborate across cybersecurity teams , including analysts, threat hunters, incident responders, platform engineers, and Detection Engineering, to improve detection logic, reduce false positives, and develop new detections and playbooks.
• Prepare incident summaries and operational reports that clearly communicate security findings, trends, and environmental activity to internal stakeholders and customers.
• Support the broader OT security service , including asset classification, vulnerability management, hardening recommendations, customer information requests, and ongoing platform operations.
• Mentor and support junior analysts , sharing investigative techniques, operational knowledge, and best practices for OT security monitoring.
• Continuously develop industrial security expertise , staying current with ICS/OT protocols, adversary tradecraft, threat intelligence, and emerging techniques relevant to industrial environments.
Requirements:
• 3–5 years of experience in network security , ideally including hands-on experience investigating real-world threats and suspicious network activity.
• Strong understanding of core networking concepts , including TCP/IP, firewalls, DNS, and packet analysis.
• Hands-on experience with security monitoring technologies , such as IDS/IPS, SIEM platforms, network traffic analysis tools, or comparable security operations technologies.
• Strong written and verbal communication skills, with excellent attention to detail and the ability to translate technical findings for both cybersecurity professionals and customers.
• Genuine interest in ICS/OT cybersecurity and critical infrastructure protection , combined with the ability to quickly understand complex industrial environments.
• Ability to work independently in a remote environment while coordinating effectively with distributed, cross-functional teams.
• Willingness to participate in shift-based coverage, weekend, and on-call responsibilities as required.
• Initial schedule is Monday–Friday, 8:00 a.m.–5:00 p.m., with weekend on-call coverage. The schedule is expected to transition to a four-day, 10-hour shift model, with employees choosing either Sunday–Wednesday or Wednesday–Saturday .
• Experience working within a Security Operations Center (SOC) is preferred.
• Familiarity with OT/ICS protocols such as Modbus, DNP3, and EtherNet/IP is preferred.
• Applied knowledge of OT-relevant adversary tactics and frameworks, including MITRE ATT&CK for ICS , is a plus.
• Hands-on laboratory, internship, threat hunting, digital forensics, or cybersecurity operations experience is valued.
• Experience with PCAP analysis or basic scripting using Python, Bash, or similar tools is a plus.
Benefits:
• AUD 130,000 annual salary according to the source posting.
• Competitive equity package .
• Comprehensive benefits plan .
• Remote-first work environment.
• Opportunity to work directly on OT and industrial cybersecurity , protecting environments that support critical infrastructure.
• Exposure to threat detection, incident response, threat hunting, vulnerability management, and OT security operations.
• Collaboration with experienced cybersecurity professionals across distributed global teams.
• Opportunities to develop specialized expertise in ICS/OT protocols, industrial threat intelligence, and adversary tradecraft .
• Structured shift options following the transition to the four-day schedule, with either Sunday–Wednesday or Wednesday–Saturday coverage.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 29 September 2026, last checked yesterday. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.