Back to Jobs
Security Analyst (OT SOC)
Actively Reviewing
Gruve
Job Description
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position Summary
We are seeking a skilled Security Analyst (OT SOC) to join our OT Security Operations Center. The ideal candidate will have 3 - 6 years of experience in OT/ICS cybersecurity monitoring and incident investigation, with hands-on exposure to industrial environments such as ICS, SCADA, PLC, RTU, and HMI ecosystems. The analyst will act as the primary escalation point from L1, perform advanced monitoring and triage, support Nozomi and SIEM operations, assist integrations and deployments, and deliver high-quality customer support and reporting while safeguarding safety-critical industrial operations.
Key Roles & Responsibilities
Validate suspicious activities, correlate security events, monitor industrial communications, and track abnormal asset behavior in ICS/SCADA environments.
Escalate confirmed incidents with complete evidence, business impact, and recommended next actions.
Perform packet analysis using Wireshark, validate indicators of compromise, identify lateral movement, and support containment and recovery activities under defined runbooks.
3.SIEM, Nozomi, and Detection Administration
Support SIEM administration activities including log source validation, parser verification, dashboard usage, alert tuning, and false-positive reduction.
Assist in the administration and health monitoring of OT security monitoring platforms such as Nozomi Guardian and related collectors/sensors.
Contribute to the creation and maintenance of detection rules and OT use cases aligned to industrial threats and operational realities.
Support integration of OT monitoring platforms with SIEM, SOAR, ticketing systems, and reporting workflows.
Demonstrate working knowledge of industrial protocols including Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related industrial Ethernet communications.
Support OT asset inventory validation, communication baseline analysis, and visibility improvement activities.
Communicate effectively with customers, internal stakeholders, and project teams while maintaining SLA commitments.
Maintain accurate incident records, SOPs, runbooks, troubleshooting notes, and knowledge-base documentation.
Escalate complex OT incidents, persistent integration issues, and monitoring gaps to the appropriate engineering or management teams.
Operate with awareness of plant safety, production availability, maintenance windows, and the sensitivity of safety-critical environments.
Stay updated on OT cyber threats, industrial attack techniques, and evolving defensive controls relevant to manufacturing, utilities, energy, and other industrial sectors.
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position Summary
We are seeking a skilled Security Analyst (OT SOC) to join our OT Security Operations Center. The ideal candidate will have 3 - 6 years of experience in OT/ICS cybersecurity monitoring and incident investigation, with hands-on exposure to industrial environments such as ICS, SCADA, PLC, RTU, and HMI ecosystems. The analyst will act as the primary escalation point from L1, perform advanced monitoring and triage, support Nozomi and SIEM operations, assist integrations and deployments, and deliver high-quality customer support and reporting while safeguarding safety-critical industrial operations.
Key Roles & Responsibilities
- Security Monitoring and Incident Triage
Validate suspicious activities, correlate security events, monitor industrial communications, and track abnormal asset behavior in ICS/SCADA environments.
Escalate confirmed incidents with complete evidence, business impact, and recommended next actions.
- Incident Investigation and Analysis
Perform packet analysis using Wireshark, validate indicators of compromise, identify lateral movement, and support containment and recovery activities under defined runbooks.
3.SIEM, Nozomi, and Detection Administration
Support SIEM administration activities including log source validation, parser verification, dashboard usage, alert tuning, and false-positive reduction.
Assist in the administration and health monitoring of OT security monitoring platforms such as Nozomi Guardian and related collectors/sensors.
Contribute to the creation and maintenance of detection rules and OT use cases aligned to industrial threats and operational realities.
- Deployment and Integration Support
Support integration of OT monitoring platforms with SIEM, SOAR, ticketing systems, and reporting workflows.
- OT Log, Asset, and Protocol Analysis
Demonstrate working knowledge of industrial protocols including Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related industrial Ethernet communications.
Support OT asset inventory validation, communication baseline analysis, and visibility improvement activities.
- Customer Support and Troubleshooting
Communicate effectively with customers, internal stakeholders, and project teams while maintaining SLA commitments.
- Reporting and Documentation
Maintain accurate incident records, SOPs, runbooks, troubleshooting notes, and knowledge-base documentation.
- Collaboration and Escalation
Escalate complex OT incidents, persistent integration issues, and monitoring gaps to the appropriate engineering or management teams.
- Compliance and Best Practices
Operate with awareness of plant safety, production availability, maintenance windows, and the sensitivity of safety-critical environments.
- Continuous Improvement
Stay updated on OT cyber threats, industrial attack techniques, and evolving defensive controls relevant to manufacturing, utilities, energy, and other industrial sectors.
- Report deviations and concerns to the SOC Manager
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Electronics, Instrumentation, or a related field.
- 3–6 years of experience in cybersecurity operations, OT SOC, ICS/SCADA monitoring, incident investigation, or industrial network security.
- Hands-on exposure to SIEM platforms such as Splunk, QRadar, Sentinel, FortiSIEM, or Elastic, and familiarity with Nozomi Guardian or similar OT monitoring tools.
- Working knowledge of OT/ICS environments including ICS, SCADA, PLC, RTU, HMI, historians, industrial switches, and engineering workstations.
- Understanding of industrial protocols such as Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related traffic analysis concepts.
- Experience with Wireshark, Syslog, Linux, Windows, Excel, and PowerShell for troubleshooting, analysis, and reporting.
- Strong analytical thinking, documentation discipline, customer interaction skills, time management, and team collaboration.
- Ability to work in rotational shifts, manage ticket queues, and operate effectively in high-availability industrial environments.
- Certifications such as Security+, Microsoft SC-200, Splunk Power User, QRadar Analyst, Nozomi Fundamentals, GICSP (foundation level exposure), or equivalent.
- Exposure to SOAR workflows, API-based integrations, threat intelligence enrichment, and OT vulnerability management processes.
- Knowledge of Purdue Model, network segmentation, jump hosts, remote access controls, firewall policy validation, and OT asset inventory concepts.
- Experience supporting industrial customers in sectors such as manufacturing, energy, utilities, oil and gas, pharma, or critical infrastructure.
- Strong interest in building deeper expertise across OT detection engineering, incident response, industrial protocols, and customer-facing delivery.
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Required Skills
Similar Jobs
View all →
Staff DevOps Engineer I
Blue Yonder
Hyderabad
Machine Learning
REST API
Red Hat
+18
Sr. Cloud Engineer
Automation Anywhere
Bengaluru
Adobe Illustrator
Root Cause Analysis
Python
+13
Software Engineer- MES II IND
First Solar
Tamil Nadu
Entity Framework
Machine Learning
PLC Programming
+24
Development Operations Engineer (Azure)
RWS Group
Indore
Release management
Adobe Illustrator
Root Cause Analysis
+9
Software Engineer- MES I IND
First Solar
Tamil Nadu
Entity Framework
Machine Learning
PLC Programming
+23
Share
Quick Apply
Upload your resume to apply for this position
–