Investigate triaged events and incidents using SIEM technologies, Endpoint Detection and Response platforms, and various cybersecurity tools.
Analyze, escalate, and assist in remediation of critical OT security incidents.
Support Incident Response Plan through Tier one support of activities surrounding following the PICERL model; Preparation, Identification, Containment, Eradication, Recovery & Lessons Learned.
Assist in enforcing and auditing OT security policies and procedures such as access, breach escalation, use of firewalls and encryption routines.
Assist in updating, maintaining, and documenting security controls. Provides direction and support to clients and internal IT and OT groups for information security-related issues.
Assist in performing high-level analysis of complex and disparate computing systems, networks, and data architectures to identify, rectify, and prevent technical and OT security vulnerabilities.
Demonstrate high-level technical skills in the areas of OT security, networking and computer systems, and excellent capacity for grasping relevant details and complex systems analysis.
Perform other related duties as assigned by the supervisor.
Investigate security breaches and other cyber security incidents.
Work with security team to perform tests and uncover network vulnerabilities.
Fix detected vulnerabilities to maintain a high-security standard.
Stay current on IT and OT security trends and news.
Develop company-wide best practices for OT security.
Help colleagues install security software and understand information security management.
Research security enhancements and make recommendations to management.
Stay up-to-date on OT cybersecurity trends and security standards.
Manage security alerts; monitors health of security sensors and endpoints; collects data and context necessary to initiate work.
Maintain and support OT sensors/ network experience.