Lead Incident Response – OT Cyber Security

G42 Group
Anywhere
Full timeFunction: CybersecurityExperience: 8+ yearsEducation: bachelorsSkills: ["Communication","Leadership","Problem-solving","Forensics","Technical writing"]

Lead IT and OT/ICS incident response engagements across energy, utilities, manufacturing, oil & gas and transport sectors. Conduct threat hunting and forensic investigations across IT/OT environments, analyze industrial protocols, and guide containment and recovery actions. Deliver technical reports and executive briefings, contribute to incident response playbooks, mentor junior staff, and drive continuous OT security improvements in cross-time-zone engagements.

This position is no longer accepting applications.

  • See live roles at G42 Group
  • Search all live jobs
  • Browse companies, collections, and locations hiring now
Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa

This position is no longer accepting applications.

See live roles at G42 GroupSearch all live jobsBrowse companies, collections, and locations hiring now

G42 Group
G42 Group
3 months ago

Lead Incident Response – OT Cyber Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Closed

Job Summary

Lead IT and OT/ICS incident response engagements across energy, utilities, manufacturing, oil & gas and transport sectors. Conduct threat hunting and forensic investigations across IT/OT environments, analyze industrial protocols, and guide containment and recovery actions. Deliver technical reports and executive briefings, contribute to incident response playbooks, mentor junior staff, and drive continuous OT security improvements in cross-time-zone engagements.
Location: Anywhere
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Act as the technical lead for IT and OT/ICS incident response engagements and support customers across industrial sectors.
  • •Independently execute assigned tasks after onboarding, showing accountability and technical ownership.
  • •Conduct proactive threat hunting across IT and OT/ICS environments, including SCADA servers, historians, HMIs, and engineering workstations.
  • •Perform host-based and network-based forensic investigations across OT and IT environments (Windows HMIs/EWS, Linux-based SCADA systems, enterprise endpoints).
  • •Lead and support digital forensic investigations, including evidence acquisition, artifact analysis, and timeline reconstruction.

Key Requirements

  • •GIAC Global Industrial Cyber Security Professional (GICSP) certification is required; GIAC Response and Industrial Defense (GRID) is highly desirable.
  • •CREST Registered Intrusion Analyst (CRIA) or equivalent is desirable.
  • •GIAC certification in at least one IT discipline (e.g., GCIH, GCFE, GCFA, GNFA, GCIA, GDAT, or equivalent) is preferred.
  • •Minimum 8 years of work experience in incident response or OT security.
  • •Bachelor’s degree in computer science or engineering is desirable but not mandatory.
Experience:8+ yearsOT cybersecurityIndustrial control systemsICSCybersecurityIT/OT
Education:Bachelor's
Skills:CommunicationLeadershipProblem-solvingForensicsTechnical writing
Certifications:GICSPGRIDCRIA
Languages:English
Tech Stack:MITRE ATT&CK for ICSWiresharkZeekSuricataRITAClarotyDragosNozomiTenable OTWindowsLinuxActive DirectorySIEMModbusDNP3IEC 61850EtherNet/IPOPC-UA/DAPROFINETBACnet

Company Brief

G42 Group
G42 is an Abu Dhabi–based holding company building large-scale AI, cloud and data infrastructure and industry AI applications across healthcare, energy, governance, space and more, partnering with governments and global tech firms.
Industry: Conglomerates & Holding Companies
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Funding: Private Equity Backed
Headquarters: Abu Dhabi, United Arab Emirates
Founded: 2018
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor