Lead SOC Engineer OT Cybersecurity

G42 Group
Anywhere
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 8-10 yearsEducation: bachelorsSkills: ["Communication","Collaboration","Cross-domain collaboration","Operational awareness"]

Lead the design and engineering of advanced OT threat detection capabilities within a hybrid Security Operations Center. Build high-fidelity SIEM detections and correlation rules, engineer SOAR playbooks for automated investigation and response, and integrate OT telemetry from PLC logs, historians, and network sources. Partner with SOC analysts and IT/OT teams to validate detections, improve triage, and align strategies with NESA, SAMA, NIST 800-82, and IEC 62443.

This position is no longer accepting applications.

  • See live roles at G42 Group
  • Search all live jobs
  • Browse companies, collections, and locations hiring now
Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa

This position is no longer accepting applications.

See live roles at G42 GroupSearch all live jobsBrowse companies, collections, and locations hiring now

G42 Group
G42 Group
2 months ago

Lead SOC Engineer OT Cybersecurity

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Closed
Reposted: similar role first listed 5 months ago

Job Summary

Lead the design and engineering of advanced OT threat detection capabilities within a hybrid Security Operations Center. Build high-fidelity SIEM detections and correlation rules, engineer SOAR playbooks for automated investigation and response, and integrate OT telemetry from PLC logs, historians, and network sources. Partner with SOC analysts and IT/OT teams to validate detections, improve triage, and align strategies with NESA, SAMA, NIST 800-82, and IEC 62443.
Location: Anywhere
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Design, develop, and fine-tune OT-specific detection use cases, correlation rules, and analytics in SIEM platforms to enhance threat visibility and reduce false positives.
  • •Build, maintain, and optimize SOAR playbooks that automate OT and IT security investigation and response workflows.
  • •Create, refine, and document SOC alert logic to ensure high-fidelity detection and smooth handover to analysts for operations.
  • •Integrate and onboard OT telemetry sources (PLC logs, historian data, network telemetry, asset inventories) into SIEM/SOAR and broader SOC workflows.
  • •Partner with SOC analysts and IT/OT teams to validate detections, enhance triage processes, support incident investigations, and align response strategies with NESA, SAMA, NIST 800-82, and IEC 62443.

Key Requirements

  • •Minimum 8–10 years in SOC operations with significant OT cybersecurity experience, including prior lead engineering experience in a SOC or industrial cybersecurity environment.
  • •Proven ability to design and implement high-fidelity OT detection logic for ICS/SCADA environments, minimizing false positives and improving alert fidelity.
  • •Strong hands-on expertise in OT/ICS protocols including Modbus, DNP3, OPC, and IEC 61850, with knowledge of threat-relevant behavioral patterns.
  • •Extensive experience building and tuning SIEM use cases and correlation rules (e.g., QRadar, Splunk) plus telemetry onboarding into SOC workflows.
  • •Proficiency in Python and PowerShell to automate detection workflows and parse OT logs, along with relevant certifications such as CISSP/CISM and OT/ICS security credentials.
Experience:8-10 years
Education:Bachelor's in computer science, Information Technology, Cybersecurity, or related field
Skills:CommunicationCollaborationCross-domain collaborationOperational awareness
Certifications:CISSPCISMGICSPGRIDISA/IEC 62443 Cybersecurity CertificateDragosNozomiCCNPCCIE
Tech Stack:SIEMSOARQRadarSplunkDragosClarotyNozomiPythonPowerShellModbusDNP3OPCIEC 61850PLC logsHistorian dataNetwork telemetryAsset inventoriesOT telemetryICS/SCADA

Company Brief

G42 Group
G42 is an Abu Dhabi–based holding company building large-scale AI, cloud and data infrastructure and industry AI applications across healthcare, energy, governance, space and more, partnering with governments and global tech firms.
Industry: Conglomerates & Holding Companies
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Funding: Private Equity Backed
Headquarters: Abu Dhabi, United Arab Emirates
Founded: 2018
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor