Jobedly Post a Job

OT SOC Analyst L2

Gruve · Pune
Full-timeManaged ServicesTechnology$136,000–$184,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the OT Soc Analyst L role

OT Soc Analyst L positions focus on delivering results in their domain. This page aggregates open OT Soc Analyst L roles and what employers typically expect.

About Gruve Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks. Position summary: We are seeking a skilled OT SOC Analyst L2 to join our OT Security Operations Center. The ideal candidate will have 3 - 6 years of experience in OT/ICS cybersecurity monitoring and incident investigation, with hands-on exposure to industrial environments such as ICS, SCADA, PLC, RTU, and HMI ecosystems. The analyst will act as the primary escalation point from L1, perform advanced monitoring and triage, support Nozomi and SIEM operations, assist integrations and deployments, and deliver high-quality customer support and reporting while safeguarding safety-critical industrial operations. Key Roles & Responsibilities: 1. Security Monitoring and Incident Triage Monitor OT and IT security alerts across SIEM and OT visibility platforms such as Splunk, QRadar, Sentinel, FortiSIEM, Elastic, and Nozomi Guardian. Validate suspicious activities, correlate security events, monitor industrial communications, and track abnormal asset behavior in ICS/SCADA environments. Escalate confirmed incidents with complete evidence, business impact, and recommended next actions. 2. Incident Investigation and Analysis Investigate OT security alerts, malware indicators, unauthorized changes, policy violations, and suspicious network behavior affecting PLCs, RTUs, HMIs, historians, and engineering workstations. Perform packet analysis using Wireshark, validate indicators of compromise, identify lateral movement, and support containment and recovery activities under defined runbooks. 3 . SIEM, Nozomi, and Detection Administration Support SIEM administration activities including log source validation, parser verification, dashboard usage, alert tuning, and false-positive reduction. Assist in the administration and health monitoring of OT security monitoring platforms such as Nozomi Guardian and related collectors/sensors. Contribute to the creation and maintenance of detection rules and OT use cases aligned to industrial threats and operational realities. 4. Deployment and Integration Support Assist OT solution deployments by validating sensor connectivity, syslog forwarding, collector health, API integrations, use-case testing, and user acceptance activities. Support integration of OT monitoring platforms with SIEM, SOAR, ticketing systems, and reporting workflows. 5. OT Log, Asset, and Protocol Analysis Review logs, alarms, and network telemetry from OT and IT sources to identify anomalies and confirm incident context. Demonstrate working knowledge of industrial protocols including Modbus, DNP3, OPC UA, IEC 60870-5-104, PROFINET, and related industrial Ethernet communications. Support OT asset inventory validation, communication baseline analysis, and visibility improvement activities. 6. Customer Support and Troubleshooting Provide remote troubleshooting, incident bridge support, health checks, upgrade support, and ticket resolution for customer OT security environments. Communicate effectively with customers, internal stakeholders, and project teams while maintaining SLA commitments. 7. Reporting and Documentation Prepare daily SOC reports, weekly incident summaries, asset visibility reports, security posture updates, and SLA-driven ticketing updates. Maintain accurate incident records, SOPs, runbooks, troubleshooting notes, and knowledge-base documentation. 8. Collaboration and Escalation Work closely with L1 analysts, L3 engineers, implementation teams, customer stakeholders, and cross-functional security teams to resolve operational issues. E…

Salary estimate

$136,000 – $184,000/yr
Provided by the employer.

Skills for this role

CommunicationSecurity

Resume tips for OT Soc Analyst L applicants

Interview preparation

Prepare concrete STAR-format stories that show OT Soc Analyst L outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical OT Soc Analyst L problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Gruve

Gruve is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles