Job Title: Senior SOC Engineer/Analyst
Location: Remote
Mode of Hire: Contract
Job Description:
Seeking a senior-level SOC/NOC Analyst / OT Security Engineer to support 24/7 security operations, alert triage, incident response, and SOC/NOC operational maturity within a hybrid IT/OT environment. The role requires hands-on experience with CrowdStrike, Nozomi, Fortinet, and critical infrastructure security.
Core Responsibilities
- Monitor, investigate, triage, and respond to security alerts across IT and OT environments.
- Perform advanced threat analysis, incident investigation, escalation, and documentation.
- Develop SOC/NOC runbooks, workflows, reporting, KPIs, and operational processes.
- Support SOC/NOC technology onboarding, integrations, and secure access management.
- Coordinate incident response activities across security, infrastructure, engineering, and OT teams.
- Create incident timelines, root-cause analysis, post-incident reviews, and knowledge base updates.
Required Technical Experience
- SOC/NOC Operations:5 12+ years of SOC/NOC experience (L3/L4 preferred) with incident response, threat hunting, and escalation management.
- CrowdStrike:Hands-on experience with Falcon SIEM, EDR, Vulnerability Management, detections, dashboards, integrations, and investigations.
OT Security (Required):
- Experience designing, deploying, and integrating OT security solutions (especially Nozomi Networks).
- Strong understanding of OT architectures, Purdue Model, ICS/SCADA environments, and industrial network security.
Network Security:
- Experience with Fortinet platforms (FortiGate, FortiAnalyzer, FortiManager).
- Knowledge of firewalls, IDS/IPS, segmentation, VPNs, and IT/OT network monitoring.
- Experience supporting hybrid enterprise environments with both traditional IT and industrial OT systems.
Preferred Background
- Critical infrastructure, utilities, manufacturing, energy, or industrial environments.
- Experience building or maturing SOC operations, onboarding security platforms, or supporting greenfield SOC/NOC implementations.
Relevant certifications:
- CrowdStrike CCFA / CCFH
- GICSP, GCIA, GCFA
- CISSP, CEH
- Fortinet NSE certifications
Ideal Candidate: Strong SOC/NOC Engineer with strong incident response capabilities plus hands-on OT security engineering experience, particularly Nozomi + CrowdStrike in industrial environments.
Core Duties
1. Onboarding & Access Management
Create user accounts, assign roles, and ensure secure access across SOC tools.
Validate OT and IT connectivity, including VPN, jump hosts, bastion access, and firewall pathways.
Confirm appropriate access controls for SOC analysts and engineering teams.
- Alert Understanding & Triage
Review, enrich, classify, and route alerts from CrowdStrike and OT monitoring systems.
Perform in-depth analysis on suspicious activities; create and manage cases/tickets.
Ensure triage accuracy, SLA compliance, and detailed documentation.
3. Incident Coordination & Response
Initiate incident bridges and manage real-time incident response.
Document timelines, maintain evidence logs, and drive resolution outcomes.
Work with IT, OT, Security Engineering, and third-party vendors as needed.
4. Escalation Management
Follow and improve the escalation matrix & severity model.
Notify appropriate on-call, SOC leadership, and vendor contacts.
Ensure transparent communication during major incidents.
5. Reporting & Documentation
Produce daily and weekly operational summaries, incident reports, and analytics.
Drive post-incident reviews (PIRs) and recommend process improvements.
Contribute to SOC playbook and procedural documentation.
Technical Environment:
CrowdStrike Falcon (SIEM, EDR, VM)
Nozomi Networks (OT monitoring, asset analysis, anomaly detection)
Fortinet / FortiGate Firewalls
Hybrid IT/OT enterprise network architecture
ICS/SCADA systems and industrial protocols