OT Security Consultant (Splunk)

Hybrid in Houston, TX, US • Posted 3 hours ago • Updated 3 hours ago
Contract W2
12 Months
No Travel Required
Hybrid
$75 - $80/hr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • CISSP
  • Change Control
  • Communication
  • Dashboard
  • Cyber Security
  • Embedded Systems
  • GCIA
  • ICS
  • GCIH
  • SPL
  • Roadmaps
  • Extraction
  • Energy
  • Documentation
  • Splunk
  • Security Operations
  • Technical Writing
  • Use Cases
  • UPS
  • Network Design
  • Coaching
  • Orchestration
  • System On A Chip
  • Reporting

Summary

Operational Technology (OT) Cybersecurity Consultant to lead Splunk detection engineering for a customer Security Operations Center (SOC). This hands-on role requires production SOC experience, an understanding of how OT environments differ from traditional IT, and advanced Splunk expertise. The consultant will evaluate current use cases, improve correlation and alert quality, develop new detection content, coach analysts, and create clear documentation that enables the team to sustain the work independently.

Business hours align to US Central time, with no on-call or 24x7 monitoring duties. Remote, hybrid, or on-site presence will be confirmed with the customer. Daily participation in stand-ups and shared team channels is expected.

Note: This is a W2 only role — C2C, C2H will not be considered

Onsite 4x a week

Responsibilities:

  • Catalogue and assess existing Splunk correlation searches, dashboards, and use cases against an agreed baseline, identifying coverage gaps and noisy rules.
  • Co-author a prioritized roadmap with the Nozomi lead during the initial phase of the engagement.
  • Design, test, and refine Search Processing Language (SPL) correlation searches, notable event logic, and detection content tailored to OT data sources.
  • Recommend and implement approved adjustments to thresholds and suppression logic to reduce false positives, and track the impact of each change.
  • Review OT log sources, parsing, normalization, field extraction, and enrichment so detections are based on reliable data.
  • Partner with the Nozomi lead to normalize, enrich, and correlate Nozomi alerts and asset data in Splunk.
  • Coach SOC analysts using real investigations and teach effective pivots across OT and IT data.
  • Create a runbook and tuning rationale for each new or materially changed use case, and teach analysts to build and tune searches independently.
  • Provide monthly reporting on changes, rationale, alert volume, false positive rate, and coverage improvement.
  • Coordinate with customer teams, implementation partners, change control, and related Splunk workstreams so improvements are delivered smoothly. Qualifications:

Required Qualifications

  • Significant cybersecurity experience, including hands-on SOC work involving triage, investigation, and detection engineering in a production environment; approximately five or more years of overall experience is preferred.
  • Experience with OT or Industrial Control System (ICS) security monitoring, ideally in utilities, energy, or critical infrastructure.
  • Advanced hands-on Splunk skills, including SPL, correlation search development, and tuning in a production SOC environment.
  • Practical knowledge of detection engineering methods and MITRE ATT&CK, with working familiarity with ATT&CK for ICS.
  • Understanding of OT network architecture, industrial protocols, and the Purdue model.
  • Strong written and verbal communication skills, with experience coaching analysts and creating clear technical documentation. 

Preferred Qualifications

  • Experience supporting an electric utility or other critical infrastructure environment, including familiarity with applicable regulatory requirements.
  • Working knowledge of IEC 62443.
  • Experience integrating Nozomi Networks or another OT monitoring platform with Splunk.
  • Experience with risk-based alerting, security orchestration, automation and response, or detection-as-code practices.
  • Prior consulting or embedded advisory experience. 

Certifications

  • Splunk Core Certified Power User or Admin, Splunk Enterprise Security Certified Admin, GICSP, GCIA, GCDA, GCIH, CISSP, or equivalent certifications are helpful. Certifications support, but do not replace, hands-on SOC and OT experience. 

Tools and Technologies:

  • Splunk Enterprise and Splunk Enterprise Security
  • Search Processing Language (SPL)
  • Correlation searches and notable event workflows
  • Nozomi Networks or another OT monitoring platform
  • MITRE ATT&CK and ATT&CK for ICS
  • IEC 62443
  • OT log sources, parsing, normalization, field extraction, and enrichment
  • Risk-based alerting and security orchestration, automation and response technologies
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097117
  • Position Id: 9107599
  • Posted 3 hours ago

Company Info

About Cloud Destinations LLC

One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.

Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.

At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

About_Company_One
Contact the job poster
AA

Antony Arokiaraj

Recruiter @ Cloud Destinations LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs