OT Security Consultant (Splunk)


Cloud Destinations LLC
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- CISSP
- Change Control
- Communication
- Dashboard
- Cyber Security
- Embedded Systems
- GCIA
- ICS
- GCIH
- SPL
- Roadmaps
- Extraction
- Energy
- Documentation
- Splunk
- Security Operations
- Technical Writing
- Use Cases
- UPS
- Network Design
- Coaching
- Orchestration
- System On A Chip
- Reporting
Summary
Operational Technology (OT) Cybersecurity Consultant to lead Splunk detection engineering for a customer Security Operations Center (SOC). This hands-on role requires production SOC experience, an understanding of how OT environments differ from traditional IT, and advanced Splunk expertise. The consultant will evaluate current use cases, improve correlation and alert quality, develop new detection content, coach analysts, and create clear documentation that enables the team to sustain the work independently.
Business hours align to US Central time, with no on-call or 24x7 monitoring duties. Remote, hybrid, or on-site presence will be confirmed with the customer. Daily participation in stand-ups and shared team channels is expected.
Onsite 4x a week
Responsibilities:
- Catalogue and assess existing Splunk correlation searches, dashboards, and use cases against an agreed baseline, identifying coverage gaps and noisy rules.
- Co-author a prioritized roadmap with the Nozomi lead during the initial phase of the engagement.
- Design, test, and refine Search Processing Language (SPL) correlation searches, notable event logic, and detection content tailored to OT data sources.
- Recommend and implement approved adjustments to thresholds and suppression logic to reduce false positives, and track the impact of each change.
- Review OT log sources, parsing, normalization, field extraction, and enrichment so detections are based on reliable data.
- Partner with the Nozomi lead to normalize, enrich, and correlate Nozomi alerts and asset data in Splunk.
- Coach SOC analysts using real investigations and teach effective pivots across OT and IT data.
- Create a runbook and tuning rationale for each new or materially changed use case, and teach analysts to build and tune searches independently.
- Provide monthly reporting on changes, rationale, alert volume, false positive rate, and coverage improvement.
- Coordinate with customer teams, implementation partners, change control, and related Splunk workstreams so improvements are delivered smoothly. Qualifications:
Required Qualifications
- Significant cybersecurity experience, including hands-on SOC work involving triage, investigation, and detection engineering in a production environment; approximately five or more years of overall experience is preferred.
- Experience with OT or Industrial Control System (ICS) security monitoring, ideally in utilities, energy, or critical infrastructure.
- Advanced hands-on Splunk skills, including SPL, correlation search development, and tuning in a production SOC environment.
- Practical knowledge of detection engineering methods and MITRE ATT&CK, with working familiarity with ATT&CK for ICS.
- Understanding of OT network architecture, industrial protocols, and the Purdue model.
- Strong written and verbal communication skills, with experience coaching analysts and creating clear technical documentation.
Preferred Qualifications
- Experience supporting an electric utility or other critical infrastructure environment, including familiarity with applicable regulatory requirements.
- Working knowledge of IEC 62443.
- Experience integrating Nozomi Networks or another OT monitoring platform with Splunk.
- Experience with risk-based alerting, security orchestration, automation and response, or detection-as-code practices.
- Prior consulting or embedded advisory experience.
Certifications
- Splunk Core Certified Power User or Admin, Splunk Enterprise Security Certified Admin, GICSP, GCIA, GCDA, GCIH, CISSP, or equivalent certifications are helpful. Certifications support, but do not replace, hands-on SOC and OT experience.
Tools and Technologies:
- Splunk Enterprise and Splunk Enterprise Security
- Search Processing Language (SPL)
- Correlation searches and notable event workflows
- Nozomi Networks or another OT monitoring platform
- MITRE ATT&CK and ATT&CK for ICS
- IEC 62443
- OT log sources, parsing, normalization, field extraction, and enrichment
- Risk-based alerting and security orchestration, automation and response technologies
- Dice Id: 91097117
- Position Id: 9107599
- Posted 3 hours ago
Company Info
One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.
Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.
At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs