OT Security Consultant (Nozomi)

Houston, TX, US • Posted 1 day ago • Updated 1 day ago
Contract Independent
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Nozomi Networks Guardian and/or Vantage
  • Splunk or another SIEM platform
  • MITRE ATT&CK for ICS
  • IEC 62443
  • Industrial protocols including Modbus
  • DNP3
  • IEC 61850
  • OPC
  • and EtherNet/IP
  • Passive network monitoring
  • SPAN
  • and TAP technologies
  • OT asset inventory and network visibility tools

Summary

Position Overview:

 embedded Operational Technology (OT) Security Consultant to lead Nozomi Networks monitoring and detection improvements for a customer Security Operations Center (SOC). This hands-on role combines production SOC experience, industrial network knowledge, and deep administration and tuning expertise with Nozomi Networks. The consultant will assess existing use cases, improve alert quality and visibility, coach analysts through each change, and create durable runbooks and tuning records that strengthen the team’s long-term capabilities.

Business hours align to US Central time, with no on-call or 24x7 monitoring duties. Remote, hybrid, or on-site presence will be confirmed with the customer. Daily participation in stand-ups and shared team channels is expected.

4x a week onsite

Responsibilities:

  • Catalogue and assess existing Nozomi alerts, policies, and use cases against an agreed baseline such as MITRE ATT&CK for ICS, applicable regulatory monitoring obligations, IEC 62443, and vendor reference content.
  • Co-author a prioritized roadmap with the Splunk lead during the initial phase of the engagement.
  • Recommend and implement approved refinements to alert rules, thresholds, asset groupings, learning profiles, and zone and conduit definitions to reduce noise and false positives.
  • Design new Nozomi detections, custom checks, and queries that address coverage gaps for OT-specific threats and protocols.
  • Review sensor coverage, asset inventory accuracy, and passive discovery results, and recommend configuration improvements that strengthen detection quality.
  • Partner with the Splunk lead to improve how Nozomi alerts and asset data flow into the security information and event management platform, including field mapping, enrichment, and correlation.
  • Coach SOC analysts using real alerts and investigations, and capture lessons learned in detections and runbooks.
  • Create a runbook and tuning rationale for each new or materially changed use case.
  • Provide monthly reporting on changes, rationale, alert volume, false positive rate, and coverage improvement.
  • Coordinate with customer teams, implementation partners, and change control stakeholders so improvements are delivered smoothly. Qualifications:

Required Qualifications

  • Significant cybersecurity experience, including hands-on SOC work involving triage, investigation, and detection tuning in a production environment; approximately five or more years of overall experience is preferred.
  • Experience working in OT or Industrial Control System (ICS) environments such as utilities, energy, water, or manufacturing.
  • Proven hands-on administration and tuning experience with Nozomi Networks Guardian and/or Vantage beyond training or demonstration environments.
  • Solid understanding of industrial protocols such as Modbus, DNP3, IEC 61850, OPC, and EtherNet/IP, along with Purdue model network architecture.
  • Working knowledge of MITRE ATT&CK for ICS and the ability to map detections to the framework.
  • Strong written and verbal communication skills, with experience coaching analysts and creating clear technical documentation. 

Preferred Qualifications

  • Experience supporting an electric utility or other critical infrastructure environment, including familiarity with applicable regulatory requirements.
  • Working knowledge of IEC 62443.
  • Experience integrating Nozomi Networks with Splunk or another security information and event management platform.
  • Experience with passive network monitoring design, SPAN and TAP strategy, and OT asset inventory.
  • Prior consulting or embedded advisory experience. 

Certifications

  • Nozomi Networks certification is valued. GICSP, GRID, GCIA, GCIH, CISSP, or equivalent certifications are also helpful. Certifications support, but do not replace, hands-on SOC and OT experience. 

Tools and Technologies:

  • Nozomi Networks Guardian and/or Vantage
  • Splunk or another SIEM platform
  • MITRE ATT&CK for ICS
  • IEC 62443
  • Industrial protocols including Modbus, DNP3, IEC 61850, OPC, and EtherNet/IP
  • Passive network monitoring, SPAN, and TAP technologies
  • OT asset inventory and network visibility tools
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097117
  • Position Id: 5485
  • Posted 1 day ago

Company Info

About Cloud Destinations LLC

One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.

Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.

At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

About_Company_One
Contact the job poster
AU

Akash Unnikrishnan

Recruiter @ Cloud Destinations LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs