Senior Lead OT Network Security Analyst
Spartanburg, SC - USA
Job Summary
Senior / Lead OT Network Security Analyst
Location: Spartanburg County SC
Type: Direct Hire
The Position
Our client is seeking a Senior / Lead OT Network Security Analyst to strengthen the security and visibility of mission-critical operational technology environments. This role will focus heavily on Nozomi Networks technologies including Guardian Vantage and Arc to monitor industrial assets identify abnormal activity investigate threats and improve the overall security posture of OT and ICS environments.
The ideal candidate will bring deep experience in OT network monitoring industrial protocols threat detection and security operations. This individual will also work closely with engineering operations and cybersecurity teams to improve asset visibility refine detection capabilities support incident response and help mature OT security practices across the organization.
Key Responsibilities
OT Security Monitoring & Nozomi Administration
- Administer and optimize Nozomi Guardian sensors across OT network segments to provide asset visibility behavioral monitoring and threat detection.
- Utilize Nozomi Vantage for centralized monitoring dashboarding alert management and cross-environment visibility.
- Deploy configure and manage Nozomi Arc agents to expand endpoint visibility across OT assets.
- Develop and tune detection rules alert thresholds dashboards and monitoring workflows within the Nozomi platform.
- Maintain accurate OT asset inventories network topology maps communication baselines and device classifications.
Threat Detection & Incident Response
- Triage investigate and prioritize OT security alerts generated by Nozomi and integrated SIEM platforms.
- Analyze industrial network traffic to identify suspicious activity unauthorized devices lateral movement configuration changes and protocol anomalies.
- Perform root cause analysis and support containment remediation and recovery activities for OT security incidents.
- Correlate OT telemetry with enterprise security data to identify threats spanning IT and OT environments.
- Develop and maintain OT-specific incident response procedures playbooks and escalation processes.
OT Security Engineering & Governance
- Partner with plant operations engineering infrastructure and cybersecurity teams to securely onboard new OT devices and systems.
- Support network segmentation initiatives and the implementation of secure OT architecture principles.
- Contribute to OT cybersecurity standards policies procedures and operational controls.
- Support security assessments audits and remediation efforts aligned with IEC 62443 NIST SP 800-82 and related frameworks.
- Produce clear security reports risk findings and recommendations for both technical teams and leadership.
Leadership & Continuous Improvement
- Mentor junior security analysts and contribute to OT cybersecurity training and knowledge development.
- Identify opportunities to automate reporting alerting and analysis workflows.
- Continuously improve monitoring coverage detection quality and operational response capabilities.
Required Qualifications
- 5 years of cybersecurity experience including 3 years focused on OT ICS or industrial network security.
- Hands-on experience administering Nozomi Networks technologies including Guardian Vantage and Arc.
- Strong understanding of industrial control systems OT architectures and common industrial assets.
- Experience analyzing industrial protocols such as Modbus DNP3 EtherNet/IP PROFINET or similar technologies.
- Experience with SIEM platforms log correlation alert investigation and incident response.
- Strong understanding of network segmentation firewalls VLANs and secure OT network architecture.
- Working knowledge of IEC 62443 NIST SP 800-82 or similar OT cybersecurity frameworks.
- Ability to communicate security risks and technical findings clearly to both technical and non-technical stakeholders.
Preferred Qualifications
- Experience within manufacturing energy utilities data centers or other critical infrastructure environments.
- Exposure to additional OT cybersecurity platforms such as Claroty or Dragos.
- Scripting experience using Python PowerShell or similar tools for workflow automation and reporting.
- Certifications such as GICSP Nozomi Networks Certified Expert CSSA or equivalent.
- Prior experience mentoring analysts or serving as a technical lead within an OT security team.