Location: Bengaluru/Mumbai | Hybrid, with travel to customer and industrial sites as required
Experience: 6-10 years
Role Overview
We are seeking an experienced OT Threat Hunter and Detection Engineer to identify suspicious activity, investigate anomalies and improve threat-detection capabilities across Operational Technology and Industrial Control System environments.
The role will focus on analysing OT network traffic, security alerts, logs, asset inventories and communication baselines to identify unauthorised activity, lateral movement, protocol misuse and potential signs of compromise.
The specialist will work closely with OT SOC teams, plant engineers, incident-response teams and security stakeholders to develop threat-hunting hypotheses, detection use cases, investigation playbooks and practical containment recommendations.
Key Responsibilities
- OT Threat Hunting
- Conduct proactive threat hunting across OT and ICS environments.
- Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
- Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
- Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
- Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
- Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
- Map findings to MITRE ATT&CK; for ICS and MITRE ATT&CK; Enterprise where applicable. Detection Engineering.
- Develop and validate OT-specific detection use cases and analytics.
- Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
- Review existing OT monitoring coverage and identify detection gaps.
- Tune security alerts to improve detection quality a
📌 OT Threat Hunter (Mumbai)
🏢 Atos
📍 Mumbai