21 Aug
|
Kroll
|
Bengaluru
Kroll is seeking an OT Security Engineer to support the delivery of Operational Technology Security engagements from India. The role requires a strong foundation in enterprise and industrial networking, combined with hands-on experience deploying and supporting OT asset visibility and threat monitoring platforms such as Nozomi Networks, Claroty, or Armis.
The role will support the design and implementation of secure OT architectures, including segmentation, industrial DMZs, firewall policy design, secure remote access, implementation of OT IDS, and controlled IT/OT connectivity. The engineer will work closely with Kroll teams across EMEA and North America, as well as client engineering teams and technology vendors, to deliver practical and resilient solutions that account for operational availability, safety, and business requirements.
Day-to-Day Responsibilities:
- Design, review, and document OT architectures, including Purdue-model zones and conduits, industrial DMZs, secure remote access, and IT/OT interconnections.
- Support OT network segmentation projects from discovery and current-state assessment through target-state design, firewall rule definition, implementation planning, testing, and validation.
- Deploy, configure, tune, upgrade, and troubleshoot OT asset visibility and security monitoring platforms such as Nozomi Networks, Claroty, or Armis.
- Plan sensor and collector placement, configure SPAN/TAP connectivity, validate packet visibility, and integrate monitoring platforms with SIEM, SOC, MDR, ticketing, and identity systems.
- Perform network discovery and traffic analysis to identify assets, protocols, communication paths, dependencies, and segmentation requirements across industrial environments.
- Configure and troubleshoot network technologies including switching, routing, VLANs, VRFs,
ACLs, firewalls, VPNs, NAT, redundancy, and high-availability designs in enterprise and OT environments.
- Develop network diagrams, low-level designs, firewall rule matrices, implementation runbooks, test plans, rollback plans, and as-built documentation.
- Support client workshops, technical discussions, Proofs of Concept, solution demonstrations, and coordination with network, controls, engineering, SOC, and vendor teams.
- Contribute to OT Zero Trust and micro-segmentation initiatives; experience with solutions such as Zscaler or ColorTokens is an advantage.
Essential Traits:
- Strong hands-on networking mindset with a structured approach to troubleshooting and root-cause analysis.
- Ability to translate discovered OT traffic flows and operational dependencies into practical segmentation designs and implementation plans.
- Delivery-focused approach that balances cybersecurity objectives with safety, availability, and production requirements.
- Confidence working with client network, engineering, controls, security operations, and technology vendor teams.
- Clear communication style and the ability to explain network and security issues to both technical and non-technical stakeholders.
- Solid ownership, attention to detail, and disciplined creation of diagrams, runbooks, rule matrices, and as-built documentation.
Prerequisites:
- Bachelor’s degree in Cybersecurity, Information Technology,
Computer Science, Electronics, Engineering, or a related field.
- Approximately 5-8 years of relevant experience in network engineering, network security, or OT/ICS security, with meaningful hands-on delivery experience.
- Strong networking fundamentals, including TCP/IP, subnetting, switching, routing, VLANs, STP, HSRP/VRRP, OSPF/BGP, DNS, DHCP, NAT, VPNs, and packet analysis.
- Hands-on experience with enterprise firewalls, switches, routers, and network management or troubleshooting tools; experience with major vendors such as Cisco, Palo Alto Networks, Fortinet, or Check Point is preferred.
- Hands-on deployment or operational support experience with at least one OT monitoring or asset visibility platform: Nozomi Networks, Claroty, or Armis.
- Experience supporting network segmentation or firewall migration projects, including traffic-flow analysis, rule-base development, implementation coordination, and post-change validation.
- Working knowledge of industrial protocols such as Modbus TCP, DNP3, OPC/OPC UA, EtherNet/IP, PROFINET, BACnet, and IEC 60870-5-104.
- Understanding of OT security standards and guidance such as ISA/IEC 62443 and NIST SP 800-82.
- Experience with OT Zero Trust, software-defined segmentation, or micro-segmentation solutions such as Zscaler or ColorTokens is preferred.
- Experience integrating OT monitoring solutions with SIEM, SOC, MDR, identity, vulnerability management, or ticketing platforms.
- Relevant certifications such as CCNA/CCNP, PCNSE, NSE/FCP, GICSP, GRID, or ISA/IEC 62443 are advantageous.
Strong analytical, troubleshooting, documentation, and client communication skills, with the ability to work independently and collaboratively across time zones.
📌 OT Security Engineer, Cyber Risk (Bengaluru)
🏢 Kroll
📍 Bengaluru