Security Operation Supervisor (OT Specialization) (Bengaluru)

Security Operation Supervisor (OT Specialization) (Bengaluru)

27 Sep
|
Fluenc
|
Bengaluru

27 Sep

Fluenc

Bengaluru

Role Overview

The Security Operations Supervisor (OT Specialization) leads the day-to-day work of a team of security operations analysts and serves as the senior technical escalation point for threats affecting both our corporate IT estate and our operational technology environments, including battery energy storage sites and the systems that support them. Based in Bengaluru, this role supervises cybersecurity analysts, quality of triage and investigation, and the professional growth of the analyst team, while personally handling complex detection, hunting and incident response work. The Supervisor partners closely with the global cybersecurity team, IT infrastructure, service desk, service and operations engineering, product security and, where required, customers and external incident response partners. The ideal candidate has hands-on security operations depth, real exposure to industrial control system and OT environments, and a genuine interest in coaching analysts and improving how a security operations team works. Key tools and platforms include Microsoft Sentinel and Defender, endpoint detection and response, SOAR and automation platforms, OT monitoring technologies, threat intelligence services and IT service management tooling.

Key Responsibilities

Security Monitoring, Detection and Incident Response

- Direct network monitoring and intrusion detection analysis using computer network defense tools such as intrusion detection and prevention systems, firewalls, proxies and host-based security systems.

- Oversee log-based, identity-based and endpoint-based threat detection to identify and contain threats originating from multiple sources.

- Drive cloud-centric detection coverage for the cloud environments and services the organization uses, including Azure, AWS and GCP workloads.

- Correlate activity across assets (endpoint, network, identity, applications) and environments (on-premises, cloud, OT) to identify patterns of anomalous activity, attacks and unauthorized use.

- Review alerts and sensor data escalated by analysts, validate findings and produce formal, technical incident reports for technical and management audiences.

- Act as incident commander or senior responder for high-severity incidents, coordinating containment, eradication and recovery activities across teams and time zones.

- Provide users and internal stakeholders with incident response support, including mitigating actions to contain activity and facilitating forensic analysis where necessary.

- Work with threat intelligence and threat-hunting teams, translating intelligence into detection content, hunting hypotheses and response playbooks.

- Research emerging threats, adversary tradecraft and vulnerabilities to support the identification and classification of incidents.

- Support the creation and testing of business continuity and disaster recovery plans, including running exercises,



publishing results and driving remediation of deficiencies.

- Perform security standards testing against systems before implementation to confirm they meet security requirements.

Operational Technology (OT) Security

- Own monitoring, detection and response for operational technology environments, including battery energy storage sites, site controllers, historians, engineering workstations and remote access paths used to support them.

- Tune and maintain OT-specific detection content, including rules for unauthorized configuration changes, unexpected protocol use, rogue devices and abnormal control traffic.

- Onboard and validate telemetry from OT monitoring and asset discovery platforms into the SIEM, and maintain accurate OT asset and network context for responders.

- Maintain and exercise OT incident response playbooks that account for safety, availability and physical process constraints, including scenarios where containment actions cannot disrupt energy delivery.

- Monitor and review privileged and vendor remote access into OT networks, escalating misuse or policy deviations.

- Work with service and operations engineering, product teams and site personnel to validate alerts, confirm expected activity and agree on safe response actions.

- Track OT vulnerabilities and advisories, assess applicability to deployed systems and coordinate risk-based mitigation with engineering owners.

- Support alignment of OT monitoring and response practices with recognized frameworks and standards such as IEC 62443, NIST SP 800-82 and applicable customer or regulatory requirements.

Supervision and Development of Analysts

- Supervise a team of security operations analysts, including day-to-day task assignment, shift and on-call scheduling, workload balancing and handover quality across regions.

- Set clear performance expectations, conduct regular one-on-ones, provide continuous feedback and contribute to goal setting, performance reviews and career development plans.

- Coach analysts on investigation technique, evidence handling, documentation quality and escalation judgment, and review a sample of closed cases for accuracy and completeness.

- Build and maintain a skills matrix and training path for the team, covering IT, cloud and OT monitoring, and identify gaps to be closed through training or hiring.

- Deliver regular internal training sessions on intrusion detection and prevention, incident response procedures, threat intelligence analysis, log analysis and OT fundamentals.

- Run tabletop exercises,



purple team activities and detection drills to test analyst readiness and improve response quality.

- Participate in recruiting, interviewing and onboarding of new analysts, including mentoring during ramp-up.

- Manage the relationship with managed detection and response or outsourced monitoring partners, reviewing their output quality and holding them to agreed service levels.

- Foster a culture of ownership, knowledge sharing and psychological safety, so analysts raise concerns early and learn from incidents without blame.

Detection Engineering, Automation and Tooling

- Work with security information and event management (SIEM) platforms to manage and tune the system, create and maintain detection content and actively watch for alerts.

- Own the detection engineering backlog, from use case definition through rule development, testing, documentation and measurement of effectiveness.

- Drive down false positives and alert fatigue through tuning, enrichment and suppression logic, with measurable targets reported to leadership.

- Design and maintain security orchestration, automation and response (SOAR) playbooks that automate repetitive triage, enrichment and containment tasks.

- Ensure log source coverage and data quality across IT, cloud and OT, identifying blind spots and driving onboarding of missing telemetry.

- Map detection coverage to MITRE ATT&CK; for Enterprise and ATT&CK; for ICS, and use the results to prioritize new content.

Process, Reporting and Continuous Improvement

- Maintain standard operating procedures, runbooks and escalation matrices for the security operations team, and keep them current as tooling and the workplace change.

- Track and report operational metrics such as alert volume, time to triage, time to contain, escalation accuracy and detection coverage, with regular reporting to cybersecurity leadership.

- Lead post-incident reviews, capture lessons learned and drive corrective actions to closure with the responsible owners.

- Manage projects to implement new security tooling or to develop new security policies and procedures, including scope, timeline and stakeholder communication.

- Apply change management practices when introducing new controls or processes, including change plans and management of business impact.

- Support audit, compliance and customer assurance activities by providing evidence of monitoring, detection and response capability.

Required Qualifications

- Bachelors degree in computer science, information security, cybersecurity, engineering or a related field, or equivalent practical experience.

- Minimum 6 years of experience.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Security Operation Supervisor (OT Specialization) (Bengaluru)
🏢 Fluenc
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security operation supervisor (ot specialization) (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: security operation supervisor (ot specialization) (bengaluru) / bengaluru