OT Incident Response Analyst – L3 (Riyadh)
Accenture Middle East · Riyad
Job description
About the role
The OT SOC L3 Analyst is the senior technical authority within the Operational Technology Security Operations Center. Based in Riyadh, this role leads advanced threat hunting, OT‑aware digital forensics, incident response, and detection engineering while mentoring junior analysts.
Key responsibilities
- Lead investigations and response for complex, high‑severity attacks targeting OT/ICS environments.
- Conduct proactive, hypothesis‑driven threat‑hunting campaigns across OT networks.
- Perform OT‑aware DFIR forensic acquisition and analysis of PLCs, HMIs, controllers, workstations and network captures while preserving safety and evidence integrity.
- Design, build and tune detection content and correlation rules; own the detection‑engineering lifecycle for the OT SOC.
- Operationalize OT threat intelligence (e.g., ELECTRUM, Sandworm, TRITON, Industroyer) and map it to MITRE ATT&CK for ICS detections.
- Develop, document and continuously improve OT incident‑response playbooks and runbooks.
- Mentor L1/L2 analysts, provide technical coaching and quality review of investigations.
- Lead tabletop exercises, purple‑team and adversary‑emulation activities.
- Advise on OT network architecture, segmentation and monitoring placement to close detection gaps.
- Produce executive and technical incident reports and support compliance with NCA OTCC‑1:2022, ECC and ISA/IEC 62443.
Required profile
- Bachelor’s degree in Cybersecurity, Computer/Electrical/Instrumentation Engineering or related field (Master’s a plus).
- 6–10+ years of cybersecurity experience, with at least 4 years in OT/ICS security operations, DFIR or threat hunting.
- Deep expertise in OT protocols, DCS, SCADA, PLC, SIS and the Purdue model.
- Proven experience leading OT/ICS incident response and forensic investigations.
- Strong knowledge of MITRE ATT&CK for ICS, NIST SP 800‑82, ISA/IEC 62443 and NCA OTCC.
- Preferred certifications: GRID, GCIP, GICSP, GCFA, GREM or vendor‑specific certifications (Dragos, Claroty, Nozomi).
Required skills
- OT monitoring platforms: Nozomi, Claroty, Dragos, Tenable OT, Microsoft Defender for IoT.
- SIEM and detection engineering tools: Splunk, QRadar, Microsoft Sentinel.
- OT protocols and architectures: DCS, SCADA, PLC, SIS, Purdue model.
- Threat‑intelligence frameworks and MITRE ATT&CK for ICS.
- Forensic acquisition and analysis of industrial control systems.
- Regulatory standards: NIST SP 800‑82, ISA/IEC 62443, NCA OTCC‑1:2022.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 day ago
Expires 1 month from now
11 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Accenture Middle East
Riyad