Source description
About the role
Gruve is an innovative software services startup specializing in cybersecurity, customer experience, cloud infrastructure, and advanced technologies. This Security Analyst (OT SOC) role involves monitoring and investigating security incidents in Operational Technology (OT) environments, supporting SIEM and OT visibility platforms, and safeguarding safety-critical industrial operations. What You'll Do Monitor OT and IT security alerts across SIEM and OT visibility platforms such as Splunk, QRadar, Sentinel, FortiSIEM, Elastic, and Nozomi Guardian; validate suspicious activities and escalate confirmed incidents with evidence and business impact analysisInvestigate OT security alerts, malware indicators, unauthorized changes, and suspicious network behavior affecting PLCs, RTUs, HMIs, and engineering workstations; perform packet analysis using Wireshark and support containment activitiesSupport SIEM administration including log source validation, parser verification, alert tuning, and false-positive reduction; assist with Nozomi Guardian administration and contribute to detection rule creation aligned to industrial threatsAssist OT solution deployments by validating sensor connectivity, syslog forwarding, collector health, and API integrations; support integration of OT monitoring platforms with SIEM, SOAR, and ticketing systemsProvide remote troubleshooting, incident bridge support, health checks, and ticket resolution for customer OT security environments; prepare daily SOC reports, incident summaries, and asset visibility reportsWhat You Need Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Electronics, Instrumentation, or related field36 years of experience in cybersecurity operations, OT SOC, ICS/SCADA monitoring, incident investigation, or industrial network securityHands-on experience with SIEM platforms such as Splunk, QRadar, Sentinel, FortiSIEM, or Elastic, and familiarity with Nozomi Guardian or similar OT monitoring toolsWorking knowledge of OT/ICS environments including ICS, SCADA, PLC, RTU, HMI, historians, industrial switches, and engineering workstations; understanding of industrial protocols such as Modbus, DNP3, OPC UA, IEC 60870-5-104, and PROFINETExperience with Wireshark, Syslog, Linux, Windows, Excel, and PowerShell for troubleshooting, analysis, and reporting; strong analytical thinking, documentation discipline, and ability to work in rotational shiftsNice to Have Certifications such as Security+, Microsoft SC-200, Splunk Power User, QRadar Analyst, Nozomi Fundamentals, or GICSP (foundation level exposure)Exposure to SOAR workflows, API-based integrations, threat intelligence enrichment, and OT vulnerability management processesKnowledge of Purdue Model, network segmentation, jump hosts, remote access controls, and OT asset inventory conceptsExperience supporting industrial customers in manufacturing, energy, utilities, oil and gas, pharma, or critical infrastructure sectors; strong interest in building expertise in OT detection engineering and incident response Gruve is an innovative software services startup specializing in cybersecurity, customer experience, cloud infrastructure, and advanced technologies. This Security Analyst (OT SOC) role involves monitoring and investigating security incidents in Operational Technology (OT) environments, supporting SIEM and OT visibility platforms, and safeguarding safety-critical industrial operations. What You'll Do Monitor OT and IT security alerts across SIEM and OT visibility platforms such as Splunk, QRadar, Sentinel, FortiSIEM, Elastic, and Nozomi Guardian; validate suspicious activities and escalate confirmed incidents with evidence and business impact analysisInvestigate OT security alerts, malware indicators, unauthorized changes, and suspicious network behavior affecting PLCs, RTUs, HMIs, and engineering workstations; perform packet analysis using Wireshark and support containment activitiesSupport SIEM administration including log source validation, parser verification, alert tuning, and false-positive reduction; assist with Nozomi Guardian administration and contribute to detection rule creation aligned to industrial threatsAssist OT solution deployments by validating sensor connectivity, syslog forwarding, collector health, and API integrations; support integration of OT monitoring platforms with SIEM, SOAR, and ticketing systemsProvide remote troubleshooting, incident bridge support, health checks, and ticket resolution for customer OT security environments; prepare daily SOC reports, incident summaries, and asset visibility reportsWhat You Need Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Electronics, Instrumentation, or related field36 years of experience in cybersecurity operations, OT SOC, ICS/SCADA monitoring, incident investigation, or industrial network securityHands-on experience with SIEM platforms such as Splunk, QRadar, Sentinel, FortiSIEM, or Elastic
More at Gruve
Related open roles
Infrastructure Security Engineer-L2 (Palo Alto & NGFW)
Mumbai
Senior Infrastructure Security Engineer-(Palo Alto & Cloud Operations) (Navi
Mumbai
Senior Infrastructure Security Engineer-L3 (Palo Alto & Cloud Operations)
Mumbai
Senior Infrastructure Security Engineer-L3 (Palo Alto & NGFW)
Mumbai
Infrastructure Security Engineer-L2 (Palo Alto & NGFW)
Mumbai
OT Security Engineer L3
Mumbai