Source description
About the role
Chennai, Tamil Nadu Job Summary The OT SOC Level 2 Analyst is responsible for advanced security monitoring, investigation, and incident response within Operational Technology (OT) settings using Nozomi Networks and Microsoft Sentinel . The role acts as an escalation point for Level 1 analysts and contributes to continuous improvement of OT SOC operations through detection fine-tuning, SOP and playbook development, and team enablementwhile ensuring security actions align with OT safety, availability, and operational constraints. . Key Responsibilities Responsibilities Perform Level 2 triage and investigation of OT security alerts generated by Nozomi Networks. Validate and analyse alerts using OT context such as asset criticality, industrial processes, site topology, and maintenance activities. Determine incident scope, root cause, impacted assets, and potential operational or safety impact. Lead and coordinate OT incident response activities in collaboration with SOC, OT engineers, and IT security teams. Escalate confirmed or high-risk incidents according to SOC and OT incident response procedures. Investigate OT-related incidents in Microsoft Sentinel by correlating Nozomi alerts with IT, network, and security telemetry. Support development and refinement of OT-specific detection use cases and alert logic. Perform detection fine-tuning to improve signal quality and reduce false positives based on operational feedback. Contribute investigation logic and response steps for SOC playbooks and runbooks . Create, maintain, and improve OT SOC SOPs , incident response procedures, and investigation guides. Support post-incident reviews and incorporate lessons learned into procedures and detection improvements. Act as an escalation and mentoring point for Level 1 OT SOC analysts . Provide training and knowledge transfer on OT threats, Nozomi alert interpretation, and investigation techniques. Support continuous improvement of OT SOC processes, reportin .
More at HCLTech
Related open roles
SeniorAdministrator - Symantec Email Security, Endpoint Security
Mumbai
Track Manager Security Investigations, Siem Gautam Buddh Nagar
India
Walk-In Drive | Fraud Analyst | 1st Aug 26 | Bangalore
Bangalore
Senior Administrator - Identity Access Management,Service-Oriented Architecture
Chennai
Senior Administrator - AWS Security, Cloud Security (Navi Mumbai)
Mumbai
Track Lead - Web App firewall, Cloud Security, Palo Alto Firewalls
India