Atos

Senior OT Threat Hunter and Detection SME

Atos

J. P. Nagar, Bengaluru, Karnataka, India; Bengaluru/Mumbai (Hybrid)

Experience 6–10 years
Posted 1 month ago
Hybrid 6–10 years Level

Atos is seeking an experienced OT Threat Hunter and Detection Engineer to identify suspicious activity, investigate anomalies and improve threat-detection capabilities across Operational Technology and Industrial Control System environments.

Key Responsibilities

OT Threat Hunting

  • Conduct proactive threat hunting across OT and ICS environments.
  • Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
  • Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
  • Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
  • Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
  • Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
  • Map findings to MITRE ATT&CK for ICS and MITRE ATT&CK Enterprise where applicable.

Detection Engineering

  • Develop and validate OT-specific detection use cases and analytics.
  • Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
  • Review existing OT monitoring coverage and identify detection gaps.
  • Tune security alerts to improve detection quality and reduce unnecessary false positives.
  • Establish baseline communication patterns for critical industrial assets and network zones.
  • Develop detection logic for unauthorised asset connections, unexpected protocol usage, abnormal communication paths, suspicious remote access, credential misuse, lateral movement, engineering-workstation anomalies and changes to PLC or controller communication.
  • Support purple-team exercises by validating whether simulated attack activity is detected and investigated effectively.

Alert Investigation and Incident Support

  • Analyse and triage alerts generated by OT IDS, NDR, SIEM and endpoint-security platforms.
  • Correlate alerts across IT and OT systems to identify potential attack paths.
  • Conduct initial compromise assessments and support incident scoping.
  • Gather, preserve and document relevant investigation evidence.
  • Work with incident-response teams to recommend containment, monitoring and recovery actions.
  • Support post-incident reviews and convert lessons learned into improved detection content.
  • Escalate critical findings in accordance with agreed incident and operational procedures.

OT Visibility and Monitoring Review

  • Review OT asset inventories and identify unknown, unmanaged or unauthorised devices.
  • Assess the quality and coverage of network sensors, packet collection and log sources.
  • Validate asset classification, communication baselines and criticality information.
  • Identify monitoring gaps across industrial zones and conduits.
  • Support the onboarding of relevant OT data sources into SIEM, SOC and detection platforms.
  • Work with plant teams to ensure monitoring activities do not affect operational availability.

Reporting and Stakeholder Engagement

  • Prepare clear threat-hunting and investigation reports containing the investigation scope, hunting hypothesis, data sources reviewed, findings and supporting evidence.
  • Work closely with OT SOC teams, plant engineers, incident-response teams and security stakeholders.

Similar Job Openings