Senior OT Threat Hunter and Detection SME
AtosJ. P. Nagar, Bengaluru, Karnataka, India; Bengaluru/Mumbai (Hybrid)
Advertisement
in-feed
Atos is seeking an experienced OT Threat Hunter and Detection Engineer to identify suspicious activity, investigate anomalies and improve threat-detection capabilities across Operational Technology and Industrial Control System environments.
Key Responsibilities
OT Threat Hunting
- Conduct proactive threat hunting across OT and ICS environments.
- Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
- Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
- Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
- Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
- Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
- Map findings to MITRE ATT&CK for ICS and MITRE ATT&CK Enterprise where applicable.
Detection Engineering
- Develop and validate OT-specific detection use cases and analytics.
- Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
- Review existing OT monitoring coverage and identify detection gaps.
- Tune security alerts to improve detection quality and reduce unnecessary false positives.
- Establish baseline communication patterns for critical industrial assets and network zones.
- Develop detection logic for unauthorised asset connections, unexpected protocol usage, abnormal communication paths, suspicious remote access, credential misuse, lateral movement, engineering-workstation anomalies and changes to PLC or controller communication.
- Support purple-team exercises by validating whether simulated attack activity is detected and investigated effectively.
Alert Investigation and Incident Support
- Analyse and triage alerts generated by OT IDS, NDR, SIEM and endpoint-security platforms.
- Correlate alerts across IT and OT systems to identify potential attack paths.
- Conduct initial compromise assessments and support incident scoping.
- Gather, preserve and document relevant investigation evidence.
- Work with incident-response teams to recommend containment, monitoring and recovery actions.
- Support post-incident reviews and convert lessons learned into improved detection content.
- Escalate critical findings in accordance with agreed incident and operational procedures.
OT Visibility and Monitoring Review
- Review OT asset inventories and identify unknown, unmanaged or unauthorised devices.
- Assess the quality and coverage of network sensors, packet collection and log sources.
- Validate asset classification, communication baselines and criticality information.
- Identify monitoring gaps across industrial zones and conduits.
- Support the onboarding of relevant OT data sources into SIEM, SOC and detection platforms.
- Work with plant teams to ensure monitoring activities do not affect operational availability.
Reporting and Stakeholder Engagement
- Prepare clear threat-hunting and investigation reports containing the investigation scope, hunting hypothesis, data sources reviewed, findings and supporting evidence.
- Work closely with OT SOC teams, plant engineers, incident-response teams and security stakeholders.