WWT is seeking an embedded Operational Technology (OT) Security Consultant to lead Nozomi Networks monitoring and detection improvements for a customer Security Operations Center (SOC). This hands-on role combines production SOC experience, industrial network knowledge, and deep administration and tuning expertise with Nozomi Networks. The consultant will assess existing use cases, improve alert quality and visibility, coach analysts through each change, and create durable runbooks and tuning records that strengthen the team's long-term capabilities. This is a full-time role dedicated to one customer for approximately 12 months, with a potential extension. Business hours align to US Central time, with no on-call or 24x7 monitoring duties. Remote, hybrid, or on-site presence will be confirmed with the customer. Daily participation in stand-ups and shared team channels is expected.
Responsibilities:
Catalogue and assess existing Nozomi alerts, policies, and use cases against an agreed baseline such as
MITRE ATT&CK
for ICS, applicable regulatory monitoring obligations, IEC 62443, and vendor reference content. Co-author a prioritized roadmap with the Splunk lead during the initial phase of the engagement. Recommend and implement approved refinements to alert rules, thresholds, asset groupings, learning profiles, and zone and conduit definitions to reduce noise and false positives. Design new Nozomi detections, custom checks, and queries that address coverage gaps for OT-specific threats and protocols. Review sensor coverage, asset inventory accuracy, and passive discovery results, and recommend configuration improvements that strengthen detection quality. Partner with the Splunk lead to improve how Nozomi alerts and asset data flow into the security information and event management platform, including field mapping, enrichment, and correlation. Coach SOC analysts using real alerts and investigations, and capture lessons learned in detections and runbooks. Create a runbook and tuning rationale for each new or materially changed use case. Provide monthly reporting on changes, rationale, alert volume, false positive rate, and coverage improvement. Coordinate with customer teams, implementation partners, and change control stakeholders so improvements are delivered smoothly.
Job Requirements Required Qualifications:
Significant cybersecurity experience, including hands-on SOC work involving triage, investigation, and detection tuning in a production environment; approximately five or more years of overall experience is preferred. Experience working in OT or Industrial Control System (ICS) environments such as utilities, energy, water, or manufacturing. Proven hands-on administration and tuning experience with Nozomi Networks Guardian and/or Vantage beyond training or demonstration environments. Solid understanding of industrial protocols such as Modbus, DNP3, IEC 61850, OPC, and EtherNet/IP, along with Purdue model network architecture. Working knowledge of
MITRE ATT&CK
for ICS and the ability to map detections to the framework. Strong written and verbal communication skills, with experience coaching analysts and creating clear technical documentation.
Preferred Qualifications:
Experience supporting an electric utility or other critical infrastructure environment, including familiarity with applicable regulatory requirements. Working knowledge of
IEC 62443.
Experience integrating Nozomi Networks with Splunk or another security information and event management platform. Experience with passive network monitoring design, SPAN and TAP strategy, and OT asset inventory. Prior consulting or embedded advisory experience.
Certifications:
Nozomi Networks certification is valued. GICSP, GRID, GCIA, GCIH, CISSP, or equivalent certifications are also helpful. Certifications support, but do not replace, hands-on SOC and OT experience. Already have an account? Log in here