SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior OT Security Analyst

Dragos - Remote - Remote - posted 2026-09-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: AUD 130,000 - 0 / annual

Dragos is the global leader in operational technology (OT) cybersecurity, protecting critical infrastructure systems including water, power, and healthcare. As a Senior OT Security Analyst on the OT Watch Complete team, you will lead frontline monitoring and triage operations responsible for identifying adversary activity in customer OT environments. You will work with experienced industrial defenders, mentor junior analysts, and investigate anomalous network behaviors to validate detection triggers and support threat hunters and incident responders with high-quality escalations. Key responsibilities include leading shift operations and guiding analysts as they triage detection alerts and network telemetry from the Dragos Platform across customer OT environments, stepping in as shift leader for your region when needed. You will serve as a senior investigator, digging into suspicious activity to identify misconfigurations, anomalies, and potential malicious behavior across industrial networks. You will apply deep analysis and context to escalate findings to Incident Responders and threat hunters with clear, actionable documentation. You will partner across teams—analysts, threat hunters, incident responders, platform engineers, and Detection Engineering—to tune detection logic, reduce false positives, and shape new Dragos Platform detections and playbooks. You will write and deliver incident summaries and operational reports that give internal stakeholders and customers clear visibility into their environment. You will support the full scope of OT Watch Complete, from asset classification and vulnerability management to hardening recommendations and direct customer information requests. You will build expertise continuously in ICS/OT protocols, adversary tradecraft, and threat intelligence specific to industrial environments. The initial schedule is Monday-Friday 8am-5pm with on-call weekends (MDT for US, CEST for Europe, AEST for Australia). The schedule will later transition to a 4-day/week, 10-hour shift model including a day on the weekend, with shift schedules running either Sunday-Wednesday or Wednesday-Saturday. Applicants can choose their preferred shift schedule. **Requirements:** - 3–5 years of experience in network security, ideally with hands-on exposure to real-world threat investigation - Solid understanding of core networking concepts: TCP/IP, firewalls, DNS, packet analysis - Hands-on experience with security monitoring tools such as IDS/IPS, SIEM platforms, or network traffic analyzers - Strong written and verbal communication skills with close attention to detail; ability to translate technical findings for both internal teams and customers - Genuine interest in ICS/OT cybersecurity and drive to defend critical infrastructure, with ability to pick up complex industrial-specific concepts quickly - Comfortable working independently in a remote environment while coordinating across distributed teams - Flexibility to participate in shift-based coverage and occasional weekend/on-call work **Preferred Qualifications:** - Experience working on a Security Operations Center (SOC) team - Familiarity with OT protocols (e.g., Modbus, DNP3, Ethernet/IP) and ICS environments - Applied knowledge of adversary tactics and frameworks relevant to OT (e.g., MITRE ATT&CK for ICS) - Hands-on lab or internship experience in cybersecurity operations, threat hunting, or digital forensics - Experience in packet capture (PCAP) analysis or basic scripting (e.g., Python, Bash)

Similar roles