SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: GBP 60,000 - 0 / annual
Dragos is the global leader in operational technology (OT) cybersecurity, protecting critical infrastructure systems including water, power, and healthcare. As a Senior OT Security Analyst on the OT Watch Complete team, you will lead frontline monitoring and triage operations responsible for identifying adversary activity in customer OT environments. You will work with experienced industrial defenders, mentor junior analysts, and investigate anomalous network behaviors to validate detection triggers and support threat hunters and incident responders with high-quality escalations.
Key responsibilities include:
- Lead shift operations, guiding analysts through detection alert triage and network telemetry analysis from the Dragos Platform across customer OT environments, stepping in as shift leader for your region when needed
- Serve as a senior investigator, analyzing suspicious activity to identify misconfigurations, anomalies, and potential malicious behavior across industrial networks
- Apply deep analysis and context to escalate findings to Incident Responders and threat hunters with clear, actionable documentation
- Partner across teams (analysts, threat hunters, incident responders, platform engineers, Detection Engineering) to tune detection logic, reduce false positives, and shape new platform detections and playbooks
- Write and deliver incident summaries and operational reports to internal stakeholders and customers
- Support the full scope of OT Watch Complete, including asset classification, vulnerability management, hardening recommendations, and customer information requests
- Build continuous expertise in ICS/OT protocols, adversary tradecraft, and threat intelligence specific to industrial environments
You will operate in a remote-first, mission-driven environment with distributed teams across North America, Europe, the Middle East, and APAC. The initial schedule is Monday-Friday 8am-5pm with on-call weekends (MDT for US, CEST for Europe, AEST for Australia). The schedule will later transition to a 4-day/week, 10-hour shift model with weekend coverage options (Sunday-Wednesday or Wednesday-Saturday shifts).
Requirements:
- 3–5 years of experience in network security with hands-on exposure to real-world threat investigation
- Solid understanding of core networking concepts (TCP/IP, firewalls, DNS, packet analysis)
- Hands-on experience with security monitoring tools such as IDS/IPS, SIEM platforms, or network traffic analyzers
- Strong written and verbal communication skills with close attention to detail; ability to translate technical findings for both internal teams and customers
- Genuine interest in ICS/OT cybersecurity and drive to defend critical infrastructure, with ability to quickly pick up complex industrial-specific concepts
- Comfortable working independently in a remote environment while coordinating across distributed teams
- Flexibility to participate in shift-based coverage and occasional weekend/on-call work
Preferred Qualifications:
- Experience working on a Security Operations Center (SOC) team
- Familiarity with OT protocols (e.g., Modbus, DNP3, Ethernet/IP) and ICS environments
- Applied knowledge of adversary tactics and frameworks relevant to OT (e.g., MITRE ATT&CK for ICS)
- Hands-on lab or internship experience in cybersecurity operations, threat hunting, or digital forensics
- Experience in packet capture (PCAP) analysis or basic scripting (e.g., Python, Bash)