OT Security Engineer L3
Gruve
| Company | Gruve |
| Category | Engineering |
| Location | Pune |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 20 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks. Position summary:
We are seeking an experienced OT Security Engineer L3 to lead the design, deployment, integration, support, and optimization of OT security monitoring solutions across ICS, SCADA, DCS, and IIoT environments. The ideal candidate will bring 6–10 years of experience in OT cybersecurity and industrial network defense, act as the highest technical escalation point within the OT SOC, and drive implementation, threat hunting, incident response, detection engineering, customer engagement, and continuous improvement for complex industrial environments.
Key Roles & Responsibilities:
1. OT Security Architecture, Deployment, and Implementation
Lead the deployment and configuration of OT monitoring solutions including Nozomi Guardian and related collectors, sensors, packet brokers, TAPs, SPAN ports, and syslog infrastructure.
Design OT monitoring architecture for industrial environments covering asset visibility, protocol decoding, segmentation-aware telemetry collection, and secure integration patterns.
Install and configure SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, FortiSIEM, and Elastic Security for OT use cases.
2. Integration and Automation
Integrate OT monitoring technologies with SIEM, SOAR, EDR, threat intelligence platforms, CMDBs, ticketing systems, and reporting solutions.
Configure Syslog, REST APIs, STIX/TAXII feeds, automation workflows, and custom integrations for OT firewalls, switches, historians, HMIs, PLCs, and engineering workstations.
3. Incident Response and Technical Escalation
Lead the investigation of high-severity OT security incidents and act as the final escalation point for complex issues raised by L1 and L2 analysts.
Coordinate containment, eradication, recovery, root-cause analysis, and technical communication with customer incident response teams and internal stakeholders.
4. Threat Hunting and Detection Engineering
Perform proactive threat hunting across OT and converged OT/IT environments to identify abnormal asset behavior, unsafe protocol usage, lateral movement, persistence mechanisms, and industrial attack techniques.
Develop and optimize detection rules, dashboards, correlation logic, and OT-specific use cases to improve fidelity and reduce false positives.
5. Security Monitoring, Packet Analysis, and Forensics
Review OT alerts and correlate them with enterprise SIEM telemetry, asset context, and industrial communication patterns.
Perform advanced packet analysis using Wireshark, support forensic triage, validate malware indicators, and guide evidence collection for OT investigations.
6. Customer Engagement and Technical Leadership
Lead onsite and remote implementation activities, conduct customer workshops, deliver technical presentations, and provide expert troubleshooting during upgrades, migrations, and health checks.
Serve as the senior technical SME for OT SOC operations and provide strategic guidance during architecture reviews, escalations, and service improvement planning.
7. Engineering, Optimization, and Playbooks
Create custom parsers, integrations, playbooks, SOPs, and knowledge artifacts that improve OT visibility, response consistency, and service quality.
Optimize detection logic, data onboarding, alert tuning, and reporting workflows to improve MTTR, response quality, and customer outcomes.
8. OT Domain, Protocol, and Asset Expertise
Apply deep working knowledge of OT/ICS comp
995,367 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →