Bachelor's degree in a technical discipline from an accredited university.
6 years of relevant IT experience in cybersecurity or related fields.
2 years of experience in Operational Technology (OT) environments.
2 years of experience using cyber threat intelligence for threat assessment.
2 years of experience with Security Information and Event Management (SIEM) platforms.
Familiarity with the NIST Incident Response Framework.
Knowledge of the MITRE ATT&CK framework and its applications.
Experience with OT technologies like PLCs and SCADA systems.
Understanding of cybersecurity threats specific to OT environments.
Responsibilities
Collect and analyze cybersecurity threat intelligence from various sources.
Develop actionable threat intelligence reports and briefings for stakeholders.
Identify protection and detection gaps in OT systems with cybersecurity engineers.
Analyze OT system logs and security alerts for indicators of compromise.
Collaborate with Cyber Intelligence and Incident Response teams for threat analysis.
Conduct root cause analysis of OT cybersecurity incidents.
Support incident remediation with technical analysis and recommendations.
Act as a Subject Matter Expert on OT cybersecurity issues.
Benefits
On-site work environment in Columbus, OH.
Opportunity to support a Defense Logistics Agency program.
Engagement in a critical cybersecurity role with potential for growth.
Collaboration with a team of cybersecurity experts.
Full Job Description
OCH Technologies is actively looking for an Operational Technology Threat Intelligence Analyst supporting a Defense Logistics Agency program.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
Location
On-site: Columbus, OH
Core Responsibilities & Duties
Collects, reviews, and analyzes cybersecurity threat intelligence from open-source and government intelligence reporting to identify threats impacting Operational Technology (OT) environments.
Develops and delivers actionable threat intelligence reporting and briefings to OT cybersecurity analysts and other stakeholders.
Supports content developers and cybersecurity engineers in identifying gaps in the protection, detection, and monitoring of OT systems.
Reviews and analyzes OT system logs, network events, and security alerts to identify indicators of compromise, malicious activity, and Advanced Persistent Threats (APTs).
Collaborates with Cyber Intelligence and Incident Response analysts to provide expert analysis, assessment, and reporting of OT cybersecurity threats and incidents.
Performs root cause analysis of Operational Technology cybersecurity incidents to identify attack vectors, contributing factors, and potential vulnerabilities.
Supports incident remediation efforts by providing technical analysis, recommendations, and cybersecurity expertise for OT-related incidents.
Serves as a Subject Matter Expert (SME) for Operational Technology cybersecurity issues, threats, vulnerabilities, and incident response activities.
Responsibilities may evolve over time to support team and organizational goals, but will remain consistent with the overall scope of the role.
Requirements
Minimum Qualifications
Education
Bachelor's degree (BS or BA) in a technical discipline from an accredited university
Experience
Six (6) years of relevant Information Technology (IT) experience supporting cybersecurity, network operations, systems engineering, or related technical functions.
Two (2) years of experience working with Operational Technology (OT) environments, systems, or related technologies.
Two (2) years of experience leveraging cyber threat intelligence to identify, assess, and communicate threats, vulnerabilities, and indicators of compromise.
Two (2) years of experience working with Security Information and Event Management (SIEM) platforms in a cybersecurity engineering, security operations, or incident response role.
Experience collecting, analyzing, and interpreting qualitative and quantitative data from multiple sources to support cybersecurity assessments, investigations, and decision-making.
Working knowledge of the NIST Incident Response Framework and its application to cybersecurity incident detection, analysis, containment, eradication, and recovery.
Working knowledge of the MITRE ATT&CK framework and its application to threat analysis, detection, and incident response.
Experience working with OT technologies, including Programmable Logic Controllers (PLCs), Supervisory Control and Data Acquisition (SCADA) systems, and related industrial control system technologies.
Demonstrated understanding of cybersecurity threats, vulnerabilities, attack techniques, and risk considerations specific to Operational Technology (OT) environments.
Security Clearance Requirement
Must possess an active DoD Top Secret security clearance and be eligible for an IT-I (Critical-Sensitive) security designation or Tier 5 (T5) investigation at the time of proposal submission