MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Senior Operational Technology Incident Response Engineer

GuidePoint Security

Full-time
USA
engineer
python
security
communication
automation
Apply for this position

Description

As a Senior Operational Technology (OT) Incident Response Engineer, you will lead complex OT incident-response engagements, perform deep-dive forensics, and help customers rapidly contain and eradicate threats in critical-infrastructure environments. Though embedded in GuidePoint Security’s OT Practice, you will work in close partnership with GuidePoint’s Digital Forensics & Incident Response (DFIR) practice, providing OT-specific expertise to broader IR efforts and ensuring seamless, end-to-end support for clients. Your creativity and technical depth will be essential as we continue to evolve our service offerings in a fast-changing adversarial landscape while mentoring teammates and collaborating with OT leadership to anticipate emerging threats and client needs.

Roles Requirements

  • Deliver OT IR services

    • Immediate on-site/remote IR, compromise assessments, and root-cause analysis

    • OT-focused digital forensics (PLC, historian, HMI, network captures, log review)

    • Tabletop exercises and purple-team simulations for OT environments

    • Development and validation of ICS/SCADA IR playbooks, runbooks, and detection logic

    • OT threat-hunting and proactive compromise assessments

    • Coordinate closely with DFIR counterparts to exchange findings, integrate evidence, and maintain a unified incident narrative

  • Author clear, actionable deliverables that explain technical findings, business impact, and pragmatic remediation steps for executive and technical audiences.

  • Advance the practice by contributing research, conference talks, blogs, and white papers on OT IR trends, malware, and defensive techniques.

  • Strengthen skills continuously to stay at the forefront of OT threat TTPs, tooling, and defensive controls.

  • Foster strong client relationships through collaborative communication and high-impact guidance.

  • Perform other duties as assigned.

Education, Credentials & Experience

  • Solid understanding of ISA/IEC 62443, NIST 800-82, NIST-CSF, NERC CIP, Purdue Model.

  • 3+ years dedicated to OT security. At least 2 years leading or co-leading live OT/ICS incident-response engagements.

  • 2+ years in a client-facing consulting or services role.

  • 5+ years combined experience across IT/OT networking, security monitoring, or digital forensics preferred.

  • Preferred certifications: GIAC GRID, GCIP, GCFA, GICSP, or equivalent practical expertise.

  • Demonstrated community involvement (conference speaker, white paper author, podcast guest) strongly preferred.

Knowledge, Skills & Abilities

  • Proven ability to lead engagements and provide technical oversight to analysts.

  • Deep knowledge of OT/ICS attack lifecycles, ransomware impacts on industrial processes, and relevant threat frameworks (e.g., ATT&CK for ICS).

  • Hands-on experience with OT visibility/security platforms (Dragos, Claroty, Nozomi, Forescout, Armis, Tenable OT, Fortinet OT, etc.).

  • Competence in packet analysis (Wireshark), log analytics (ELK, Splunk), memory forensics (Volatility, Rekall), and scripting for automation (Python, PowerShell, or Go).

  • Strong written communication; reports generally need minimal editing before client delivery.

  • Ability to manage multiple workstreams, meet deadlines, and calmly navigate demanding client situations.

  • Passion for continuous learning, adaptability, and contributing to a high-performance team culture.

Apply for this position
Bookmark Report

About the job

Full-time
USA
Posted 22 hours ago
engineer
python
security
communication
automation

Apply for this position

Bookmark
Report
Enhancv advertisement

30,000+
REMOTE JOBS

Unlock access to our database and
kickstart your remote career
Join Premium

Senior Operational Technology Incident Response Engineer

GuidePoint Security

Description

As a Senior Operational Technology (OT) Incident Response Engineer, you will lead complex OT incident-response engagements, perform deep-dive forensics, and help customers rapidly contain and eradicate threats in critical-infrastructure environments. Though embedded in GuidePoint Security’s OT Practice, you will work in close partnership with GuidePoint’s Digital Forensics & Incident Response (DFIR) practice, providing OT-specific expertise to broader IR efforts and ensuring seamless, end-to-end support for clients. Your creativity and technical depth will be essential as we continue to evolve our service offerings in a fast-changing adversarial landscape while mentoring teammates and collaborating with OT leadership to anticipate emerging threats and client needs.

Roles Requirements

  • Deliver OT IR services

    • Immediate on-site/remote IR, compromise assessments, and root-cause analysis

    • OT-focused digital forensics (PLC, historian, HMI, network captures, log review)

    • Tabletop exercises and purple-team simulations for OT environments

    • Development and validation of ICS/SCADA IR playbooks, runbooks, and detection logic

    • OT threat-hunting and proactive compromise assessments

    • Coordinate closely with DFIR counterparts to exchange findings, integrate evidence, and maintain a unified incident narrative

  • Author clear, actionable deliverables that explain technical findings, business impact, and pragmatic remediation steps for executive and technical audiences.

  • Advance the practice by contributing research, conference talks, blogs, and white papers on OT IR trends, malware, and defensive techniques.

  • Strengthen skills continuously to stay at the forefront of OT threat TTPs, tooling, and defensive controls.

  • Foster strong client relationships through collaborative communication and high-impact guidance.

  • Perform other duties as assigned.

Education, Credentials & Experience

  • Solid understanding of ISA/IEC 62443, NIST 800-82, NIST-CSF, NERC CIP, Purdue Model.

  • 3+ years dedicated to OT security. At least 2 years leading or co-leading live OT/ICS incident-response engagements.

  • 2+ years in a client-facing consulting or services role.

  • 5+ years combined experience across IT/OT networking, security monitoring, or digital forensics preferred.

  • Preferred certifications: GIAC GRID, GCIP, GCFA, GICSP, or equivalent practical expertise.

  • Demonstrated community involvement (conference speaker, white paper author, podcast guest) strongly preferred.

Knowledge, Skills & Abilities

  • Proven ability to lead engagements and provide technical oversight to analysts.

  • Deep knowledge of OT/ICS attack lifecycles, ransomware impacts on industrial processes, and relevant threat frameworks (e.g., ATT&CK for ICS).

  • Hands-on experience with OT visibility/security platforms (Dragos, Claroty, Nozomi, Forescout, Armis, Tenable OT, Fortinet OT, etc.).

  • Competence in packet analysis (Wireshark), log analytics (ELK, Splunk), memory forensics (Volatility, Rekall), and scripting for automation (Python, PowerShell, or Go).

  • Strong written communication; reports generally need minimal editing before client delivery.

  • Ability to manage multiple workstreams, meet deadlines, and calmly navigate demanding client situations.

  • Passion for continuous learning, adaptability, and contributing to a high-performance team culture.

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Free Job Alerts

Job Skills
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.