Senior OT Threat Hunter and Detection SME
Atos
Remote
With more than 54,000 employees serving over 4,500 clients across 54 countries, Atos helps modernize core IT systems, accelerate cloud and data transformation, strengthen cybersecurity, and deliver secure digital workplace environments to support its clients, its employees and society. Atos also provides consulting and advisory services through its Atos Amplify brand.
A trusted partner in operating complex and mission-critical environments, Atos supports organizations across highly regulated and sovereign contexts.
About Atos Group
Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. €7.2 billion (at the go-forward perimeter), operating in 54 countries under two brands - Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris.
Function Cybersecurity – OT Threat Detection, Hunting and Incident Investigation
Location Bengaluru/Mumbai | Hybrid, with travel to customer and industrial sites as required
Experience 6–10 years
Role Overview
We are seeking an experienced OT Threat Hunter and Detection Engineer to identify suspicious activity, investigate anomalies and improve threat-detection capabilities across Operational Technology and Industrial Control System environments.
The role will focus on analysing OT network traffic, security alerts, logs, asset inventories and communication baselines to identify unauthorised activity, lateral movement, protocol misuse and potential signs of compromise.
The specialist will work closely with OT SOC teams, plant engineers, incident-response teams and security stakeholders to develop threat-hunting hypotheses, detection use cases, investigation playbooks and practical containment recommendations.
Key Responsibilities
- OT Threat Hunting
- Conduct proactive threat hunting across OT and ICS environments.
- Develop threat-hunting hypotheses based on threat intelligence, attack techniques, asset criticality and known vulnerabilities.
- Identify unauthorised assets, abnormal communications, unusual access patterns, protocol misuse and suspicious lateral movement.
- Investigate activity affecting HMIs, engineering workstations, historians, domain infrastructure, remote-access systems and industrial network zones.
- Analyse packet captures, network flows, authentication logs, firewall logs, endpoint telemetry and OT security-monitoring data.
- Identify indicators of compromise and suspicious behaviour associated with industrial threat actors.
- Map findings to MITRE ATT&CK for ICS and MITRE ATT&CK Enterprise where applicable. Detection Engineering.
- Develop and validate OT-specific detection use cases and analytics.
- Create investigation procedures, hunting queries, alert-triage guides and response playbooks.
- Review existing OT monitoring coverage and identify detection gaps.
- Tune security alerts to improve detection quality and reduce unnecessary false positives.
- Establish baseline communication patterns for critical industrial assets and network zones.
- Develop detection logic for o Unauthorised asset connections o Unexpected protocol usage o New or abnormal communication paths o Suspicious remote access o Credential misuse o Lateral movement o Engineering-workstation anomalies o Changes to PLC or controller communication
- Support purple-team exercises by validating whether simulated attack activity is detected and investigated effectively. Alert Investigation and Incident Support
- Analyse and triage alerts generated by OT IDS, NDR, SIEM and endpoint-security platforms.
- Correlate alerts across IT and OT systems to identify potential attack paths.
- Conduct initial compromise assessments and support incident scoping.
- Gather, preserve and document relevant investigation evidence.
- Work with incident-response teams to recommend containment, monitoring and recovery actions.
- Support post-incident reviews and convert lessons learned into improved detection content.
- Escalate critical findings in accordance with agreed incident and operational procedures. OT Visibility and Monitoring
- Review OT asset inventories and identify unknown, unmanaged or unauthorised devices.
- Assess the quality and coverage of network sensors, packet collection and log sources.
- Validate asset classification, communication baselines and criticality information.
- Identify monitoring gaps across industrial zones and conduits.
- Support the onboarding of relevant OT data sources into SIEM, SOC and detection platforms.
- Work with plant teams to ensure monitoring activities do not affect operational availability
- Reporting and Stakeholder Engagement
- Prepare clear threat-hunting and investigation reports containing o Investigation scope o Hunting hypothesis o Data sources reviewed o Findings and supporting evidence o Affected ass
Atos is a recognized leader in its industry across Environment, Social and Governance (ESG) criteria. Find out more on our CSR commitment.
Choose your future. Choose Atos.