Assistant Manager - SOC Engineer (OT Security)

Renault Nissan Technology & Business Centre India

Job Summary

    We are seeking a SOC Engineer specialized in Operational Technology (OT) environments to join the Cybersecurity team within IS/IT. The role focuses on supporting the deployment, configuration, administration, and operational management of security solutions across both IT and OT landscapes, with a strong emphasis on industrial environments.

    The candidate will contribute to strengthening the company’s security posture by actively participating in security tool provisioning, platform configuration, and day-to-day SOC operations, ensuring visibility, detection, and response capabilities across production and manufacturing systems.

Key Responsibilities

Provisioning & Deployment:-

  • Support the deployment and onboarding of cybersecurity tools across IT and OT environments.
  • Participate in provisioning activities, including agent deployment, system integration, and infrastructure configuration.
  • Assist in integrating security tooling with core platforms such as ServiceNow, Microsoft ecosystem, and SIEM solutions.
  • Collaborate with infrastructure, network, and OT teams to ensure proper rollout of security controls in industrial environments.

Configuration & Administration

  • Configure and maintain endpoint security and monitoring solutions.
  • Manage policies, rules, and detection use cases within security tools.
  • Ensure proper asset onboarding, classification, and visibility, especially in OT networks.
  • Maintain documentation of configurations, procedures, and architecture using Confluence.
  • Support continuous improvement initiatives related to detection, automation, and response capabilities.

SOC Operations

  • Monitor and analyze security events and alerts across IT and OT environments.
  • Investigate incidents, perform triage, and coordinate response activities.
  • Contribute to use case tuning and false positive reduction.
  • Collaborate with the SOC team to improve detection coverage and response efficiency.
  • Participate in incident response processes, including containment, eradication, and recovery.
  • Support vulnerability management and endpoint hygiene activities.

Collaboration & Tools

  • Work closely with Cybersecurity, IT Operations, OT teams, and Engineering.
  • Use ServiceNow for incident and request management.
  • Use Jira for task tracking and project activities.
  • Use Confluence for documentation and knowledge sharing.
  • Operate within a Microsoft-centric environment (Defender ecosystem, Azure, Active Directory, etc.).

Required Skills And Experience

Must-Have

  • Hands-on experience with Tanium (deployment, administration, or operations).
  • Hands-on experience with CrowdStrike (endpoint protection, detection, and response).
  • Experience in cybersecurity operations (SOC or equivalent).
  • Understanding of OT environments and industrial systems (manufacturing, SCADA, ICS).
  • Knowledge of endpoint security, asset visibility, and incident response processes.
  • Familiarity with ticketing and workflow tools such as ServiceNow.

Nice-to-Have

  • Experience with SOTI MobiControl (device management, especially in industrial/mobile environments).
  • Experience with Cisco ISE (network access control and segmentation).
  • Experience with Octoplant (industrial asset management and OT environments).
  • Exposure to SIEM platforms and detection engineering.
  • Knowledge of IT/OT network segmentation principles and zero-trust concepts.

Soft Skills

  • Strong analytical and problem-solving capabilities.
  • Ability to work in cross-functional and international teams.
  • Proactive mindset with a focus on continuous improvement.
  • Clear communication skills (technical and non-technical stakeholders).
  • Ability to work in structured environments with processes and documentation.

Education and Background

  • Degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • Relevant certifications (e.g., Security+, CISSP, GIAC, or vendor-specific) are a plus.

Location and Reporting

  • Part of the IS/IT Cyber security organización within RNTBCI / HORSE Team
  • Reporting in to SOC / Cyber Operations leadership.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.