The Sr. Operational Technology Security Engineer will lead Sandisk’s OT security visibility and resilience program across high-technology manufacturing sites. This role is responsible for deploying and maturing OT monitoring solutions, integrating telemetry into SIEM/SOAR platforms, and ensuring cybersecurity measures do not disrupt production continuity.
What You'll Do
- Assist in defining and executing the OT security roadmap, aligning with corporate cybersecurity strategy and manufacturing uptime objectives
- Manage installation and configuration of OT monitoring platforms such as Nozomi Networks, Claroty, Dragos, Armis, ensuring proper sensor placement for maximum visibility
- Implement tools for deep packet inspection and protocol analysis (e.g., Wireshark, Zeek, Suricata) to monitor Modbus, Profinet, DNP3, OPC-UA, and other industrial protocols
- Collaborate with SOC and architecture teams to stream OT telemetry into SIEM/SOAR platforms, develop detection logic, and optimize alerting to reduce false positives
- Establish and maintain a comprehensive OT asset inventory, vulnerability management process, and configuration baselines for critical systems
- Participate in segmentation projects, firewall rule reviews, and identity separation between IT and OT environments
- Implement secure remote vendor access protocols
- Participate in creating OT-specific incident response playbooks
- Conduct tabletop exercises
- Ensure disaster recovery plans meet manufacturing continuity requirements
- Ensure adherence to NIST CSF, IEC 62443, and corporate security policies
- Prepare for internal and external audits
- Work closely with onsite IT teams and Manufacturing leadership to schedule changes, minimize production impact, and jointly achieve zero-downtime objectives
- Manage KPIs (e.g., telemetry coverage, MTTR, segmentation compliance)
- Deliver executive-level reporting on OT security posture
Technical Stack
- Nozomi Networks
- Claroty
- Dragos
- Armis
- Wireshark
- Zeek
- Suricata
- Modbus
- Profinet
- DNP3
- OPC-UA
- SIEM
- SOAR
Work Mode
This role is onsite.
