SME - IT security
India
Job Description
SME - IT security
Bengaluru, Karnataka

Job Summary

Operational Network Security Consultant

OT Security – Consultant (L3)

The candidate for the L3 role should have minimum 12+ years of experience in OT/ICS security with min 8 years exp in OT/IOT sector with different verticals and 4 years in handling cyber security in OT landscape. The candidate is expected to have zeal to learn new technologies in dynamic space and actively contribute to business growth along with personal growth.

Key Responsibilities

Armis / threat detection

Following would be the high-level responsibilities he/she is expected to deliver:

Responsibilities:

• Reviewing ICS network architectures and determining if good practices are being followed (e.g., the “zones & conduits” concept, proper network segmentation, use of Industrial DMZ, etc.); and providing recommendations to comply with cybersecurity framework like NIST/ IEC etc

• Design, Consult and implement various security solutions like threat detection, remote secure authorized access in OT Landscape as per best practices.

• Good experience with integrations between 3rd party solutions like SOC, ITSM, AD etc.

• Proof of Concept (POC) and technical analysis on new solutions.

• Reviewing security products utilized (e.g., firewalls, IDS, IPS) and determining if they are configured properly as per the architecture data flow and provide recommendations.

• Reviewing & configuring security policies, security events, assessing network monitoring capabilities and packet captures to identify security threats as per best practices.

• Reviewing security policies, plans, and procedures and providing recommendations to comply with applicable cybersecurity framework as per best practices.

• Reviewing technical, administrative, and physical security controls and providing recommendations to mitigate the identified security risks.

• Performing vulnerability and risk assessments using the various tools like Claroty, Armis, Nozomi tool for manufacturing and critical infrastructure environments to identify security risks and threats (e.g., unsecure remote access points, suspicious remote connections, unauthorized devices on the network, etc.) and providing recommendation to remediate the identified issues.

• Create detailed diagrams (e.g., network, cabling, server, rack, logical architecture, etc.), procedures, and plans (e.g., implementation, SAT, mitigation, etc.) as needed to support projects

• Accessing inventory of client’s hardware & software assets and assessing those assets for security vulnerabilities, obsolescence, and other risks

• Front ending and driving discussions with customers and provide consultations and recommendations

Skill Requirements

Armis / threat detection

Required Experience

• A minimum of five (5) years “hands on” experience in designing and implementing ICS/OT network architectures and ICS process controls.

• A minimum of three (3) years “hands on” experience in designing and implementing ICS Security controls and solutions in different verticals

• Must have worked on various OT Native OEMs like Claroty, Armis, Nozomi, Microsoft Defender and should have experience with atleast 2 of them while designing, implementing and managing that solution.

• Must have worked on few OEMs for OT services like Forescout, Fortinet, Palo Alto, Cisco and should have experience with atleast 1 of them while designing, implementing, and managing that solution.

• Strong understanding of cybersecurity frameworks for ICS/OT environments (ISA-99/IEC 62443, NIST SP 800-82, CIS, etc.)

• Understanding of the ICS/OT network communication protocols (e.g., Ethernet/IP, CIP, Modbus, OPC, etc.) and industrial networking topologies (e.g., ring, star, etc.)

• Demonstrated technical skills to analyze, design, and deploy complex Ethernet/IP architectures and communication technologies.

• Ability to perform vulnerability / penetration testing in ICS/OT environment, and/or threat hunting.

• Prior experience Control System Engineer or SCADA Engineer working in manufacturing environments or power generation facilities.

• Industry experience in Food and Beverage,Chemical, Pharma, Semiconductor, Water & Wastewater, Refining, Pulp and Paper, Oil/Gas Pipeline, Power Generation, Electrical Transmission & Distribution, Material Handling, and/or Packaging

• Strong understanding of the ICS Network architecture and data flows in the OT environment.

• Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP800-53) Networking certifications (e.g., CCNA, CCNP, JNCIP-ENT, etc.), Cybersecurity certification (e.g., CEH, CISA, CISM, CCSP, etc.) or OT/ ICS security certification (e.g. GICSP, IEC-62443 etc.) will give an edge to the candidate.

• Degree in Engineering (Electrical, Mechanical, Chemical, Computer Science, or similar scientific / technical field.

• Strong presentation and communication skills 

Other Requirements

Armis / threat detection

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.