Lead Consultant - Incident Response (CPX)
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
Overview As a Principal Consultant – Incident Response, you live and breathe blue team operations. Your technical expertise in endpoint and network threat detection and defence is complemented by your integrity and passion for cyber security and technology in general.
Key Skills for This Role
Full Job Posting
Overview
As a Lead Incident Response – OT Cyber Security, you bring deep expertise in industrial control systems and a strong foundation in enterprise security to lead complex incident response engagements across OT and IT environments.
The role involves conducting threat hunting (across IT and OT), forensic investigations (across IT and OT), and industrial protocol analysis to support safe and effective incident containment and recovery, particularly within critical operational environments.
In addition, the role includes delivering technical reports and executive briefings, contributing to incident response playbooks, and supporting the continuous improvement of OT cybersecurity services.
Key Responsibilities :-
Act as the technical lead for IT and OT/ICS incident response engagements and support customers across industrial sectors (energy, utilities, manufacturing, oil & gas, transport).
Independently execute assigned tasks following an initial onboarding period, demonstrating accountability and technical ownership.
Conduct proactive threat hunting across IT and OT/ICS environments, including SCADA servers, historians, HMIs, and engineering workstations.
Perform host-based and network-based forensic investigations across OT and IT environments (Windows HMIs/EWS, Linux-based SCADA systems, enterprise endpoints).
Analyze industrial network traffic and protocols (e.g., Modbus, DNP3, EtherNet/IP, OPC-UA/DA, PROFINET, IEC 61850) to determine attack scope and root cause.
Lead and support digital forensic investigations (IT and OT), including evidence acquisition, artifact analysis, and timeline reconstruction for IT and OT environments.
Assess IT/OT segmentation, Purdue Model alignment, and DMZ configurations during incident scoping and post-incident reviews.
Coordinate with operations, engineering, and safety teams to implement containment and recovery actions without impacting critical physical processes.
Provide expert guidance on OT security hardening, ICS architecture improvements, and defensive control enhancements.
Contribute to OT incident response playbooks, procedures, and documentation, driving continuous service improvement.
Produce detailed technical reports and executive briefings, effectively communicating findings to both technical and non-technical stakeholders.
Demonstrate thought leadership through knowledge sharing, blog publication, and participation in industry forums.
Support on-call incident response activities, including cross-time-zone engagements.
Mentor junior team members and contribute to a collaborative, high-performance team culture.
Strong understanding of OT/ICS architectures and the Purdue Reference Model (Levels 0–4).
Strong understand of IT incident response life cycle.
Hands-on experience with industrial platforms, including PLCs (Siemens, Allen-Bradley, Schneider), HMIs, DCS, RTUs, and SCADA systems.
Deep knowledge of industrial communication protocols, including Modbus TCP/RTU, DNP3, IEC 61850/60870, EtherNet/IP, OPC-UA/DA, PROFINET, and BACnet.
Familiarity with Safety Instrumented Systems (SIS) and safety constraints during incident response operations.
Understanding of OT asset lifecycle challenges, including patching limitations, legacy systems, and operational constraints.
Technical Skills : -
Strong working knowledge of the MITRE ATT&CK for ICS framework.
Solid understanding of enterprise networking concepts, TCP/IP, and network architectures.
Proficiency in host-based forensics across Windows and Linux systems.
Working knowledge of Active Directory, authentication systems, and Windows event logging.
Experience
with network analysis tools (e.g., Wireshark, Zeek, Suricata, RITA).
Ability to perform log analysis across SIEM platforms and OT security monitoring solutions (e.g., Claroty, Dragos, Nozomi, Tenable OT).
Basic understanding of malware analysis techniques, including both static and dynamic approaches, with exposure to OT-targeted malware.
Strong organizational and prioritization skills, with the ability to work independently in high-pressure environments.
Excellent technical report writing and communication skills, delivering both detailed analysis and executive-level summaries.
Skills/Certifications (Technical & Non-Technical) : -
GIAC Global Industrial Cyber Security Professional (GICSP) — primary OT certification requirement
GIAC Response and Industrial Defense (GRID) — highly desirable
CREST Registered Intrusion Analyst (CRIA) or equivalent — desirable
GIAC Certified in a minimum of one IT discipline: GCIH, GCFE, GCFA, GNFA, GCIA, GDAT, or equivalent
Any other certification with proven relevance to incident response and OT cybersecurity
Education : -
Bachelor’s degree in computer science or engineering is desirable but not mandatory
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at CPX
Lead Analyst - Sector Domain (OT Cybersecurity)
Abu Dhabi, UAE
Overview OT Lead Analyst Sector Domain is the liaison officer of the sector in OT SOC and vice versa. Communicate activities, decision, etc. to the sector stakeholders. Responsibilities Hold and provide all sector speci
Senior Manager - Alliances and Partnerships (CPX)
Abu Dhabi, UAE
Overview About the Role The Senior Manager – Partnerships & Alliances is responsible for activating, scaling, and monetising CPX’s strategic partner ecosystem to drive measurable revenue, pipeline, and market differentia
Manager - OT Cybersecurity (CPX)
Abu Dhabi, UAE
Overview Securing operational technology (OT), industrial IoT (IIoT), and IoT environments across multiple critical infrastructure sectors, including oil and gas, utilities, manufacturing, mining, and more. Provide consu
Lead Specialist - Account Management (CPX)
Abu Dhabi, UAE
Overview Role is to act as the translation layer between an organization’s cyber security needs, business strategy and technology. In practice, this means that we work closely with our clients to assess their needs, char
Specialist - Business Operations (Client Administration)
Abu Dhabi, UAE
Overview CPX is seeking a data-driven and collaborative Sales Enablement Specialist to elevate the productivity and effectiveness of our sales organization. This individual will play a pivotal role in ensuring sales read
SOC Engineer (Azure)
Abu Dhabi, UAE
Overview The Azure Security Engineer will support Security Operations Center (SOC) functions by securing, monitoring, and responding to threats across Microsoft Azure and hybrid environments. This role focuses on cloud s
Manager - Threat Intelligence
Abu Dhabi, UAE
Job Purpose The Threat Intelligence Manager is an integral part of the Threat Intelligence Center. As the Threat Intelligence Manager, you will be leading a team of highly skilled Cyber Threat Intelligence Analysts to en
OT Security Solution Sales Lead
Abu Dhabi, UAE
Overview This role operates as a quota-carrying OT Security Solution Sales Specialist, acting as a specialist overlay to Account Managers who own the customer relationship. The Specialist partners closely with CPX Accoun
Lead Analyst - Sector Domain (OT Cybersecurity)
Abu Dhabi, UAE
Senior Manager - Alliances and Partnerships (CPX)
Abu Dhabi, UAE
Manager - OT Cybersecurity (CPX)
Abu Dhabi, UAE
Lead Specialist - Account Management (CPX)
Abu Dhabi, UAE
Specialist - Business Operations (Client Administration)
Abu Dhabi, UAE
SOC Engineer (Azure)
Abu Dhabi, UAE
Manager - Threat Intelligence
Abu Dhabi, UAE
OT Security Solution Sales Lead
Abu Dhabi, UAE