IT/OT L2 Cybersecurity Monitoring Specialist

Employer: Siemens Energy
Domain:
  • Internet - eCommerce
  • IT Hardware
  • IT Software
  • Job type:: full-time
    Job level: 1 - 5 ani experienta
    Location:
  • BUCURESTI
  • Updated at: 09-09-2026
    Remote work: On-site

    A Snapshot of Your Day

    Join us as an L2 SOC Analyst in our new Security Operations Center in Bucharest, where you will be on the front line of monitoring, detecting, and responding to threats across both enterprise IT and industrial (OT) environments - from servers, endpoints, and networks through to the ICS, PLCs, DCS, and SCADA systems that keep HVDC stations running. Imagine investigating alerts, digging into suspicious activity, and driving incidents to resolution, all while helping a greenfield SOC find its rhythm. You will work closely with fellow analysts, OT engineering, and incident response colleagues to ensure security events are caught early and handled effectively, without disrupting operational continuity or safety. Your curiosity and technical skills will be vital in keeping our HVDC Service engagement secure.

    How You'll Make an Impact

    • Monitor security events and alerts across both IT and OT environments for HVDC stations, performing triage, prioritization, and initial investigation as part of day-to-day SOC operations.
    • Conduct deeper analysis (L2) on escalated or complex alerts, determining scope and impact, distinguishing true positives from false positives, and driving incidents toward containment and resolution.
    • Investigate suspicious activity across endpoints, networks, and industrial systems, correlating data from multiple sources to reconstruct the timeline and root cause of security events.
    • Use SIEM (Splunk), EDR/XDR, NDR, and specialized OT/ICS monitoring tools to detect, analyse, and respond to threats across hybrid environments.
    • Follow and help refine SOC playbooks, runbooks, and escalation procedures, providing feedback to improve detection quality and reduce noise.
    • Support the development and tuning of detection content, correlation rules, analytics, and alerts - by flagging gaps, false positives, and opportunities for improvement.
    • Contribute to threat hunting activities, proactively searching for indicators of compromise and suspicious patterns across IT and OT data.
    • Document investigations, findings, and response actions clearly and consistently, maintaining accurate case records and contributing to knowledge-based articles.
    • Escalate major or high-impact incidents promptly with clear, well-structured handovers, and support incident response efforts through to closure.
    • Collaborate with OT engineering and operations teams to understand industrial context and ensure security actions respect operational continuity and safety requirements.
    • Stay current with emerging threats, attack techniques, and relevant frameworks (IEC 62443, NIST CSF, ISO 27001, NIS2) to continuously sharpen detection and response.

    What You Bring

    • 3+ years of hands-on cybersecurity experience, with meaningful time in a Security Operations Center (SOC), incident response, or a comparable monitoring/detection role ??? solid at an L2 (mid-level) capacity.
    • Strong IT security foundation, including endpoint, network, identity, and infrastructure security, with the ability to investigate across a broad enterprise attack surface (the primary focus of the role).
    • Practical experience with SIEM, EDR/XDR, and NDR tooling for alert triage, investigation, and threat detection ??? hands-on experience with Splunk is strongly preferred, as it will be the primary SIEM platform.
    • Working knowledge of common attack techniques, the incident lifecycle, and log analysis across operating systems (Windows and Linux) and network traffic.
    • Exposure to or interest in ICS/OT environments (PLC, HMI, SCADA, DCS, industrial networking) ??? direct OT experience or familiarity with HVDC, power transmission, or grid environments is a strong advantage.
    • Awareness of industrial communication protocols such as Modbus, PROFINET, DNP3, IEC 60870-5-104, OPC UA, and EtherNet/IP is a plus.
    • Familiarity with cybersecurity frameworks and standards such as IEC 62443, NIST CSF, ISO 27001, and NIS2.
    • Strong analytical and problem-solving skills, with attention to detail and the ability to stay focused under pressure during active incidents.
    • Good communication skills, able to document findings clearly and hand over incidents effectively to peers and, where needed, OT engineering teams.
    • Fluent English; German is a plus.

    About the Team

    Our Grid Technology division enables a reliable, sustainable, and digital grid. Siemens Energy offers an outstanding range and solutions in HVDC transmission, grid stabilization and storage, high voltage switchgears and transformers, and technology related to digital grid technology.

    Who is Siemens Energy?

    At Siemens Energy, we are more than just an energy technology company. We meet the growing energy demand across 90+ countries while ensuring our climate is protected. With 100,000 dedicated employees, we not only generate electricity for over 16% of the global community, but we're also using our technology to help protect people and the environment.

    Our cross-border team is committed to making sustainable, reliable, and affordable energy a reality by pushing the boundaries of what is possible. We uphold a 150-year legacy of innovation that encourages our search for people who will support our focus on decarbonization, new technologies, and energy transformation.

    Find out how you can make a difference at Siemens Energy: https://www.siemens-energy.com/employeevideo

    Our Office

    Siemens Energy's location in One Cotroceni Park is more than just an office space - it's a hub for a vibrant and growing community. Nestled in the heart of Bucharest, this urban development is the perfect place to work, surrounded by green spaces, shopping destinations, and everything the city center has to offer. And with the Academia Militara subway station just a 3-minute walk away, getting around the city has never been easier.

    Our Commitment to Diversity

    Lucky for us, we are not all the same. Through diversity, we generate power. We run on inclusion and our combined creative energy is motivated by over 130 nationalities. Siemens Energy celebrates character ??? no matter what ethnic background, gender, age, religion, identity, or disability. We energize society, all of society, and we do not discriminate based on our differences.

    Rewards/ Benefits

    • Your lunch with SE meal tickets
    • Keep your brain fit with our trainings
    • Special for books lovers - Bookster
    • Stay safe and healthy with our medical subscription
    • Think about your future too with Private Pension Pilon III
    • Look after yourself with our Wellbeing Initiatives

    #LI-CG1

    #LI-Hybrid


    Job-uri similare care te-ar putea interesa:

    Cybersecurity Monitoring Lead

    BUCURESTI,

    Industrial Cybersecurity Risk Analyst

    BUCURESTI,

    OT Security Analyst - Operational Technology Cybersecurity

    BUCURESTI,

    Vezi job-uri similare ( 196 )