Lead OT SOC Architect
Jacobs · Baton Rouge, LA · 2 days ago
Information Technology$145k–$180k/yrFull-time
About the role
As the Lead OT SOC Architect at Jacobs, you will design and lead the defense of critical infrastructure by architecting and technical leadership of Jacobs' managed OT Security Operations Center. You'll own the platform, define operational standards, and lead the team protecting industrial control systems. This role involves translating deep Security Operations expertise into a defense capability tailored for OT environments, where cyber events have physical consequences.
Responsibilities
- Architect the end-to-end OT SOC platform, including SIEM, detection pipeline, data model, enrichment, and multi-tenant service architecture for a scalable, productized managed-service.
- Own the detection-engineering strategy and lifecycle, designing, building, testing, and continuously improving detection content mapped to MITRE ATT&CK for ICS, treating detections as code.
- Design SOC operational workflows: alert triage, severity routing, case management, escalation paths, and response playbooks, and codify team standards.
- Serve as the top-tier technical escalation point for all SOC issues, resolving complex and high-severity investigations.
- Lead, mentor, and develop SOC engineers and analysts, setting investigation standards, triage thresholds, and escalation criteria.
- Establish "continuous operational assurance," defining and verifying security baselines for client environments and surfacing deviations.
- Design consequence-driven detection engineering, mapping OT platform data to physical-process impact.
- Maintain the health and direction of the security technology stack, ensuring telemetry is complete and detection-ready.
- Architect secure, multi-tenant data collection and segregation aligned to Purdue Model and IEC 62443 zones.
- Partner with sales and delivery teams to embed OT SOC capabilities into new and active client programs.
- Coordinate with controls, instrumentation, and systems engineering teams to integrate OT control systems and network telemetry into the SOC.
- Produce leadership- and client-facing reporting on SOC posture, coverage, and operational assurance; support compliance evidence for OT-relevant regulations.
- Participate in and lead escalation support during high-severity incidents, including after-hours response as required.
Requirements
- Extensive experience designing, building, and operationalizing a Security Operations Center (SOC) from the ground up, including platform, detection content, workflows, and team.
- 10+ years in cybersecurity with deep Security Operations expertise, including 5+ years in a lead, architect, or senior technical role directing SOC design and operations.
- Experience applying the SOC-CMM to assess, benchmark, and mature SOC functions across people, process, and technology.
- Expert-level hands-on SIEM architecture and detection-engineering experience (Elastic strongly preferred; Splunk, Sentinel, QRadar, Stellar Cyber, or AlienVault applicable).
- Demonstrated experience leading and mentoring SOC analysts and engineers, and serving as a lead escalation point for advanced investigations and threat hunting.
- Proven detection-engineering depth: authoring, tuning, and lifecycle-managing detection content, with expertise in MITRE ATT&CK and ATT&CK for ICS.
- Strong understanding of networking fundamentals (routing, switching, VLANs, segmentation, firewall policy) and Purdue Model architectures.
- Working knowledge of Purdue Enterprise Reference Architecture and IEC 62443, or ability to rapidly apply IT-SOC expertise to OT/ICS environments.
- Experience designing SOC operational processes: alert triage, case management, incident response, escalation, and playbook development.
- Experience with security architecture and engineering: firewalls, IDS/IPS, secure remote access (VPN/ZTNA), IAM/PAM, and Zero Trust Architecture.
- Experience designing or delivering managed security services (Managed SOC, MDR/MXDR) in a productized, multi-client model.
- Strong grounding in governance frameworks: NIST CSF, NIST 800-53, CIS Controls, and OT frameworks (IEC 62443, NIST SP 800-82).
- Hands-on systems and infrastructure depth: Active Directory, Linux administration, and virtualization platforms (VMware, Hyper-V, Proxmox, Nutanix).
Preferred Qualifications
- Direct OT/ICS security experience: OT network monitoring platforms (Dragos, Claroty, Nozomi, Nomic), OT-safe operations, and industrial environments.
- IAT Level II or equivalent certification (Security+, GICSP); GIAC GRID, GCIP, or CISSP.
- Expertise in MITRE ATT&CK for ICS, including ICS technique-mapped detection content.
- Knowledge of OT/ICS protocols: Modbus, DNP3, IEC 61850, SEL, PROFINET (serial and IP-based).
- Working knowledge of NIST SP 800-82 and OT-specific regulatory context (NERC CIP, AWIA, CIRCIA).
- Hands-on experience with critical infrastructure OT control systems and ICS components (PLCs, HMIs, RTUs, controllers) and consequence analysis.
- Cisco (CCNP Security, CCNA), Fortinet NSE, or equivalent network/security certifications.
- Experience in water/wastewater, power generation, or other critical-infrastructure verticals.
- Experience with SOAR and detection automation (Swimlane, Siemplify) and threat-intelligence platforms (MISP, OpenCTI).
- Experience in 24x7 managed-services or operational support environments, and IT/OT service management (incident, change, problem management).
- Experience balancing operational SOC leadership with project-based design and assessment work.
Benefits
- Medical, dental, and vision insurance.
- Basic life insurance.
- 401(k) plan with company match.
- Paid time off and ability to purchase company stock at a discount.
- Eligible employees may enroll in a deferred compensation plan or the Executive Deferral Plan.
- Certain roles may be eligible for additional rewards, including merit increases, performance discretionary bonus, and stock.
Pay
The base salary range for this position is $145,000.00 to $180,000.00. Individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.