OT Security Consultant (Splunk) Job at Match Point Solutions, Houston, TX

bnVBS2c0anZjS1h4Qk9ad1QyYWVBRXNud3c9PQ==
  • Match Point Solutions
  • Houston, TX

Job Description

MatchPoint Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US . We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India . Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise.

We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!

Job : OT Security Consultant (Splunk)

Location : Houston, TX - onsite

Duration : 12 Months

Rate : $80 to $85 per hour

  • Embedded Operational Technology (OT) Cybersecurity Consultant to lead Splunk detection engineering for a customer Security Operations Center (SOC).

  • This hands-on role requires production SOC experience, an understanding of how OT environments differ from traditional IT, and advanced Splunk expertise.
  • The consultant will evaluate current use cases, improve correlation and alert quality, develop new detection content, coach analysts, and create clear documentation that enables the team to sustain the work independently.
  • This is a full-time role dedicated to one customer for approximately 12 months, with a potential extension.
  • Business hours align to US Central time, with no on-call or 24x7 monitoring duties.
  • Remote, hybrid, or on-site presence will be confirmed with the customer. Daily participation in stand-ups and shared team channels is expected.

Responsibilities:

  • Catalogue and assess existing Splunk correlation searches, dashboards, and use cases against an agreed baseline, identifying coverage gaps and noisy rules.

  • Co-author a prioritized roadmap with the Nozomi lead during the initial phase of the engagement.

  • Design, test, and refine Search Processing Language (SPL) correlation searches, notable event logic, and detection content tailored to OT data sources.

  • Recommend and implement approved adjustments to thresholds and suppression logic to reduce false positives, and track the impact of each change.

  • Review OT log sources, parsing, normalization, field extraction, and enrichment so detections are based on reliable data.

  • Partner with the Nozomi lead to normalize, enrich, and correlate Nozomi alerts and asset data in Splunk.

  • Coach SOC analysts using real investigations and teach effective pivots across OT and IT data.

  • Create a runbook and tuning rationale for each new or materially changed use case, and teach analysts to build and tune searches independently.

  • Provide monthly reporting on changes, rationale, alert volume, false positive rate, and coverage improvement.

  • Coordinate with customer teams, implementation partners, change control, and related Splunk workstreams so improvements are delivered smoothly.

Required Qualifications

  • Significant cybersecurity experience, including hands-on SOC work involving triage, investigation, and detection engineering in a production environment; approximately five or more years of overall experience is preferred.
  • Experience with OT or Industrial Control System (ICS) security monitoring, ideally in utilities, energy, or critical infrastructure.
  • Advanced hands-on Splunk skills, including SPL, correlation search development, and tuning in a production SOC environment.
  • Practical knowledge of detection
  • engineering methods and MITRE ATT&CK, with working familiarity with ATT&CK for ICS.
  • Understanding of OT network architecture, industrial protocols, and the Purdue model.
  • Strong written and verbal communication skills, with experience coaching analysts and creating clear technical documentation.

Preferred Qualifications

Experience supporting an electric utility or other critical infrastructure environment, including familiarity with applicable regulatory requirements.

Working knowledge of IEC 62443.

Experience integrating Nozomi Networks or another OT monitoring platform with Splunk.

Experience with risk-based alerting, security orchestration, automation and response, or detection-as-code practices.

Prior consulting or embedded advisory experience. Certifications

  • Splunk Core Certified Power User or Admin, Splunk Enterprise Security Certified Admin, GICSP, GCIA, GCDA, GCIH, CISSP, or equivalent certifications are helpful. Certifications support, but do not replace, hands-on SOC and OT experience. Tools and Technologies:

  • Splunk Enterprise and Splunk Enterprise Security

  • Search Processing Language (SPL)

  • Correlation searches and notable event workflows

  • Nozomi Networks or another OT monitoring platform

  • MITRE ATT&CK and ATT&CK for ICS

MatchPoint Solutions provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Job Tags

Hourly pay, Full time, For contractors, Local area, Remote work

Similar Jobs

GreenSlate

Benefits Data Analyst Job at GreenSlate

 ...JOB BRIEF The Benefits Data Analyst will be responsible for analyzing, coordinating, and optimizing the administration of employee benefits...  ...leave, and disability benefit compliance. This role is remote within the United States. WHO WE ARE GreenSlate is the... 

BEST ONE TIRE & SERVICE

Delivery Driver Job at BEST ONE TIRE & SERVICE

Description: Delivery Driver | Best-One Tire & Service | Oak Grove Join the Best-One Team! Best-One Tire & Service in Oak Grove is looking for a Delivery Driver who can be a dependable driver to join our team. Responsibilities include delivering orders safely... 

Cloud Analytics Technologies LLC

Workday Security Consultant Job at Cloud Analytics Technologies LLC

 ...Job Description: We are seeking an experienced Workday Security Consultant to join our Workday team. The ideal candidate will have expertise in designing, implementing, and managing Workday security frameworks to ensure compliance, data integrity, and secure access... 

ICON plc

Remote CRA II Job at ICON plc

 ...CRA II Greece Remote ICON plc is a world-leading healthcare intelligence and clinical research organization. Were proud to foster an inclusive environment driving innovation and excellence, and we welcome you to join us on our mission to shape the future of clinical... 

Cisco Equipment Rentals LLC

Yard Technician Job at Cisco Equipment Rentals LLC

 ...backed by investors who represent leading figures within the equipment rental industry. Our rental department is seeking a yard Technician with experience in operating heavy equipment safely Requirements: Skills & Qualifications: Personal skills must include mechanical...