{"id":1139448,"url":"https://alion.io/job/fluence-energy-security-operation-supervisor-ot-specialization","title":"Security Operation Supervisor (OT Specialization)","company":{"id":58575,"name":"Fluence Energy","domain":"fluenceenergy.com","url":"https://alion.io/company/fluence-energy","size_band":"1001-5000","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Workday","truth_index":{"grade":"B","score":83,"open_postings":11,"ghost_share":0,"stale_share":0.636,"repost_share":0.091,"time_to_fill_p50_days":34,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":6,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Commander.js","optional":false},{"name":"GCP","optional":false},{"name":"ISO 27001","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Service Desk","optional":false},{"name":"SIEM","optional":false},{"name":"Supervision","optional":false},{"name":"JavaScript","optional":true},{"name":"Node JS","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-09-23T10:04:59Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-20T18:16:25Z","board_verified":false,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are transforming the way we power our world for a more sustainable future. For more information, please visit fluenceenergy.com.\nJob Description:\nRole Overview\nThe Security Operations Supervisor (OT Specialization) leads the day-to-day work of a team of security operations analysts and serves as the senior technical escalation point for threats affecting both our corporate IT estate and our operational technology environments, including battery energy storage sites and the systems that support them. Based in Bengaluru, this role supervises cybersecurity analysts, quality of triage and investigation, and the professional growth of the analyst team, while personally handling complex detection, hunting and incident response work. The Supervisor partners closely with the global cybersecurity team, IT infrastructure, service desk, service and operations engineering, product security and, where required, customers and external incident response partners. The ideal candidate has hands-on security operations depth, real exposure to industrial control system and OT environments, and a genuine interest in coaching analysts and improving how a security operations team works. Key tools and platforms include Microsoft Sentinel and Defender, endpoint detection and response, SOAR and automation platforms, OT monitoring technologies, threat intelligence services and IT service management tooling.\nKey Responsibilities\nSecurity Monitoring, Detection and Incident Response\nDirect network monitoring and intrusion detection analysis using computer network defense tools such as intrusion detection and prevention systems, firewalls, proxies and host-based security systems.\nOversee log-based, identity-based and endpoint-based threat detection to identify and contain threats originating from multiple sources.\nDrive cloud-centric detection coverage for the cloud environments and services the organization uses, including Azure, AWS and GCP workloads.\nCorrelate activity across assets (endpoint, network, identity, applications) and environments (on-premises, cloud, OT) to identify patterns of anomalous activity, attacks and unauthorized use.\nReview alerts and sensor data escalated by analysts, validate findings and produce formal, technical incident reports for technical and management audiences.\nAct as incident commander or senior responder for high-severity incidents, coordinating containment, eradication and recovery activities across teams and time zones.\nProvide users and internal stakeholders with incident response support, including mitigating actions to contain activity and facilitating forensic analysis where necessary.\nWork with threat intelligence and threat-hunting teams, translating intelligence into detection content, hunting hypotheses and response playbooks.\nResearch emerging threats, adversary tradecraft and vulnerabilities to support the identification and classification of incidents.\nSupport the creation and testing of business continuity and disaster recovery plans, including running exercises, publishing results and driving remediation of deficiencies.\nPerform security standards testing against systems before implementation to confirm they meet security requirements.\nOperational Technology (OT) Security\nOwn monitoring, detection and response for operational technology environments, including battery energy storage sites, site controllers, historians, engineering workstations and remote access paths used to support them.\nTune and maintain OT-specific detection content, including rules for unauthorized configuration changes, unexpected protocol use, rogue devices and abnormal control traffic.\nOnboard and validate telemetry from OT monitoring and asset discovery platforms into the SIEM, and maintain accurate OT asset and network context for responders.\nMaintain and exercise OT incident response playbooks that account for safety, availability and physical process constraints, including scenarios where containment actions cannot disrupt energy delivery.\nMonitor and review privileged and vendor remote access into OT networks, escalating misuse or policy deviations.\nWork with service and operations engineering, product teams and site personnel to validate alerts, confirm expected activity and agree on safe response actions.\nTrack OT vulnerabilities and advisories, assess applicability to deployed systems and coordinate risk-based mitigation with engineering owners.\nSupport alignment of OT monitoring and response practices with recognized frameworks and standards such as IEC 62443, NIST SP 800-82 and applicable customer or regulatory requirements.\nSupervision and Development of Analysts\nSupervise a team of security operations analysts, including day-to-day task assignment, shift and on-call scheduling, workload balancing and handover quality across regions.\nSet clear performance expectations, conduct regular one-on-ones, provide continuous feedback and contribute to goal setting, performance reviews and career development plans.\nCoach analysts on investigation technique, evidence handling, documentation quality and escalation judgment, and review a sample of closed cases for accuracy and completeness.\nBuild and maintain a skills matrix and training path for the team, covering IT, cloud and OT monitoring, and identify gaps to be closed through training or hiring.\nDeliver regular internal training sessions on intrusion detection and prevention, incident response procedures, threat intelligence analysis, log analysis and OT fundamentals.\nRun tabletop exercises, purple team activities and detection drills to test analyst readiness and improve response quality.\nParticipate in recruiting, interviewing and onboarding of new analysts, including mentoring during ramp-up.\nManage the relationship with managed detection and response or outsourced monitoring partners, reviewing their output quality and holding them to agreed service levels.\nFoster a culture of ownership, knowledge sharing and psychological safety, so analysts raise concerns early and learn from incidents without blame.\nDetection Engineering, Automation and Tooling\nWork with security information and event management (SIEM) platforms to manage and tune the system, create and maintain detection content and actively watch for alerts.\nOwn the detection engineering backlog, from use case definition through rule development, testing, documentation and measurement of effectiveness.\nDrive down false positives and alert fatigue through tuning, enrichment and suppression logic, with measurable targets reported to leadership.\nDesign and maintain security orchestration, automation and response (SOAR) playbooks that automate repetitive triage, enrichment and containment tasks.\nEnsure log source coverage and data quality across IT, cloud and OT, identifying blind spots and driving onboarding of missing telemetry.\nMap detection coverage to MITRE ATT&CK for Enterprise and ATT&CK for ICS, and use the results to prioritize new content.\nProcess, Reporting and Continuous Improvement\nMaintain standard operating procedures, runbooks and escalation matrices for the security operations team, and keep them current as tooling and the environment change.\nTrack and report operational metrics such as alert volume, time to triage, time to contain, escalation accuracy and detection coverage, with regular reporting to cybersecurity leadership.\nLead post-incident reviews, capture lessons learned and drive corrective actions to closure with the responsible owners.\nManage projects to implement new security tooling or to develop new security policies and procedures, including scope, timeline and stakeholder communication.\nApply change management practices when introducing new controls or processes, including change plans and management of business impact.\nSupport audit, compliance and customer assurance activities by providing evidence of monitoring, detection and response capability.\nRequired Qualifications\nBachelor's degree in computer science, information security, cybersecurity, engineering or a related field, or equivalent practical experience.\nMinimum 6 years of experience in cybersecurity, with at least 4 years in a security operations, incident response or threat detection role.\nMinimum 2 years of experience supervising, leading or mentoring analysts, including shift coordination, quality review and coaching. Formal people management experience is welcome but a strong technical lead background will also be considered.\nMinimum 2 years of hands-on experience with industrial control system or operational technology environments, such as battery energy storage, power generation, utilities or manufacturing.\nDemonstrated experience with SIEM platforms, including writing and tuning detection content and building dashboards and reports. Experience with Microsoft Sentinel and KQL is strongly preferred.\nPractical experience with endpoint detection and response, network detection, identity protection and email security tooling.\nWorking knowledge of cloud security concepts and the security capabilities of major cloud platforms such as Azure, AWS and GCP, including detection of cloud-native attack techniques.\nFamiliarity with industrial protocols and OT architecture concepts, such as Modbus, DNP3, IEC 61850, OPC and the Purdue model, and the ability to read a basic network or one-line diagram.\nExperience with risk assessment, incident response and security audits.\nExperience with regulatory compliance and information security management frameworks such as ISO 27001, NIST Cybersecurity Framework, NIST SP 800-53 or COBIT.\nAdvanced analytical, problem-solving and troubleshooting capabilities, with sound judgment under time pressure.\nStrong written and verbal communication skills in English, with the ability to write clear incident reports and explain technical risk to non-technical stakeholders.\nWillingness to participate in an on-call rotation and to support incidents outside standard business hours when required.\nPreferred Qualifications\nMaster's degree in cybersecurity, information security or a related technical field.\nOT or ICS security certification such as GICSP, GRID or GCIP.\nSecurity operations or incident response certification such as GCIA, GCIH, GCFA or Microsoft SC-200.\nManagement or governance certification such as CISSP, CISM or CISA.\nExperience with OT monitoring and asset visibility platforms such as Dragos, Claroty, Nozomi or Tenable OT.\nExperience building SOAR automation, for example with Logic Apps, and scripting in PowerShell or Python.\nFamiliarity with DevOps security practices and the ability to integrate security checks into a DevOps pipeline.\nExperience supporting a follow-the-sun or globally distributed security operations model.\nDigital forensics or malware analysis experience.\nExposure to the energy storage, renewable energy or utility sector, and to customer-facing security obligations in service agreements.\nKey Competencies\nTeam leadership and analyst development, including coaching, feedback and workload management.\nThreat detection and incident response judgment, with strong decision-making that weighs the relative costs and benefits of possible actions and selects the most appropriate one.\nOT and safety awareness, understanding where availability and physical process safety constrain security actions.\nTechnical breadth across firewalls, intrusion detection and prevention systems, SIEM, SOAR, endpoint and identity security tooling.\nInfluence and stakeholder management, with the ability to shift the opinions, plans or behavior of teams outside direct authority.\nProcess discipline and continuous impr...","description_format":"text","description_chars":13646,"description_truncated":true,"requirements":{"experience_years_min":6,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Energy Storage","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-23T10:04:59Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":34,"reasons":["conf:4","win:early","comp:brand"],"computed_at":"2026-09-23T14:39:59Z"},"pay":null,"html_url":"https://alion.io/job/fluence-energy-security-operation-supervisor-ot-specialization","json_url":"https://alion.io/job/fluence-energy-security-operation-supervisor-ot-specialization.json","meta":{"generated_at":"2026-09-23T14:39:59Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}