IT Security Analyst I
Job Description
Join the Security Operations Center to monitor, detect, and respond to security events across enterprise IT and OT/ICS environments in a manufacturing setting.
- Monitor security alerts and events using SIEM and other security tools across enterprise IT and OT/ICS networks
- Triage and analyze alerts to identify potential security incidents, including impacts to production, plant floor systems, and industrial control systems
- Escalate confirmed incidents to Level 2/3 analysts, incident response teams, or OT engineering staff as appropriate
- Document findings, actions taken, and incident details in ticketing systems
- Assist in creating and tuning detection rules and security use cases, including those tailored to ICS/SCADA protocols and behaviors
- Follow SOPs for incident handling and escalation, including OT-specific procedures that account for safety and uptime needs
- Stay current on emerging threats and vulnerabilities affecting both IT and OT environments
- Administer and monitor web and email security controls to reduce risk from phishing, malware, spam, malicious websites, and other cyber threats
Requirements
- Associate's degree in Cybersecurity, Information Technology, or related field or equivalent experience
- 3+ years of IT Cybersecurity experience
- Basic understanding of networking concepts: TCP/IP, DNS, firewalls
- Familiarity with security tools: SIEM, XDR, IDS/IPS, endpoint protection
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Align with Patrick Industries āBETTER Togetherā mentality: Balance, Excellence, Trust, Teamwork, Empowerment, Respect
Technologies
- SIEM, XDR, IDS/IPS, endpoint protection
- Splunk, Logscale, Sentinel
- MITRE ATT&CK framework, ATT&CK for ICS matrix
- Python, PowerShell
- Azure, AWS, GCP
- Purdue Model (ICS network segmentation and IT/OT convergence)
- Industrial protocols and environments: Modbus, DNP3, OPC-UA, EtherNet/IP
- OT monitoring/security platforms: Claroty, Dragos, Nozomi Networks, Tenable.ot
- Standards/training: ISA/IEC 62443 Cybersecurity Fundamentals Specialist, GICSP (Global Industrial Cyber Security Professional), SANS ICS410/ICS515
Preferred Qualifications
- Security certifications such as CompTIA Security+, CySA+, or equivalent
- Experience with Splunk, Logscale, or Sentinel
- Knowledge of MITRE ATT&CK, including the ATT&CK for ICS matrix
- Exposure to scripting or automation (Python, PowerShell)
- Experience securing cloud environments (Azure, AWS, GCP)
- Experience or coursework in OT/ICS security, especially in manufacturing environments
- Familiarity with the Purdue Model for ICS network segmentation and IT/OT convergence
- Understanding industrial protocols such as Modbus, DNP3, OPC-UA, or EtherNet/IP
- Exposure to OT monitoring platforms: Claroty, Dragos, Nozomi Networks, Tenable.ot
- Industrial/OT security certifications including GICSP, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or SANS ICS410/ICS515 coursework
- Awareness of safety-first incident response practices unique to production and manufacturing environments
Location: Elkhart, IN (onsite)