Security Operation Supervisor (OT Specialization)

Fluence Energy PolandBengaluru, KarnatakaOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are transforming the way we power our world for a more sustainable future. For more information, please visit  fluenceenergy.com .

Job Description:

Role Overview

The Security Operations Supervisor (OT Specialization) leads the day-to-day work of a team of security operations analysts and serves as the senior technical escalation point for threats affecting both our corporate IT estate and our operational technology environments, including battery energy storage sites and the systems that support them. Based in Bengaluru, this role supervises cybersecurity analysts, quality of triage and investigation, and the professional growth of the analyst team, while personally handling complex detection, hunting and incident response work. The Supervisor partners closely with the global cybersecurity team, IT infrastructure, service desk, service and operations engineering, product security and, where required, customers and external incident response partners. The ideal candidate has hands-on security operations depth, real exposure to industrial control system and OT environments, and a genuine interest in coaching analysts and improving how a security operations team works. Key tools and platforms include Microsoft Sentinel and Defender, endpoint detection and response, SOAR and automation platforms, OT monitoring technologies, threat intelligence services and IT service management tooling.

Key Responsibilities

Security Monitoring, Detection and Incident Response

- Direct network monitoring and intrusion detection analysis using computer network defense tools such as intrusion detection and prevention systems, firewalls, proxies and host-based security systems.
- Oversee log-based, identity-based and endpoint-based threat detection to identify and contain threats originating from multiple sources.
- Drive cloud-centric detection coverage for the cloud environments and services the organization uses, including Azure, AWS and GCP workloads.
- Correlate activity across assets (endpoint, network, identity, applications) and environments (on-premises, cloud, OT) to identify patterns of anomalous activity, attacks and unauthorized use.
- Review alerts and sensor data escalated by analysts, validate findings and produce formal, technical incident reports for technical and management audiences.
- Act as incident commander or senior responder for high-severity incidents, coordinating containment, eradication and recovery activities across teams and time zones.
- Provide users and internal stakeholders with incident response support, including mitigating actions to contain activity and facilitating forensic analysis where necessary.
- Work with threat intelligence and threat-hunting teams, translating intelligence into detection content, hunting hypotheses and response playbooks.
- Research emerging threats, adversary tradecraft and vulnerabilities to support the identification and classification of incidents.
- Support the creation and testing of business continuity and disaster recovery plans, including running exercises, publishing results and driving remediation of deficiencies.
- Perform security standards testing against systems before implementation to confirm they meet security requirements.

Operational Technology (OT) Security

- Own monitoring, detection and response for operational technology environments, including battery energy storage sites, site controllers, historians, engineering workstations and remote access paths used to support them.
- Tune and maintain OT-specific detection content, including rules for unauthorized configuration changes, unexpected protocol use, rogue devices and abnormal control traffic.
- Onboard and validate telemetry from OT monitoring and asset discovery platforms into the SIEM, and maintain accurate OT asset and network context for responders.
- Maintain and exercise OT incident response playbooks that account for safety, availability and physical process constraints, including scenarios where containment actions cannot disrupt energy delivery.
- Monitor and review privileged and vendor remote access into OT networks, escalating misuse or policy deviations.
- Work with service and operations engineering, product teams and site personnel to validate alerts, confirm expected activity and agree on safe response actions.
- Track OT vulnerabilities and advisories, assess applicability to deployed systems and coordinate risk-based mitigation with engineering owners.
- Support alignment of OT monitoring and response practices with recognized frameworks and standards such as IEC 62443, NIST SP 800-82 and applicable customer or regulatory requirements.

Supervision and Development of Analysts

- Supervise a team of security operations analysts, including day-to-day task assignment, shift and on-call scheduling, workload balancing and handover quality across regions.
- Set clear performance expectations, conduct regular one-on-ones, provide continuous feedback and contribute to goal setting, performance reviews and career development plans.
- Coach analysts on investigation technique, evidence handling, documentation quality and escalation judgment, and review a sample of closed cases for accuracy and completeness.
- Build and maintain a skills matrix and training path for the team, covering IT, cloud and OT monitoring, and identify gaps to be closed through training or hiring.
- Deliver regular internal training sessions on intrusion detection and prevention, incident response procedures, threat intelligence analysis, log analysis and OT fundamentals.
- Run tabletop exercises, purple team activities and detection drills to test analyst readiness and improve response quality.
- Participate in recruiting, interviewing and onboarding of new analysts, including mentoring during ramp-up.
- Manage the relationship with managed detection and response or outsourced monitoring partners, reviewing their output quality and holding them to agreed service levels.
- Foster a culture of ownership, knowledge sharing and psychological safety, so analysts raise concerns early and learn from incidents without blame.

Detection Engineering, Automation and Tooling

- Work with security information and event management (SIEM) platforms to manage and tune the system, create and maintain detection content and actively watch for alerts.
- Own the detection engineering backlog, from use case definition through rule development, testing, documentation and measurement of effectiveness.
- Drive down false positives and alert fatigue through tuning, enrichment and suppression logic, with measurable targets reported to leadership.
- Design and maintain security orchestration, automation and response (SOAR) playbooks that automate repetitive triage, enrichment and containment tasks.
- Ensure log source coverage and data quality across IT, cloud and OT, identifying blind spots and driving onboarding of missing telemetry.
- Map detection coverage to MITRE ATT&CK for Enterprise and ATT&CK for ICS, and use the results to prioritize new content.

Process, Reporting and Continuous Improvement

- Maintain standard operating procedures, runbooks and escalation matrices for the security operations team, and keep them current as tooling and the environment change.
- Track and report operational metrics such as alert volume, time to triage, time to contain, escalation accuracy and detection coverage, with regular reporting to cybersecurity leadership.
- Lead post-incident reviews, capture lessons learned and drive corrective actions to closure with the responsible owners.
- Manage projects to implement new security tooling or to develop new security policies and procedures, including scope, timeline and stakeholder communication.
- Apply change management practices when introducing new controls or processes, including change plans and management of business impact.
- Support audit, compliance and customer assurance activities by providing evidence of monitoring, detection and response capability.

Required Qualifications

- Bachelor's degree in computer science, information security, cybersecurity, engineering or a related field, or equivalent practical experience.
- Minimum 6 years of experience in cybersecurity, with at least 4 years in a security operations, incident response or threat detection role.
- Minimum 2 years of experience supervising, leading or mentoring analysts, including shift coordination, quality review and coaching. Formal people management experience is welcome but a strong technical lead background will also be considered.
- Minimum 2 years of hands-on experience with industrial control system or operational technology environments, such as battery energy storage, power generation, utilities or manufacturing.
- Demonstrated experience with SIEM platforms, including writing and tuning detection content and building dashboards and reports. Experience with Microsoft Sentinel and KQL is strongly preferred.
- Practical experience with endpoint detection and response, network detection, identity protection and email security tooling.
- Working knowledge of cloud security concepts and the security capabilities of major cloud platforms such as Azure, AWS and GCP, including detection of cloud-native attack techniques.
- Familiarity with industrial protocols and OT architecture concepts, such as Modbus, DNP3, IEC 61850, OPC and the Purdue model, and the ability to read a basic network or one-line diagram.
- Experience with risk assessment, incident response and security audits.
- Experience with regulatory compliance and information security management frameworks such as ISO 27001, NIST Cybersecurity Framework, NIST SP 800-53 or COBIT.
- Advanced analytical, problem-solving and troubleshooting capabilities, with sound judgment under time pressure.
- Strong written and verbal communication skills in English, with the ability to write clear incident reports and explain technical risk to non-technical stakeholders.
- Willingness to participate in an on-call rotation and to support incidents outside standard business hours when required.

Preferred Qualifications

- Master's degree in cybersecurity, information security or a related technical field.
- OT or ICS security certification such as GICSP, GRID or GCIP.
- Security operations or incident response certification such as GCIA, GCIH, GCFA or Microsoft SC-200.
- Management or governance certification such as CISSP, CISM or CISA.
- Experience with OT monitoring and asset visibility platforms such as Dragos, Claroty, Nozomi or Tenable OT.
- Experience building SOAR automation, for example with Logic Apps, and scripting in PowerShell or Python.
- Familiarity with DevOps security practices and the ability to integrate security checks into a DevOps pipeline.
- Experience supporting a follow-the-sun or globally distributed security operations model.
- Digital forensics or malware analysis experience.
- Exposure to the energy storage, renewable energy or utility sector, and to customer-facing security obligations in service agreements.

Key Competencies

- Team leadership and analyst development, including coaching, feedback and workload management.
- Threat detection and incident response judgment, with strong decision-making that weighs the relative costs and benefits of possible actions and selects the most appropriate one.
- OT and safety awareness, understanding where availability and physical process safety constrain security actions.
- Technical breadth across firewalls, intrusion detection and prevention systems, SIEM, SOAR, endpoint and identity security tooling.
- Influence and stakeholder management, with the ability to shift the opinions, plans or behavior of teams outside direct authority.
- Process discipline and continuous improvement, turning incidents and metrics into lasting change.

Business alignment, consistently applying an understanding of organizational mission, values and goals to security decisions.

Our Culture

At Fluence, our culture is the foundation that drives our ambitious growth strategy and fuels our mission to transform the future of energy. Our core cultural pillars empower us to innovate, collaborate, and lead with purpose, ensuring we continue to deliver unparalleled value to our customers and the world.

Unleash Voices

We believe every voice matters. We encourage openness, active listening, and decisive action to create a culture where everyone has the opportunity to contribute to our success. We foster an environment where diverse perspectives are heard and valued, driving innovation and progress.

Customer Fluent

Our customers are at the heart of everything we do. We’re committed to delivering exceptional value that exceeds expectations by understanding our customers' needs and adapting swiftly to meet them. Our deep focus on customer satisfaction drives us to continuously improve and innovate.

Infinite Impact

We are committed to creating the impossible. We push boundaries to deliver sustainable, game-changing solutions that shape a brighter, more energy-efficient future for all. Our team is passionate about making a lasting impact that will resonate for generations to come.

All In

We are all in for growth. Our teams are relentlessly focused on identifying and seizing opportunities that propel us forward. We embrace an ownership mindset, pushing ourselves and each other to accelerate progress and create lasting success.