Dragos is on a relentless mission to defend industrial organizations that provide us with the necessities of modern civilization; running water, functioning electricity, and safe industrial working environments. As the market leader in ICS/OT Cybersecurity, we are dedicated to arming our customers with best-in-class technology, threat intelligence, and services to protect their systems as effectively and efficiently as possible. We’re a remote-first culture with operations in North America, Europe, the Middle East, and APAC. We’re looking for mission-oriented teammates who embody our core values of authenticity, transparency, and trust. Are you ready to make a difference? Come join a mission that can save the world!
About the Role:
Our Professional Services team is looking for a Senior OT Incident Responder to join our APAC organization. In this role, you’ll lead incident response cases across complex OT environments, applying deep industrial cybersecurity expertise to investigate unclear situations, identify root cause and impact, and drive containment and recovery. You’ll also play a key role in guiding stakeholders through high‑pressure incidents. Many teams you support may have limited OT security experience, so strong communication and the ability to influence decisions are essential. You’ll translate technical findings into clear, actionable guidance for audiences ranging from plant engineers to executive leadership.
Responsibilities:
- Perform hands‑on forensic investigations, root‑cause analysis, and threat hunting to detect, analyze, and remediate security incidents. Support and deliver exercise‑based engagements such as tabletop exercises and purple‑team activities.
- Lead investigations and threat‑hunting operations in industrial environments, using advanced techniques to rapidly identify and mitigate threats.
- Work closely with teammates supporting Incident Response Retainer customers—both onsite and remote—to ensure coordinated, effective incident management. Develop and refine incident response playbooks, workflows, and technical content tailored to customer environments and evolving threats.
- Recommend service and process improvements based on operational insights and customer feedback to strengthen overall delivery and alignment with engagement objectives.
- Provide expert, hands‑on support during high‑pressure incidents, ensuring timely containment, recovery, and clear guidance for customer teams.
Qualifications:
- Australian Citizenship is required.
- 3+ years of hands-on experience with intrusion analysis and digital forensics/incident response (DFIR).
- Ability to support an investigation from start to finish including pivoting between data types and correlating events together.
- Proficiency with Windows, Linux and a broad range of applicable security toolsets.
- Ability to write scripts in Python, Ruby, Bash, or similar languages.
- Strong interpersonal, verbal, and written communication skills, with the ability to work effectively with customers.
- Willingness to participate in on‑call rotations, including occasional non‑standard hours and unplanned remote or onsite response work.
- Experience handling communications during incidents, especially regarding customer and stakeholder briefings.
- An desire to master industrial environments including software platforms, PLCs, RTUs, instrumentation and the industrial processes they sustain (prior experience is a big plus).
- Willingness to travel up to 30% for onsite engagements.
Compensation:
- Salary: 150,000 AUD
- Competitive Equity Package
- Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE
Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.