Cyber OT SecOps
Coca-Cola
- Location
- US - GA - Atlanta
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 3 approvals (FY2023)
- Posted
- 16h ago
Skills
About this role
Job Description
Summary: Cyber OT SecOps Overview The Manager, Cyber OT SecOps is The Coca-Cola Company's operational leader for monitoring, detecting, and responding to cyber threats targeting the industrial control systems and manufacturing technology that keep Coca-Cola production running. This role sits within Cybersecurity Operations and owns the SOC-side of OT security — ensuring that threats to plant floor systems are detected, triaged, investigated, and resolved with the speed and manufacturing context required to protect production, safety, and product quality. Reporting to the Senior Director, Cybersecurity Operations, this is an individual-contributor role that also provides day-to-day operational leadership of the managed security service provider (MSSP) SOC analysts supporting OT environments. The Manager builds deep relationships with plant teams to understand how manufacturing operations work, designs detection playbooks calibrated to OT realities, and partners with the OT Cybersecurity engineering team to ensure the right monitoring and detection mechanisms are in place. The role bridges the gap between traditional IT-centric SOC operations and the unique requirements of operational technology environments.
Key Responsibilities
OT Security Monitoring & Detection Own the OT security monitoring and detection capability within the SOC, ensuring comprehensive visibility into threats targeting industrial control systems, SCADA, HMIs, PLCs, historians, and manufacturing networks. Design, tune, and maintain OT-specific detection rules, alerts, and use cases across OT monitoring platforms (such as Claroty or Microsoft Defender for IoT), EDR, network monitoring (such as Palo Alto), and SIEM. Continuously evaluate and improve detection coverage for OT-relevant threats, including unauthorized access, network anomalies, configuration changes, and lateral movement between IT and OT environments. Partner with the OT Cybersecurity engineering team to ensure monitoring tools are properly deployed, configured, and maintained across manufacturing sites. OT Incident Triage & Response Lead the triage, investigation, and response to security events and incidents in OT environments, providing manufacturing context and ensuring response actions account for safety, uptime, and operational continuity. Develop and maintain OT-specific incident response playbooks, escalation procedures, and communication templates in partnership with SOC leadership and plant teams. Coordinate with IT SOC, Incident Response, and OT engineering teams during cross-domain incidents that span IT and OT boundaries. Conduct post-incident reviews and drive lessons learned into improved detection, response, and prevention capabilities. Plant Partnerships & OT Context Build and maintain trusted relationships with plant leadership, plant engineers, and operations teams to understand manufacturing processes, control system architectures, and operational constraints. Translate plant floor operational knowledge into SOC detection playbooks and triage procedures that reduce false positives and improve response relevance. Educate SOC analysts and MSSP team members on OT-specific concepts, protocols, and operational considerations. Support plant visits and site assessments to evaluate monitoring effectiveness and identify coverage gaps. MSSP SOC Team Leadership Provide day-to-day operational direction to MSSP SOC analysts supporting OT monitoring, setting priorities, reviewing alert quality, and maintaining service-level expectations. Define standard operating procedures, detection playbooks, and training materials for the MSSP team specific to OT environments. Monitor MSSP performance and drive continuous improvement in OT alert handling, triage accuracy, and escalation quality. Reporting & Continuous Improvement Provide clear,