
Why Join Dawon?
We bring together cybersecurity, Operational Technology, engineering, and Threat Research to resolve cybersecurity challenges in Critical Infrastructure. You will work with the most innovative minds and contribute directly towards building technologies that strengthen the security and resilience of Critical Infrastructure.
Open Roles
19 positions open across 4 countries
Engineering
Job Overview
Dawon is looking for an X-IOT Security Analyst to work on the operational networks behind Critical Infrastructure. You will run Asset Discovery and Threat Detection across customer estates, investigate what turns up on operational, IoT and IT networks, and turn each finding into a response a plant can actually carry out. The role sits alongside the engineering team that builds the platform, so what you learn on a customer network changes the product.
Key Responsibilities
Asset Discovery and Inventory: Build and maintain a complete inventory of Operational Technology, industrial and medical IoT, building systems and IT endpoints across customer sites, and keep it current as the estate changes.
Threat Detection and Monitoring: Monitor customer environments for activity that departs from normal process behaviour, and separate an engineering change from an intrusion before it is escalated.
Protocol Level Analysis: Analyse traffic on industrial protocols including Modbus, DNP3, OPC UA and vendor proprietary protocols, and explain what a given exchange means in process terms.
Vulnerability Assessment: Assess exposure across PLCs, RTUs, HMIs, SCADA servers, historians, engineering workstations and safety instrumented systems, and rank it by operational consequence and not by severity score alone.
Incident Response: Support customers through triage, containment and recovery on networks where taking a device offline is an operational decision before it is a security one.
Detection Engineering: Write, tune and retire detection content, and cut the false positives that come from normal plant behaviour being read as attack behaviour.
Architecture Review: Review customer segmentation against the Purdue Model and IEC 62443 zones and conduits, and record where a conduit is undocumented or unenforced.
Reporting: Produce findings for two audiences at once: the plant engineer who has to act on them and the risk owner who has to fund the fix.
Platform Feedback: Feed detection gaps, protocol coverage gaps and analyst workflow problems back to the engineering and research teams as product requirements.
Customer Enablement: Walk customer teams through what the platform is showing them, so they can operate it themselves.
Qualifications
Experience
4 to 5 years in OT, ICS or IoT security, or in IT security with hands on exposure to industrial or plant environments.
Certifications
Required- GICSP, IEC 62443 Cybersecurity Fundamentals Specialist or CompTIA Security+.
Preferred- GRID or GCIP.
- CISSP.
- OSCP.
- A vendor certification from an automation OEM such as Siemens, Rockwell Automation or Schneider Electric.
Technical Skills
- Working knowledge of the Purdue Model and of IEC 62443 zones and conduits as they are actually deployed, and not only as they are drawn.
- Packet analysis on industrial protocols including Modbus, DNP3 and OPC UA, using Wireshark or an equivalent.
- Familiarity with PLC, RTU, HMI, SCADA, DCS, historian and engineering workstation behaviour under normal operation.
- SIEM and detection engineering, including writing and tuning rules against noisy operational data.
- Scripting in Python or PowerShell for analysis and automation.
- Comfort with passive collection, and with the constraints of networks that cannot carry active scanning.
Education
Bachelor's degree in Computer Science, Electrical, Electronics or Instrumentation Engineering, Cybersecurity or a related field, or equivalent practical experience.
Soft Skills
- Ability to explain a security finding to a control engineer who owns uptime and is not a security specialist.
- Judgement under pressure during a live incident, including knowing when not to act.
- Clear written reporting, since most of this work is read by people who were not on the call.
Additional Requirements
- Willingness to travel to customer plants, substations and treatment works within the region.
- Participation in an on call rotation shared across the regional analyst team.
- Comfort working with equipment that cannot be rebooted, patched or taken offline on demand.
Work Environment
- Hybrid, based in the country the position is listed under.
- Regular travel to customer sites, including plants, substations, treatment works and hospitals.
- An on call rotation for customer incidents, shared across the regional team.
- Some work happens inside plant environments, with the safety induction and personal protective equipment that requires.
Why Join Us?
Most security analysts never see the equipment their alerts are about. Here you will work on live operational networks, alongside the research team that studies the devices and the engineering team that builds the platform. What you find on a customer estate becomes detection content, and the response you develop with an OEM reaches every other customer.
5 openings · South Africa · Dubai, United Arab Emirates · Indonesia · India
Job Overview
Dawon is looking for a Software Development Engineer in India to build the platform itself. You will work on the services that ingest, normalise and reason over asset and telemetry data from operational networks, and on the interfaces that put that data in front of an analyst. This is product engineering on a system where the data is unusual, the volumes are large, and correctness matters more than novelty.
Key Responsibilities
Feature Development: Design, build and ship features across the platform, from the data ingestion services through to the analyst facing interface.
Data Pipelines: Build and maintain the pipelines that take asset, protocol and telemetry data out of customer environments and turn it into one queryable model.
API Design: Design internal and customer facing APIs that stay stable while the data model behind them keeps moving.
Front End Engineering: Build interfaces in React and TypeScript that stay usable when a customer estate holds far more assets than a screen can show at once.
Performance: Profile and improve query and rendering performance against realistic estate sizes, and not against sample data.
Testing: Write the tests that let the team change this system safely, including around the data model, where a silent regression is expensive to find later.
Code Review: Review other engineers' work with the care you expect on your own, and keep the review loop short.
Reliability: Own what you ship through to production, including its instrumentation, its alerting and the failure modes it introduces.
Collaboration: Work directly with the security analysts and the research team, whose findings define what the platform needs to do next.
Technical Documentation: Record the decisions behind a design, so the next person to touch it understands why it works the way it does.
Qualifications
Experience
3 to 5 years building and shipping production software, ideally on data intensive backend systems or on complex product interfaces.
Technical Skills
- Strong programming fundamentals in TypeScript, and in at least one of Python, Go or Rust.
- Experience with relational and time series data stores, and a working understanding of why a given query is slow.
- Distributed systems basics: queues, idempotency, backpressure, and what happens when a downstream service stops answering.
- React and modern front end tooling, including state management on data heavy screens.
- Containers and continuous integration, and the confidence to deploy your own work.
- An interest in security or industrial systems. Domain knowledge is taught here. Engineering judgement is not.
Education
Bachelor's degree in Computer Science, Software Engineering or a related field, or equivalent practical experience.
Soft Skills
- Ability to take an ambiguous problem and return a scoped, defensible design.
- Directness in code review and in design discussion, without making it personal.
- Willingness to work on the unglamorous parts of a product that has to be correct.
Additional Requirements
- Experience with OT, ICS or IoT data is welcome and is not expected.
- Exposure to graph data models, protocol parsing or large scale ingestion is an advantage.
- Open source contributions and personal projects are read, if you point us at them.
Work Environment
- Hybrid, based in India.
- Regular working sessions with the security and research teams across time zones.
- A shared on call rotation once you are established on the systems you own.
Why Join Us?
You will build a product whose users are named, reachable and specific: analysts defending real plants. Feedback arrives in days and not in quarters. The problems are genuinely hard, the data is unlike anything in an ordinary SaaS product, and the team is small enough that what you build stays recognisably yours.
2 openings · India
Research
Job Overview
Dawon is looking for a Security Research Analyst to join Rakshastra Research, the team that studies the equipment Critical Infrastructure runs on. You will research vulnerabilities in automation and IoT devices, work with the OEMs that build them on a definitive response, and produce the advisories and detection content that reach every customer.
Key Responsibilities
Vulnerability Research: Research vulnerabilities in PLCs, RTUs, gateways, IoT devices and the software that manages them, on hardware in the lab and in customer environments where that is authorised.
Protocol Analysis: Reverse engineer industrial and proprietary protocols to the point where their behaviour can be modelled, detected and tested.
Firmware Analysis: Extract and analyse device firmware, and identify weaknesses in its update, authentication and configuration paths.
OEM Coordination: Work with automation OEMs through coordinated disclosure, so that a finding arrives with a response the operator can actually apply.
Threat Intelligence: Track threat activity against Critical Infrastructure and translate it into what it means for the environments Dawon protects.
Detection Content: Turn research output into detection content, and validate it against real traffic before it ships.
Attack Simulation: Build and run safe reproductions of attack techniques in the lab, so that a response model is tested and not assumed.
Advisories and Publication: Write Security Advisories and Threat Research for a technical audience, held to the standard that a reader can act on them.
Product Input: Feed research findings into the platform roadmap, so what the team learns becomes a capability and not only a report.
Community: Represent the research team in the wider Critical Infrastructure security community, including at conferences and in industry working groups.
Qualifications
Experience
3 to 5 years in vulnerability research, offensive security, malware analysis, protocol research or a closely related discipline.
Certifications
Required- OSCP, GREM, GRID, or an equivalent demonstration of practical research capability such as published CVEs.
Preferred- GXPN or OSCE.
- GICSP or IEC 62443 Cybersecurity Fundamentals Specialist.
- Published advisories, CVEs or conference talks.
Technical Skills
- Reverse engineering with IDA, Ghidra or Binary Ninja, on embedded targets as well as on desktop binaries.
- Firmware extraction and analysis, including on devices that do not want to be read.
- Protocol reverse engineering and traffic analysis on industrial and proprietary protocols.
- Exploit development fundamentals, including memory safety issues on embedded architectures.
- Scripting in Python, and enough C or assembly to follow the target where it goes.
- Familiarity with ICS attack technique taxonomies, and with how those techniques appear in telemetry.
Education
Bachelor's degree in Computer Science, Electronics Engineering, Cybersecurity or a related field, or equivalent demonstrated research work.
Soft Skills
- Persistence on problems that do not resolve quickly, and the honesty to record a negative result.
- Writing clear enough that an OEM engineer, a customer and a regulator each take the same meaning from it.
- Discretion, because most of this work is sensitive before it is public.
Additional Requirements
- Understanding of coordinated disclosure practice, and of why the timelines are held.
- Access to or willingness to build a hardware bench, including serial, JTAG and logic analysis.
- Interest in the physical process behind the device, and not only in the device.
Work Environment
- Hybrid, based in the country the position is listed under, with lab work on site.
- Occasional travel for conferences, OEM engagement and customer research.
- Findings are held under embargo until disclosure has been coordinated.
Why Join Us?
Rakshastra Research exists to produce the response and not only the finding. Working directly with the OEM that built the device means your research ends in something an operator can apply, which is rare in this field. The lab is real, the targets are real, and the output is published under the team's name.
3 openings · South Africa · Indonesia · India
Professional Services
Job Overview
Dawon is looking for an OT GRC Consultant to deliver Governance Risk and Compliance programmes for Critical Infrastructure operators. You will build policy, control libraries, risk registers and audit readiness on the Dawon platform, working directly with the customer teams that answer to regulators. This is delivery work with a platform behind it, so a control you map once reports against every framework that references it.
Key Responsibilities
Compliance Gap Assessment: Assess a customer's OT security programme against the frameworks they are held to, and produce a gap position they can take to their board.
Control Library Development: Build and maintain control libraries mapped across IEC 62443, NIST SP 800 82, ISO 27001, NIS2, NERC CIP and the regional regimes that apply.
Policy and Procedure: Develop OT security policy and the procedures that make it operable, including the approvals and evidence capture attached to each step.
Risk Assessment: Run risk assessments across operational estates, and land the findings in a risk register with owner, scoring, affected assets and framework linkage already attached.
Audit Support: Prepare customers for internal and external audit, and support them through it with evidence that was generated and not assembled the week before.
Accountability Mapping: Record who is responsible, accountable, supporting, consulted and informed for each control, so that accountability survives a staff change.
Remediation Planning: Turn assessment findings into treatment plans with sequencing that works for environments which cannot take arbitrary downtime.
Platform Delivery: Configure the Dawon GRC modules to the customer's framework set, and hand over a system their own team can run.
Regulatory Tracking: Track changes in the regulations customers are assessed against, and advise on what a change actually requires of them.
Stakeholder Engagement: Work across plant engineering, IT security, legal and executive teams, who each need a different account of the same programme.
Qualifications
Experience
4 to 5 years in cybersecurity governance, risk and compliance, with at least part of it in Operational Technology, industrial or Critical Infrastructure environments.
Certifications
Required- CISA, CISM, ISO 27001 Lead Auditor or IEC 62443 Cybersecurity Expert.
Preferred- CISSP or CRISC.
- GICSP.
- Lead Implementer certification for ISO 27001 or IEC 62443.
- Regional qualifications relevant to the market the position covers.
Technical Skills
- Working command of IEC 62443, NIST SP 800 82, NIST CSF, ISO 27001 and NERC CIP, and of where they overlap.
- Familiarity with the regional regimes that apply in the market, including NIS2, the EU Cyber Resilience Act, SAMA, CERT In Directions and UAE IAS.
- Risk assessment methodology, including quantitative approaches and their limits.
- Enough understanding of OT architecture to know whether a control is deployable on a given network.
- Audit evidence practice, including what an auditor will and will not accept.
- GRC tooling, and the judgement to know when a spreadsheet has stopped being adequate.
Education
Bachelor's degree in Cybersecurity, Information Systems, Engineering, Law or a related field, or equivalent practical experience.
Soft Skills
- Facilitation, since much of this work happens in rooms where plant and IT disagree.
- Writing that holds up under audit scrutiny and still reads clearly.
- Firmness about what the evidence supports, including when a customer would prefer a different answer.
Additional Requirements
- Willingness to travel to customer sites within the region.
- Experience delivering to a defined scope and timeline in a consulting or advisory setting.
- Comfort presenting to executive and board audiences.
Work Environment
- Hybrid, based in the country the position is listed under.
- Regular travel to customer sites, and to audit and workshop sessions.
- Work is organised around customer engagements with defined scope and delivery dates.
Why Join Us?
Governance work in Operational Technology is usually a spreadsheet exercise repeated every audit cycle. Here it sits on a platform that already holds the asset data, the control status and the risk register, so the mapping you do once keeps reporting itself. You will deliver programmes that are still standing after the engagement closes.
3 openings · South Africa · Indonesia · India
Sales
Job Overview
Dawon is looking for a Sales Specialist to sell into Critical Infrastructure operators. These are long, technical cycles with several buyers in the room at once: a plant engineer, a CISO, a risk owner and a procurement team. You will own the territory from first conversation to signed agreement, with the engineering and GRC teams behind you.
Key Responsibilities
Territory Ownership: Own pipeline generation and revenue for the market the position covers, including account planning and forecasting.
Prospecting: Build first conversations with Critical Infrastructure operators, System Integrators and automation OEMs across the region.
Discovery: Establish what a prospect is actually trying to secure, which regulations they answer to, and who inside the organisation carries the risk.
Technical Selling: Position the platform credibly to a technical audience, and bring in the engineering or GRC team at the point where real depth is needed.
Proposals and Commercials: Build proposals, respond to tenders, and negotiate commercial terms alongside legal and finance.
Partner Development: Develop System Integrator and reseller relationships in the region, which is how a large part of this market actually buys.
Executive Engagement: Reach and hold conversations at CISO, plant leadership and board level, where the budget for this work sits.
Market Feedback: Report what the market is asking for and what it objects to, so that the product and the positioning move with it.
Pipeline Discipline: Keep pipeline, forecast and account records accurate, because the forecast is used.
Industry Presence: Represent Dawon at industry events, conferences and customer forums in the region.
Qualifications
Experience
3 to 5 years in enterprise B2B sales, with a record of closing complex technical deals. Cybersecurity, industrial automation or Critical Infrastructure experience is a strong advantage.
Domain and Commercial Knowledge
- Enough understanding of Operational Technology and Critical Infrastructure to hold a credible conversation with a plant engineer.
- Familiarity with the regulatory pressure operators are under in the region, and with how that pressure turns into budget.
- Command of a structured sales methodology, and the discipline to work a long cycle without abandoning it.
- Experience selling through System Integrators and channel partners.
- Comfort with tender and public procurement processes, which govern much of this market.
- CRM fluency, and forecasting people can rely on.
Education
Bachelor's degree in Business, Engineering or a related field, or equivalent practical experience.
Soft Skills
- Listening, since discovery is where deals in this market are actually won.
- Credibility with technical buyers, which comes from knowing the limits of what you are selling.
- Persistence across cycles measured in quarters and not in weeks.
Additional Requirements
- Existing relationships with Critical Infrastructure operators or automation partners in the region are a significant advantage.
- Willingness to travel across the territory.
- Fluency in the working languages of the market the position covers.
Work Environment
- Hybrid, based in the country the position is listed under.
- Substantial travel across the territory, including to customer plants and industry events.
- Compensation includes a variable component tied to territory performance.
Why Join Us?
You will sell a platform that covers in one system what this market usually buys in parts, into operators who already know they have a problem. The technical teams are reachable and will join your calls. The territory is yours to build, and the roadmap is close enough that what your customers ask for is heard.
6 openings · South Africa · Indonesia · India

