Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff, IT Security Specialist - Security Operations Center (SOC)

Murphy Oil

At Murphy Oil Corporation, we believe the rich experiences and backgrounds of our employees strengthen our Company, create a productive workforce, and drive our success. We encourage you to apply for the positions for which you meet the qualifications.Job Summary Murphy Oil Corporation is looking for an IT Security Specialist to support our growing Global Cybersecurity team. The ideal candidate is a highly technical and hands-on cybersecurity professional who will support the design, implementation, administration, and continuous improvement of Murphy’s security monitoring, logging, detection, and incident response capabilities. This role supports the Security Operations Center (SOC) function with a primary focus on SIEM engineering, detection engineering, security telemetry management, and security operations enablement.The right candidate has recent hands-on experience deploying, configuring, operating, and troubleshooting SIEM platforms, security data lakes, observability platforms, and log management solutions. This individual remains actively involved in technical implementation work, including onboarding data sources, creating data pipelines, developing detection content, writing queries, automating workflows, troubleshooting production issues, and working with stakeholders in the business, internal IT, Operations, and third-party service providers to securely enable the business.This is an individual contributor role requiring strong technical depth and hands-on engineering experience. Candidates whose recent experience has primarily been focused on people leadership, program management, governance, or vendor management may not be the best fit.The IT Security Specialist will work in our Houston Corporate office and may work two (2) days a week remote.ResponsibilitiesContribute to cybersecurity vision, roadmap, and execution plan, with emphasis on security monitoring, logging, telemetry, SIEM engineering, and detection engineering capabilities.Lead and mature technical incident response enablement, including updating plans, documenting playbooks, facilitating cyber drills, improving security telemetry, coordinating with Incident Response vendors, setting up alternate communication channels, and implementing automation to reduce response time.Respond to security-related incidents by creating queries, validating telemetry, assisting with forensic analysis, determining scope, urgency, potential impact, and materiality, identifying relevant vulnerabilities, and making recommendations that enable expeditious remediation.Support day-to-day SOC operations by partnering with Murphy’s managed SOC provider to optimize monitoring, alert quality, response workflows, help desk tickets, incidents, cases, and visibility across security data sources.Provide technical support for on-call and after-hours security response by ensuring required telemetry, detection logic, queries, dashboards, and runbooks are available to support timely investigation and escalation.Collaborate with service desk, infrastructure, cloud, OT, and application teams to deploy critical security patches in a timely, risk-based manner, formalize vulnerability management processes, improve telemetry coverage, and introduce automation.Collaborate with the Head of IT Security to implement security architecture best practices within incident response, daily SOC activities, logging architecture, detection coverage, and security data platform design.Support the Head of IT Security by providing technical guidance to the cybersecurity team in managing day-to-day security operations, improving detection content, strengthening telemetry coverage, and responding to incidents.Establish and maintain technical metrics to measure SOC and security data platform effectiveness, including detection coverage, telemetry quality, ingestion health, false positive rate, MTTD, MTTR, and SLA adherence.Establish relationships between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies, vendors, public relations professionals)Keep current with latest cyber security developments, threat intelligence, attacker techniques, emerging tools, technologies, and security monitoring best practices, and translate relevant developments into detection use cases and hunting content.Manage the lifecycle, configuration, health, and operational effectiveness of security-related products, including SIEM, log management, security analytics, observability, SOAR, and telemetry pipeline technologies.Design, implement, administer, and maintain enterprise SIEM, security analytics, security data lake, observability, and log management capabilities.Configure and manage log collection, normalization, enrichment, routing, filtering, retention, and ingestion pipelines using APIs, syslog, collectors, agents, event hubs, and cloud-native telemetry services.Onboard new log sources from cloud, endpoint, identity, infrastructure, network, application, SaaS, and OT environments; troubleshoot ingestion issues, missing telemetry, parsing failures, duplicate events, and logging gaps.Develop, tune, and maintain SIEM correlation rules, detections, alerts, dashboards, queries, hunting content, and automation workflows; map detections to MITRE ATT&CK and continuously reduce false positives.Actively identify, recommend, and implement cybersecurity and risk management solutions that ensure business needs are met while enhancing the organization’s security posture, and maturing the cybersecurity functionEnsure cloud security considerations are integrated into overall security operations, including appropriate telemetry onboarding, detection coverage, monitoring dashboards, alerting, and response workflows for Azure, AWS, Microsoft Defender, Entra ID, SaaS, and cloud-native services.Lead special projects as assignedCoordinate with relevant teams and managed SOC/MDR providers to manage risks associated with third-party relationships and optimize integrations between provider monitoring services and Murphy-controlled logging and analytics platforms.Licenses/ Certifications Preferred certifications include Microsoft Security Operations Analyst, Microsoft Sentinel certifications, Cribl Certified User / Administrator, Datadog certifications, Splunk certifications, Azure Security certifications, GIAC certifications (GCIH, GCFA, GMON), and CISSP. Certifications are preferred but do not replace recent hands-on engineering experience demonstrated.Qualifications/Requirements Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, Data Engineering, Computer Engineering, or a related technical field; or equivalent combination of education and hands-on experienceMinimum 15 years’ experience in cybersecurity, infrastructure engineering, cloud engineering, platform engineering, or security engineering, including at least 3 years of hands-on experience administering or engineering SIEM, security analytics, logging, or observability platforms.Hands-on experience investigating potential security incidents using SIEM, telemetry, and log analytics platforms, including analyzing high volumes of logs, network data, endpoint data, identity data, and other attack artifactsDemonstrated experience onboarding log sources, troubleshooting data ingestion, developing detection content, and writing production queries or detections using technologies such as KQL, SQL, SPL, Python, or PowerShellHands-on experience documenting Incident Response plans, playbooks, runbooks, engineering standards, and SOPs in line with security best practice standards such as NIST, SANS, etc.Knowledge of incident categories, incident responses, and timelines for responsesKnowledge of security best practice standards such as NIST CSF, NIST 800-53, ISO 27001, etc. Familiarity with a standardized incident response framework (SANS/NIST)Knowledge of different classes of attacks (e.g., passive, active, insider, distribution attacks)Knowledge of cyberattack vectors and stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, etc.) Knowledge of penetration testing principles, tools, and techniquesKnowledge of the basics of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection) Knowledge of Cyber Kill Chain methodology and/or MITRE ATT&CK framework, including the ability to map detection content to attacker techniques and identify visibility gapsExperience working with APIs, automation, integrations, telemetry pipelines, collectors, agents, event hubs, syslog, and cloud-native telemetry services.Able to manage multiple projects and initiatives concurrentlyAbility to work independently and with othersHighly organized with strong time-management skillsCandidates should be prepared to discuss SIEM, security data lake, observability platform, or telemetry pipeline they personally implemented or operated, including specific examples of data source onboarding, parser development, troubleshooting, detection engineering, automation, and operational ownershipThe individual is required to follow all applicable safety precautions. Work is performed almost entirely in controlled (i.e., inside) environment and does not typically subject the incumbent to any hazardous/ extreme elements; some positions may require regularly moving or transporting items weighing up to 25 lbs. around the office for various needs. Th successful candidate must be able to complete all essential physical requirements of the job with or without reasonable accommodation.Desired/Preferred Qualifications Minimum 2 years’ experience working in a managed SOC environment, ideally including integrations between managed SOC/MDR services and internally controlled logging or analytics platformsExperience supporting SOC operations across onshore and offshore resources, with emphasis on hands-on technical enablement, telemetry quality, alert fidelity, and detection engineering rather than formal people leadershipHands-on cyber incident response experience including prior experience responding to large scale incidents such as a Ransomware attack, supply chain attack, or data breach Recent hands-on experience implementing, administering, or operating industry-leading SIEM, security analytics, observability, or log management platforms such as Microsoft Sentinel, Google Security Operations (Chronicle), Splunk, Elastic, Cribl, Databricks, Datadog, or Microsoft Fabric.Strong experience managing large-scale telemetry and detections from Microsoft 365 Defender, Defender for Identity, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Conditional Access, Azure Defender/Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Intune, AWS, network devices, EDR, and SaaS platformsExperience deploying Security Orchestration, Automation and Response (SOAR) solutions and implementing automation opportunities that improve monitoring, detection, triage, enrichment, and response efficiencyExperience writing scripts and production queries, such as PowerShell, Python, KQL, SPL, SQL, or similar languages, to parse large data files, automate manual tasks, fetch and process data, develop detections, and troubleshoot platform or ingestion issuesExperience building or managing security data lakes, telemetry pipelines, log management platforms, detection engineering programs, or migrations from provider-hosted SIEM solutions to internally controlled logging and analytics platformsExperience working within the Oil/Gas industry, Critical Infrastructure, or OT/ICS monitoring environmentsKnowledge of network security implementations (e.g., host-based IDS, IPS, access control lists), including their function and placement in a networkKnowledge of system administration, network, and operating system hardening techniques#LI-Hybrid PURPOSEWe believe in providing energy that empowers people.MISSION We challenge the norm, tap into our strong legacy and use our foresight and financial discipline to deliver inspired energy solutions.VISION We see a future where we are an industry leader who is positively impacting lives for the next 100 years and beyond.VALUES & BEHAVIORSDo Right AlwaysRespect people, safety, environment and the lawFollow through on commitmentsMake it betterThink Beyond PossibleOffer solutionStep up and leadDon’t settle for “good enough”Embrace new opportunitiesStay With ItShow resilienceLean into challengesSupport each otherConsider the implications_________________________________________________________________________________________________Murphy Oil Corporation participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program. Please read the E-Verify Notice-English / E-Verify Notice-Spanish and Right to Work Notice before proceeding with your job application.For additional information, you may also visit the USCIS website.Murphy Oil Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, and status as a protected veteran, or any other category protected by federal, state or local laws.EEO is the Law Poster EEO is the Law SupplementRequisition ID5277- Posted09/22/2026-United States-Texas-Houston-IT-

Vacancy posted 22 hours ago
Similar jobs that could be interesting for youBased on the Staff, IT Security Specialist - Security Operations Center (SOC) in Houston, TX vacancy
  •  ...Soni's client is seeking a Senior Security Engineer to lead the design, modernization, and optimization of enterprise Security Operations Center (SOC) technologies. This role is responsible for security architecture, AI-driven threat detection, automation, and cloud security... 
    Suggested

    Soni Resources

    Houston, TX
    5 days ago
  • $105.4k - $207.8k

     ...and managed services that simplify complexity and strengthen resilience. In this role, you will support Next-Generation Security Operations Center (SOC) capabilities built on the CrowdStrike Falcon platform, including Falcon Next-Gen SIEM (NG SIEM), Falcon Insight... 
    Suggested
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    4 days ago
  • $105.4k - $207.8k

     ...we enable our clients to operate with resilience, grow...  ...and proactively manage to secure success. Recruiting for...  ...Lead/Engineering/SDMs and SOC Manager using documented...  ...Engineering, or related IT discipline; or...  ...inquiries to the Global Call Center (GCC) at USTalentCICInbox... 
    Suggested
    Work at office
    Local area
    Visa sponsorship
    Shift work
    Rotating shift

    Deloitte

    Houston, TX
    1 day ago
  • $105.4k - $207.8k

     ...we enable our clients to operate with resilience, grow...  ...and proactively manage to secure success. Recruiting for...  ...Threat Hunting teams and SOC analystsAct as escalation...  ...Engineering, or related IT discipline; or...  ...inquiries to the Global Call Center (GCC) at USTalentCICInbox... 
    Suggested
    Local area
    Visa sponsorship
    Shift work
    Rotating shift

    Deloitte

    Houston, TX
    4 days ago
  •  ...you want to own and evolve an advanced operational threat defense capability, grounded in...  ...for the outcomes that keep our clients secure?If yes, then Deloitte's Cyber Detect and...  ...monitoring and managed Security Operations Center (SOC) services, helping organizations adapt... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  •  ...by turning rapidly changing threats and operating environments into a clear strategy, and...  ...in helping to transform the cyber security services marketplace. Managing our industry...  ...years of experience in Security Operations Center (SOC), Managed Security Services, or Cyber... 
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  •  ...you’ll monitor, detect, and respond to security incidents, while working alongside experts...  ...(IOC)s Manage the Security Operations Center (SOC) mailbox, and monitor and analyze the emails...  ...substitution for associate degree. Experience in IT security, infrastructure or... 
    Work at office
    Remote work
    Monday to Friday
    Afternoon shift

    Virtuo Group Corporation

    Houston, TX
    8 days ago
  •  ...Software and Product Development, IT Outsourcing and Technology...  ...Chantilly, VA with off-shore delivery centers in India. We offer world-class...  ...experience in the information security fieldThree or more years of...  ...experience with the multiple operating systems (Windows, *nix, OSX,... 
    Remote work
    Worldwide

    USM Systems

    Houston, TX
    1 day ago
  • $82.6k - $162.8k

     ...simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/...  ...; and collaborate with security operations center analysts, threat hunters, incident responders... 
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    4 days ago
  •  ...you’re in the right place.About the roleDow has an opportunity for an Operational Technology (OT) Cyber Defense Specialist located in Midland, MI or Houston, TX. The Dow Cyber Security Operations Center (CSOC) is seeking an experienced Operational Technology (OT)... 
    Permanent employment
    Full time
    Work experience placement
    Live in
    Visa sponsorship
    Relocation package

    Dow

    Houston, TX
    23 hours ago
  • $198k - $368k

     ...join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part...  ...and cost efficiency of the GSOC (Global Security Operations Center) technology estate; contribute to the platform strategy and... 
    H1b
    Local area

    KPMG

    Houston, TX
    5 days ago
  •  ...drilling to decommissioning. We operate the world's premier fleet of...  ...as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and...  ...The Application Security Architect is responsible for building...  ...with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity... 
    Work at office
    Local area

    Oceaneering

    Houston, TX
    3 days ago
  •  ...leading capabilities in digital, cloud and security. Combining unmatched experience and...  ...Strategy and, Interactive, Technology, and Operations services, all powered by the world’s...  ...Advanced Technology and Intelligent Operations centers. Our 738,000 people deliver on the... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Houston, TX
    3 days ago
  • $82.6k - $162.8k

     ...simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/...  ...direct your inquiries to the Global Call Center (GCC) at ****@*****.***.... 
    Work at office
    Local area
    Visa sponsorship
    Shift work
    Rotating shift

    Deloitte

    Houston, TX
    1 day ago
  • $82.6k - $162.8k

     ...Helping clients protect people, assets, and critical operations requires a practical approach to physical security and resilience. As a Physical Security Consultant,...  ...security platforms, and security operations center processesPreparing risk assessments, technical reports... 
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  •  ...consulting, technology, operations, Song and Industry X...  ...ACCENTURE SECURITYAccenture Security helps organizations...  ...goalsCollaborate with client IT/OT teams, system...  ...gas, life sciences, data center OT)Minimum 3 years of hands...  ..., anomaly analysis, or SOC operations experience... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Houston, TX
    5 days ago
  • $134.5k - $265.1k

     ...and technology, but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats...  ...continuity support, and Global Security Operations Center workstreams, including monitoring, alarm response, incident... 
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  • $163.4k - $322.1k

     ...efforts that help clients strengthen physical security programs, align security capabilities to...  ...across people, facilities, assets, and operations. This role supports clients across...  ...technology, Global Security Operations Center (GSOC) technology, video management systems... 
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the...  ...and privacy standards, including FedRAMP, SOC 2 Type II, ISO 27001, PCI-DSS, and global...  ...incident management, threat and vulnerability operations, and business continuity planning. Bonus... 

    Confidential

    Houston, TX
    4 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry...  ...infrastructure security, and data protection, and direct experience with SOC 2, ISO 27001, NIST, and FedRAMP programs. The ideal candidate... 

    Confidential

    Houston, TX
    4 days ago
  • Title:Associate Security Engineer, Identity SecurityKBR is seeking an Associate Security Engineer to join our Identity Security Services...  ...solutions.Key ResponsibilitiesSupport the administration and operation of Microsoft Entra ID, Active Directory, hybrid identity, and... 
    Permanent employment
    Full time
    Local area
    Remote work

    KBR

    Houston, TX
    3 days ago
  • $110k - $135k

     ...seeking an experienced Security Engineer II, SecOps to...  ...Software Engineering, IT, Compliance, and GRC teams...  ...with HIPAA, HITRUST, SOC 2, PCI-DSS , and...  ...engineering, security operations, or related IT security...  ...streamlined and patient centered. Note: This job description... 
    Full time
    Temporary work
    Remote work
    Flexible hours

    GetixHealth

    Houston, TX
    4 days ago
  •  ....Accenture SecurityAccenture Security delivers continuous, rapid-fire...  ...that range from cloud, data centers and workplace to networks,...  ...or running an entire security operations center, we will help companies...  ...set by senior management as it relates to the teamTravel may... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Houston, TX
    2 days ago
  • $78.68k - $157.88k

     ..., and financial risks to operational, cyber, and regulatory risks...  ...Party Assurance Reports (SOC 1,2,3)System ImplementationsCyber Security AuditsInternal Control...  ...services, external audit, or IT auditDemonstrated ability...  ...to the Global Call Center (GCC) at USTalentCICInbox... 
    Work experience placement
    Work at office
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  • $143.25k - $179.04k

     ...expert guidance on technical security solutions, and ensure...  ...goals. Design secure IT environments and systems...  ...(NIST, ISO 27001, SOC 2, etc.). Architect and...  ...leadership and training to staff across departments,...  ...Available at our 260+ service centers Old Dominion... 
    Full time
    Temporary work
    Work experience placement
    Local area
    Immediate start
    Shift work
    Day shift

    Old Dominion Freight

    Houston, TX
    1 day ago
  • $82.6k - $162.8k

     ...strategies across business, technology, and operational environments while working with cross-...  ...Science, Information Systems, Cyber Security, or equivalent demonstrated technical background...  ...your inquiries to the Global Call Center (GCC) at ****@*****.***.... 
    Local area
    Visa sponsorship

    Deloitte

    Houston, TX
    3 days ago
  • $105.4k - $207.8k

     ...the place for you. Traditional security programs have often been...  ...recommendations, prioritized roadmaps, operating models, and implementation...  ...framework, such as ISO 27001/27017, SOC 2, PCI DSS, HIPAA, SOX, GLBA,...  ...inquiries to the Global Call Center (GCC) at USTalentCICInbox@... 
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Houston, TX
    5 days ago
  •  ...Headquartered in Houston, Oxy primarily operates in the United States, Middle East and...  ...individual to fill the position of Expert IT Cyber Security within our IT Cyber Security Operations...  ..., and collaborating closely with the SOC to deliver rapid response capabilities... 
    Full time
    Local area

    Occidental Petroleum

    Houston, TX
    2 days ago
  •  ...Services team to support network design, data center routing/switching, and large-scale SD-...  ...controller integration. The position operates on a hybrid schedule out of the Houston,...  ...Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable... 
    Work at office
    Local area
    Remote work

    InterSources

    Houston, TX
    5 days ago
  •  ...Houston.The Cybersecurity Advisor (or Security Advisor / SA as we call it) plays a critical...  ...Network Security; Offensive Security; Operations (SOC, SIEM, SOAR, UEBA, Threat Intelligence)...  .... Actively participate in the Field Center of Excellence for the assigned domain and... 
    Full time
    Work experience placement
    Local area
    Remote work
    Work from home

    Optiv

    Houston, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff, IT Security Specialist - Security Operations Center (SOC). Be the first to apply!