Staff, IT Security Specialist - Security Operations Center (SOC)

Murphy Oil Corp
  • Houston, TX
    2 days ago

    Job Description

    Career Opportunities: Staff, IT Security Specialist - Security Operations Center (SOC) (5277)

    Requisition ID 5277 - Posted 09/22/2026 - United States - Texas - Houston - IT

    At Murphy Oil Corporation, we believe the rich experiences and backgrounds of our employees strengthen our Company, create a productive workforce, and drive our success. We encourage you to apply for the positions for which you meet the qualifications.

    Job Summary

    Murphy Oil Corporation is looking for an IT Security Specialist to support our growing Global Cybersecurity team. The ideal candidate is a highly technical and hands-on cybersecurity professional who will support the design, implementation, administration, and continuous improvement of Murphy's security monitoring, logging, detection, and incident response capabilities. This role supports the Security Operations Center (SOC) function with a primary focus on SIEM engineering, detection engineering, security telemetry management, and security operations enablement.

    The right candidate has recent hands-on experience deploying, configuring, operating, and troubleshooting SIEM platforms, security data lakes, observability platforms, and log management solutions. This individual remains actively involved in technical implementation work, including onboarding data sources, creating data pipelines, developing detection content, writing queries, automating workflows, troubleshooting production issues, and working with stakeholders in the business, internal IT, Operations, and third-party service providers to securely enable the business.

    This is an individual contributor role requiring strong technical depth and hands-on engineering experience. Candidates whose recent experience has primarily been focused on people leadership, program management, governance, or vendor management may not be the best fit.

    The IT Security Specialist will work in our Houston Corporate office and may work two (2) days a week remote.

    Responsibilities

    • Contribute to cybersecurity vision, roadmap, and execution plan, with emphasis on security monitoring, logging, telemetry, SIEM engineering, and detection engineering capabilities.
    • Lead and mature technical incident response enablement, including updating plans, documenting playbooks, facilitating cyber drills, improving security telemetry, coordinating with Incident Response vendors, setting up alternate communication channels, and implementing automation to reduce response time.
    • Respond to security-related incidents by creating queries, validating telemetry, assisting with forensic analysis, determining scope, urgency, potential impact, and materiality, identifying relevant vulnerabilities, and making recommendations that enable expeditious remediation.
    • Support day-to-day SOC operations by partnering with Murphy's managed SOC provider to optimize monitoring, alert quality, response workflows, help desk tickets, incidents, cases, and visibility across security data sources.
    • Provide technical support for on-call and after-hours security response by ensuring required telemetry, detection logic, queries, dashboards, and runbooks are available to support timely investigation and escalation.
    • Collaborate with service desk, infrastructure, cloud, OT, and application teams to deploy critical security patches in a timely, risk-based manner, formalize vulnerability management processes, improve telemetry coverage, and introduce automation.
    • Collaborate with the Head of IT Security to implement security architecture best practices within incident response, daily SOC activities, logging architecture, detection coverage, and security data platform design.
    • Support the Head of IT Security by providing technical guidance to the cybersecurity team in managing day-to-day security operations, improving detection content, strengthening telemetry coverage, and responding to incidents.
    • Establish and maintain technical metrics to measure SOC and security data platform effectiveness, including detection coverage, telemetry quality, ingestion health, false positive rate, MTTD, MTTR, and SLA adherence.
    • Establish relationships between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies, vendors, public relations professionals)
    • Keep current with latest cyber security developments, threat intelligence, attacker techniques, emerging tools, technologies, and security monitoring best practices, and translate relevant developments into detection use cases and hunting content.
    • Manage the lifecycle, configuration, health, and operational effectiveness of security-related products, including SIEM, log management, security analytics, observability, SOAR, and telemetry pipeline technologies.
    • Design, implement, administer, and maintain enterprise SIEM, security analytics, security data lake, observability, and log management capabilities.
    • Configure and manage log collection, normalization, enrichment, routing, filtering, retention, and ingestion pipelines using APIs, syslog, collectors, agents, event hubs, and cloud-native telemetry services.
    • Onboard new log sources from cloud, endpoint, identity, infrastructure, network, application, SaaS, and OT environments; troubleshoot ingestion issues, missing telemetry, parsing failures, duplicate events, and logging gaps.
    • Develop, tune, and maintain SIEM correlation rules, detections, alerts, dashboards, queries, hunting content, and automation workflows; map detections to MITRE ATT&CK and continuously reduce false positives.
    • Actively identify, recommend, and implement cybersecurity and risk management solutions that ensure business needs are met while enhancing the organization's security posture, and maturing the cybersecurity function
    • Ensure cloud security considerations are integrated into overall security operations, including appropriate telemetry onboarding, detection coverage, monitoring dashboards, alerting, and response workflows for Azure, AWS, Microsoft Defender, Entra ID, SaaS, and cloud-native services.
    • Lead special projects as assigned
    • Coordinate with relevant teams and managed SOC/MDR providers to manage risks associated with third-party relationships and optimize integrations between provider monitoring services and Murphy-controlled logging and analytics platforms.

    Licenses/ Certifications

    Preferred certifications include Microsoft Security Operations Analyst, Microsoft Sentinel certifications, Cribl Certified User / Administrator, Datadog certifications, Splunk certifications, Azure Security certifications, GIAC certifications (GCIH, GCFA, GMON), and CISSP. Certifications are preferred but do not replace recent hands-on engineering experience demonstrated.

    Qualifications/Requirements

    • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, Data Engineering, Computer Engineering, or a related technical field; or equivalent combination of education and hands-on experience
    • Minimum 15 years' experience in cybersecurity, infrastructure engineering, cloud engineering, platform engineering, or security engineering, including at least 3 years of hands-on experience administering or engineering SIEM, security analytics, logging, or observability platforms.
    • Hands-on experience investigating potential security incidents using SIEM, telemetry, and log analytics platforms, including analyzing high volumes of logs, network data, endpoint data, identity data, and other attack artifacts
    • Demonstrated experience onboarding log sources, troubleshooting data ingestion, developing detection content, and writing production queries or detections using technologies such as KQL, SQL, SPL, Python, or PowerShell
    • Hands-on experience documenting Incident Response plans, playbooks, runbooks, engineering standards, and SOPs in line with security best practice standards such as NIST, SANS, etc.
    • Knowledge of incident categories, incident responses, and timelines for responses
    • Knowledge of security best practice standards such as NIST CSF, NIST 800-53, ISO 27001, etc.
    • Familiarity with a standardized incident response framework (SANS/NIST)
    • Knowledge of different classes of attacks (e.g., passive, active, insider, distribution attacks)
    • Knowledge of cyberattack vectors and stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, etc.)
    • Knowledge of penetration testing principles, tools, and techniques
    • Knowledge of the basics of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection)
    • Knowledge of Cyber Kill Chain methodology and/or MITRE ATT&CK framework, including the ability to map detection content to attacker techniques and identify visibility gaps
    • Experience working with APIs, automation, integrations, telemetry pipelines, collectors, agents, event hubs, syslog, and cloud-native telemetry services.
    • Able to manage multiple projects and initiatives concurrently
    • Ability to work independently and with others
    • Highly organized with strong time-management skills
    • Candidates should be prepared to discuss SIEM, security data lake, observability platform, or telemetry pipeline they personally implemented or operated, including specific examples of data source onboarding, parser development, troubleshooting, detection engineering, automation, and operational ownership

    The individual is required to follow all applicable safety precautions. Work is performed almost entirely in controlled (i.e., inside) environment and does not typically subject the incumbent to any hazardous/ extreme elements; some positions may require regularly moving or transporting items weighing up to 25 lbs. around the office for various needs. Th successful candidate must be able to complete all essential physical requirements of the job with or without reasonable accommodation.

    Desired/Preferred Qualifications

    • Minimum 2 years' experience working in a managed SOC environment, ideally including integrations between managed SOC/MDR services and internally controlled logging or analytics platforms
    • Experience supporting SOC operations across onshore and offshore resources, with emphasis on hands-on technical enablement, telemetry quality, alert fidelity, and detection engineering rather than formal people leadership
    • Hands-on cyber incident response experience including prior experience responding to large scale incidents such as a Ransomware attack, supply chain attack, or data breach
    • Recent hands-on experience implementing, administering, or operating industry-leading SIEM, security analytics, observability, or log management platforms such as Microsoft Sentinel, Google Security Operations (Chronicle), Splunk, Elastic, Cribl, Databricks, Datadog, or Microsoft Fabric.
    • Strong experience managing large-scale telemetry and detections from Microsoft 365 Defender, Defender for Identity, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Conditional Access, Azure Defender/Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Intune, AWS, network devices, EDR, and SaaS platforms
    • Experience deploying Security Orchestration, Automation and Response (SOAR) solutions and implementing automation opportunities that improve monitoring, detection, triage, enrichment, and response efficiency
    • Experience writing scripts and production queries, such as PowerShell, Python, KQL, SPL, SQL, or similar languages, to parse large data files, automate manual tasks, fetch and process data, develop detections, and troubleshoot platform or ingestion issues
    • Experience building or managing security data lakes, telemetry pipelines, log management platforms, detection engineering programs, or migrations from provider-hosted SIEM solutions to internally controlled logging and analytics platforms
    • Experience working within the Oil/Gas industry, Critical Infrastructure, or OT/ICS monitoring environments
    • Knowledge of network security implementations (e.g., host-based IDS, IPS, access control lists), including their function and placement in a network
    • Knowledge of system administration, network, and operating system hardening techniques

    #LI-Hybrid

    PURPOSE

    We believe in providing energy that empowers people.

    MISSION

    We challenge the norm, tap into our strong legacy and use our foresight and financial discipline to deliver inspired energy solutions.

    VISION

    We see a future where we are an industry leader who is positively impacting lives for the next 100 years and beyond.

    VALUES & BEHAVIORS

    Do Right Always

    • Respect people, safety, environment and the law
    • Follow through on commitments
    • Make it better

    Think Beyond Possible

    • Offer solution
    • Step up and lead
    • Don't settle for "good enough"
    • Embrace new opportunities

    Stay With It

    • Show resilience
    • Lean into challenges
    • Support each other
    • Consider the implications

    _____

    Murphy Oil Corporation participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program. Please read the E-Verify Notice-English / E-Verify Notice-Spanish and Right to Work Notice before proceeding with your job application.

    For additional information, you may also visit the USCIS website.

    Murphy Oil Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, and status as a protected veteran, or any other category protected by federal, state or local laws.

    EEO is the Law Poster

    EEO is the Law Supplement

    Email this job to a friend

    The job has been sent to

    Please provide the information below Job title: *Your friend's email address: Message:

    Maximum character limit: 1000

    • Confirm you are not a robot:

    Numbers & Facts

    LocationHouston, TX

    Skills

    • Access Controlunmatched
    • Alliance/Partner Marketingunmatched
    • Amazon Web Services (AWS)unmatched
    • Application Programming Interface (API)unmatched
    • Authenticationunmatched
    • Automationunmatched
    • Best Practicesunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Computer Engineeringunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Content Developmentunmatched
    • Continuous Improvementunmatched
    • Cryptographyunmatched
    • Customer Support/Serviceunmatched
    • Data Lakeunmatched
    • Data Managementunmatched
    • Data Processingunmatched
    • Documentationunmatched
    • E Programming Languageunmatched
    • Emerging Technologyunmatched
    • Engineeringunmatched
    • English Languageunmatched
    • Enterprise Protectionunmatched
    • Environmental Monitoringunmatched
    • Firewallsunmatched
    • Follow Throughunmatched
    • Forensic Scienceunmatched
    • GCFA - GIAC Certified Forensic Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Help Deskunmatched
    • Homeland Securityunmatched
    • Honeypotsunmatched
    • Hubsunmatched
    • Huntingunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identify Issuesunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Law Enforcementunmatched
    • Leadershipunmatched
    • Legalunmatched
    • Metricsunmatched
    • Microsoft Access Databaseunmatched
    • Microsoft Certificationsunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Multitaskingunmatched
    • Network Administration/Managementunmatched
    • Network Securityunmatched
    • Offshoringunmatched
    • Oil and Gasunmatched
    • On Callunmatched
    • Onboardingunmatched
    • Operating Systemsunmatched
    • Operational Auditunmatched
    • Operational Improvementunmatched
    • Operational Supportunmatched
    • Operations Processesunmatched
    • Operations Security (OPSEC)unmatched
    • Organizational Skillsunmatched
    • Penetration Testingunmatched
    • Physical Demandsunmatched
    • Process Improvementunmatched
    • Product Lifecycleunmatched
    • Project/Program Managementunmatched
    • Public/Media/Press/Analyst Relationsunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Monitoringunmatched
    • Ransomwareunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • SQL (Structured Query Language)unmatched
    • Sales Pipelineunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Designunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Security Patchesunmatched
    • Service Level Agreement (SLA)unmatched
    • Software Engineeringunmatched
    • Software as a Service (SaaS)unmatched
    • Splunkunmatched
    • Standard Operating Procedures (SOP)unmatched
    • Supply Chainunmatched
    • Systems Administration/Managementunmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • Technical Supportunmatched
    • Telemetryunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenship and Immigration Services (USCIS)unmatched
    • Use Casesunmatched
    • Vendor/Supplier Managementunmatched
    • Vendor/Supplier Selectionunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder