IT Cyber Security Expert
Oxy · Houston, TX · 2 days ago
Information TechnologyFull-time
About the role
Oxy is seeking an experienced and motivated Expert IT Cyber Security professional to join the IT Cyber Security Operations team in Houston, Texas. This role serves as a Microsoft Sentinel SIEM Administrator to own, optimize, and scale the threat detection platform across hybrid IT and Operational Technology (OT) environments. The candidate will manage end-to-end administration of Microsoft Sentinel—including data ingestion, ASIM parsing, and engineering custom KQL analytics rules—while building automated SOAR playbooks using Azure Logic Apps, optimizing workspace storage costs, and collaborating closely with the SOC to deliver rapid response capabilities and robust compliance monitoring.
Responsibilities
- Administer and maintain the Microsoft Sentinel SIEM platform, including log ingestion, ASIM parsing, normalization, and analytical rule tuning.
- Develop and manage custom analytics rules, Workbooks (dashboards), threat hunting queries, and alerts to detect security threats.
- Design, build, and maintain automated workflows and mitigation playbooks using Azure Logic Apps and Sentinel Automation Rules.
- Integrate data sources across on-prem, cloud, and OT environments to ensure comprehensive visibility.
- Monitor system health, performance, ingestion costs, and storage utilization (retention/archive tiers) of the Log Analytics Workspaces.
- Collaborate with SOC analysts, incident responders, Security tools SMEs, and threat hunters to enhance detection.
- Conduct regular reviews of log sources and parsing accuracy to ensure data quality.
- Support compliance and audit requirements by maintaining documentation and reporting capabilities.
- Stay current with emerging threats, SIEM technologies, and best practices.
- Other security-related projects that may be assigned according to skills.
Required Qualifications
- Bachelor's degree in computer science, cybersecurity, or a related area of study.
- 7+ years of experience administering enterprise SIEM platforms, with a strong preference for 3+ years of hands-on experience with Microsoft Sentinel.
- Strong proficiency in Kusto Query Language (KQL), regex, or other query languages used in SIEM platforms, along with experience building custom detection rules.
- Experience with log ingestion, parsing, and normalization from diverse sources (Windows, Linux, firewalls, cloud services, and OT systems).
- Familiarity with the MITRE ATT&CK framework and threat detection methodologies.
- Understanding of incident response workflows and integration with SOAR tools.
- Ability to work with sensitive and confidential information while maintaining the highest level of confidentiality, professionalism, and ethics.
- Excellent written and oral communication skills, with the ability to explain complex technical threats clearly to both technical and non-technical audiences.
- Strong analytical troubleshooting capabilities and a proven ability to work independently while maintaining standard technical documentation.
- Ability to work dynamically in a collaborative team environment utilizing structured project management frameworks (Waterfall and/or Scrum).
Desired Qualifications
- Relevant technical certifications are highly preferred, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CISSP, or GIAC (e.g., GCIH, GCIA).
- Hands-on experience securing Operational Technology (OT/ICS) environments.
- Knowledge of data governance and regulatory compliance frameworks governing enterprise and industrial environments (e.g., GDPR, NIST, ISO/IEC 27001 & 27019, or IEC 62443).