IT Cyber Security Expert

OXY, Inc.

Houston (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Oxy in Houston, Texas, is seeking an experienced Expert IT Cyber Security professional to join the IT Cyber Security Operations team. The role focuses on owning, optimizing, and scaling Microsoft Sentinel across hybrid IT and OT environments, ensuring robust threat detection and rapid response.

The successful candidate will manage end-to-end Sentinel data ingestion, ASIM parsing, custom KQL analytics, and automated playbooks with Azure Logic Apps, while collaborating with SOC analysts and

Qualifications

  • Bachelor's degree in computer science, cybersecurity, or a related area of study.
  • 7+ years administering enterprise SIEM platforms, with 3+ years hands-on with Microsoft Sentinel.
  • Strong proficiency in KQL and detection rule development.
  • Experience with log ingestion, parsing, and normalization from Windows, Linux, cloud, and OT sources.
  • Familiarity with MITRE ATT&CK and threat detection methodologies.
  • Understanding incident response workflows and SOAR integration.
  • Excellent communication and the ability to explain threats to diverse audiences.
  • Ability to work in a collaborative team using Waterfall and Scrum.

Responsibilities

  • Administer and maintain the Microsoft Sentinel SIEM platform, including log ingestion, ASIM parsing, normalization, and analytic rule tuning.
  • Develop and manage custom analytics rules, Workbooks, threat hunting queries, and alerts to detect security threats.
  • Design, build, and maintain automated workflows and mitigation playbooks using Azure Logic Apps and Sentinel Automation Rules.
  • Integrate data sources across on-prem, cloud, and OT environments for comprehensive visibility.
  • Monitor workspace health, performance, ingestion costs, and storage utilization.
  • Collaborate with SOC analysts, incident responders, and threat hunters to enhance detection.
  • Regularly review log sources and parsing accuracy to ensure data quality.
  • Support compliance and audit requirements with documentation and reporting.

Skills

Microsoft Sentinel
KQL
SIEM Administration
Threat Detection
SOAR Playbooks
Log Ingestion
OT Security
Incident Response
Communication
Project Mgmt

Education

Bachelor's degree in CS/Cybersecurity

Tools

Azure Logic Apps
Log Analytics
Azure Monitor
Kusto

Job description

Oxyproduces,markets and transportsoil and natural gas to maximize value and provide resources fundamental to life. The company leverages its global leadership incarbon managementto advance lower-carbon technologies and products. Headquartered in Houston, Oxy primarily operates in the United States, Middle East and North Africa. To learn more, visitOxy

Oxy strives to attract and retain talented employees by investing in their professional development and providing rewarding opportunities for personal growth. Our goal is to meet the highest employer standards by ensuring the health and safety of our employees, protecting the environment and positively impacting our communities where we do business.

We are looking for an experienced and motivated individual to fill the position of Expert IT Cyber Security within our IT Cyber Security Operations team group based in Houston, Texas. In this role, the candidate will serve as a Microsoft Sentinel SIEM Administrator to own, optimize, and scale our threat detection platform across hybrid IT and Operational Technology (OT) environments.

The candidate will manage the end-to-end administration of Microsoft Sentinel-inclusive data ingestion, ASIM parsing, and the engineering of custom KQL analytics rules-while building automated SOAR playbooks using Azure Logic Apps, optimizing workspace storage costs, and collaborating closely with the SOC to deliver rapid response capabilities and robust compliance monitoring.

Key Responsibilities:
  • Administer and maintain the Microsoft Sentinel SIEM platform, including log ingestion, ASIM parsing, normalization, and analytical rule tuning.
  • Develop and manage custom analytics rules, Workbooks (dashboards), threat hunting queries, and alerts to detect security threats.
  • Design, build, and maintain automated workflows and mitigation playbooks using Azure Logic Apps and Sentinel Automation Rules.
  • Integrate data sources across on-prem, cloud, and OT environments to ensure comprehensive visibility.
  • Monitor system health, performance, ingestion costs, and storage utilization (retention/archive tiers) of the Log Analytics Workspaces.
  • Collaborate with SOC analysts, incident responders, Security tools SMEs, and threat hunters to enhance detection.
  • Conduct regular reviews of log sources and parsing accuracy to ensure data quality.
  • Support compliance and audit requirements by maintaining documentation and reporting capabilities.
  • Stay current with emerging threats, SIEM technologies, and best practices.
  • Other security-related projects that may be assigned according to skills.
Required Qualifications:
  • Bachelor's degree in computer science, cybersecurity, or a related area of study.
  • 7+ years of experience administering enterprise SIEM platforms, with a strong preference for 3+ years of hands-on experience with Microsoft Sentinel.
  • Strong proficiency in Kusto Query Language (KQL), regex, or other query languages used in SIEM platforms, along with experience building custom detection rules.
  • Experience with log ingestion, parsing, and normalization from diverse sources (Windows, Linux, firewalls, cloud services, and OT systems).
  • Familiarity with the MITRE ATT&CK framework and threat detection methodologies.
  • Understanding of incident response workflows and integration with SOAR tools.
  • Ability to work with sensitive and confidential information while maintaining the highest level of confidentiality, professionalism, and ethics.
  • Excellent written and oral communication skills, with the ability to explain complex technical threats clearly to both technical and non-technical audiences.
  • Strong analytical troubleshooting capabilities and a proven ability to work independently while maintaining standard technical documentation.
  • Ability to work dynamically in a collaborative team environment utilizing structured project management frameworks (Waterfall and/or Scrum).
Desired Qualifications:
  • Relevant technical certifications are highly preferred, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CISSP, or GIAC (e.g., GCIH, GCIA).
  • Hands-on experience securing Operational Technology (OT/ICS) environments.
  • Knowledge of data governance and regulatory compliance frameworks governing enterprise and industrial environments (e.g., GDPR, NIST, ISO/IEC 27001 & 27019, or IEC 62443).

All qualified applicants will receive consideration for employment without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cyber Security Expert
IT Cyber Security Expert

Oxy • Georgia

On-site
USD 120,000 - 180,000
IT Cyber Security Expert
IT Cyber Security Expert

Occidental Petroleum Corporation • Houston (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Microsoft Sentinel SIEM Expert
Senior Microsoft Sentinel SIEM Expert

OXY, Inc. • Houston (TX)

On-site
USD 120,000 - 180,000
Senior Microsoft Sentinel SIEM Engineer (Hybrid IT/OT)
Senior Microsoft Sentinel SIEM Engineer (Hybrid IT/OT)

Oxy • Georgia

On-site
USD 120,000 - 180,000
Senior Microsoft Sentinel SIEM Architect (Hybrid IT/OT)
Senior Microsoft Sentinel SIEM Architect (Hybrid IT/OT)

Occidental Petroleum Corporation • Houston (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
IT Services Specialist II
IT Services Specialist II

Oxy • Houston (TX)

On-site
USD 65,000 - 90,000
Microsoft Sentinel Security Platform Engineer
Microsoft Sentinel Security Platform Engineer

Allied Consultants, Inc. • Austin (TX)

On-site
USD 120,000 - 190,000
Highly competitive pay rates
Medical insurance
401(k) plan with company match
+1
IT Services Specialist II
IT Services Specialist II

Oxy • Georgia

On-site
USD 70,000 - 95,000
Lead Security Operations Analyst
Lead Security Operations Analyst

Ledgent Technology • Houston (TX)

Hybrid
USD 110,000 - 150,000
Work-from-home flexibility
Occasional in-person meetings
Microsoft Sentinel Deployment Consultant
Microsoft Sentinel Deployment Consultant

Mission.dev • Northern (KY)

Hybrid
USD 90,000 - 130,000