Senior Vice President, Information Security

BNY Mellon

Houston (TX)

On-site

USD 220,000 - 350,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BNY Mellon in Houston, TX seeks a Senior Vice President for SIEM Engineering & Insider Risk Analytics SME. You will design, deploy, and optimize enterprise SIEM platforms to monitor security, detect insider risk, and support rapid response.

Lead correlation rules, UEBA models, and data analytics to identify High-Risk Users, integrate with threat intel and cloud monitoring, and drive continuous improvement across the insider risk program.

Qualifications

  • 10-12 years in information security or related tech.
  • Experience in SIEM engineering, cybersecurity operations, or data analytics.
  • Strong hands-on with enterprise SIEM platforms, rule/use-case development, and dashboards.

Responsibilities

  • Design, deploy, maintain SIEM platforms for monitoring and insider risk.
  • Develop correlation rules, UEBA models, and risk scoring.
  • Manage log ingestion pipelines from multiple sources.
  • Integrate SIEM with threat intel, identity, and case management.
  • Conduct threat analysis to support high-risk user identification.
  • Collaborate with insider threat analysts and fraud teams.
  • Enhance insider risk workflows and incident response.

Skills

SIEM engineering
Security operations
UEBA development
Data analytics
Python
SQL
Cloud security
Threat detection
Incident response

Tools

Splunk
Elastic Stack
Python
SQL
SOAR
Cloud monitoring

Job description

Senior Vice President, Information Security

We're seeking a future team member for the role of SIEM Engineering & Insider Risk Analytics SME to join our cybersecurity and insider risk team. This role is in Houston, TX.

Key Responsibilities
  • Design, stand up, configure, deploy, maintain, and support enterprise SIEM platforms for security monitoring, insider risk detection, and threat response.
  • Develop and fine-tune correlation rules, use cases, UEBA models, and behavioral analytics to identify High-Risk Users and detect insider risk, fraud, and advanced cyber threats, prioritizing risk through user inherent risk, observed behavior, and potential exposure to crown jewel assets.
  • Assist in the management of log ingestion pipelines and optimize data collection from network, endpoint, cloud, identity, workstation monitoring, and other security data sources.
  • Deploy, support, and troubleshoot User Enhanced Monitoring workstations and related platform integrations, performance, and data-processing pipelines.
  • Develop data models, analytics dashboards, reports, and risk-scoring approaches that enhance security monitoring, forensic investigations, and user risk prioritization.
  • Apply AI, machine learning, statistical analysis, and behavioral analytics to detect anomalies, identify emerging patterns, and improve insider risk detection.
  • Integrate SIEM, threat intelligence, endpoint, identity, case management, and other security applications into a unified insider risk program.
  • Conduct trend and threat analysis across multiple risk domains and a broad range of cyber and insider risk scenarios to support High-Risk User identification, crown jewel protection, proactive risk mitigation, early detection, and rapid response.
  • Collaborate with Insider Threat analysts, threat hunters, fraud teams, and other security partners to investigate incidents using SIEM, UEBA, endpoint, identity, and workstation monitoring data.
  • Maintain and enhance insider risk workflows through use case development, alert tuning, automation, process improvements, and response orchestration that reduce time to detection and response.
  • Assist in root cause analysis and remediation efforts for complex security threats.
Compliance & Optimization
  • Ensure SIEM configurations align with regulatory requirements (e.g., NIST, PCI DSS).
  • Maintain documentation for use cases, data flows, integrations, operating procedures, risk-scoring logic, and SIEM policies across the unified insider risk program.
  • Identify and implement improvements to log ingestion, data normalization, system scalability, analytic coverage, operational processes, and program effectiveness.
  • Provide peer review of use cases and threat models to ensure efficacy and effectiveness.
Qualifications & Experience

10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus

  • Experience in SIEM engineering, cybersecurity operations, or data analytics.
  • Strong hands-on experience with enterprise SIEM platforms, including platform implementation and support, rule and use case development, log ingestion, integrations, and dashboard development.
  • Proficiency in SQL, Python, Splunk, Elastic Stack, or other data analytics tools.
  • Experience with threat detection, UEBA development, AI and machine learning in security, and risk prioritization using both user inherent risk and user behavior.
  • Familiarity with cloud security monitoring (AWS, Azure, GCP) and integration with SIEM solutions.
  • Knowledge of MITRE ATT&CK, insider risk and fraud detection, user and entity behavior analytics, crown jewel protection, and a broad range of cyber threats, attack patterns, adversary techniques, and risk domains.
  • Strong understanding of log management, data correlation, and incident response frameworks.
  • Certifications such as SANS GIAC, CISSP, CEH, or relevant SIEM, analytics, cloud, or AI certifications are a plus.
Preferred Skills
  • Experience working in the financial sector with a focus on fraud prevention, insider risk, or compliance monitoring.
  • Knowledge of big data platforms (Hadoop, Spark, Snowflake), automation tools (SOAR, Python scripting, APIs), and integration patterns for connecting security applications across an insider risk ecosystem.
  • Experience applying analytics across multiple risk domains to identify High-Risk Users, assess access and behavioral risk, and protect crown jewel assets and other critical resources.
  • Experience deploying and supporting User Enhanced Monitoring workstations, working with large datasets, and building predictive or AI-assisted models for actionable security insights.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior VP of SIEM & Insider Risk Analytics
Senior VP of SIEM & Insider Risk Analytics

BNY Mellon • Houston (TX)

On-site
USD 220,000 - 350,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Risk & Cyber Analytics.
Risk & Cyber Analytics.

Recurring Decimal • New Jersey

On-site
USD 90,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate, LLC. • Richmond (VA)

On-site
USD 110,000 - 140,000
Senior Cybersecurity Analyst #3344
Senior Cybersecurity Analyst #3344

Genius Road, LLC • Austin (TX)

Hybrid
USD 150,000 - 190,000
Certified Women’s Business Enterprise
Equal Opportunity Employer
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Network Security Analyst 2
Network Security Analyst 2

Akaasa Technologies • United States

On-site
USD 120,000 - 160,000
Cyber Data Analytics Lead – 150281
Cyber Data Analytics Lead – 150281

Sovereign Technologies, LLC. • St. Louis (MO), Northern (KY)

Hybrid
USD 110,000 - 170,000
Access to cutting-edge analytics tools
On-site role in St. Louis
Sr SIEM Data Engineer
Sr SIEM Data Engineer

Shain Associates • Quincy (MA)

Hybrid
USD 140,000 - 190,000