About The Position

Murphy Oil Corporation is seeking an IT Security Specialist to join its Global Cybersecurity team. This role focuses on supporting the design, implementation, administration, and continuous improvement of the company's security monitoring, logging, detection, and incident response capabilities. The position is primarily centered on SIEM engineering, detection engineering, security telemetry management, and enabling security operations within the Security Operations Center (SOC). The ideal candidate will have recent hands-on experience with SIEM platforms, security data lakes, observability platforms, and log management solutions, actively participating in technical implementation, data onboarding, detection development, automation, and troubleshooting. This is an individual contributor role requiring deep technical expertise and hands-on engineering experience, not primarily focused on people leadership, program management, governance, or vendor management. The role is based in the Houston Corporate office with the option for two remote workdays per week.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, Data Engineering, Computer Engineering, or a related technical field; or equivalent combination of education and hands-on experience.
  • Minimum 15 years’ experience in cybersecurity, infrastructure engineering, cloud engineering, platform engineering, or security engineering, including at least 3 years of hands-on experience administering or engineering SIEM, security analytics, logging, or observability platforms.
  • Hands-on experience investigating potential security incidents using SIEM, telemetry, and log analytics platforms, including analyzing high volumes of logs, network data, endpoint data, identity data, and other attack artifacts.
  • Demonstrated experience onboarding log sources, troubleshooting data ingestion, developing detection content, and writing production queries or detections using technologies such as KQL, SQL, SPL, Python, or PowerShell.
  • Hands-on experience documenting Incident Response plans, playbooks, runbooks, engineering standards, and SOPs in line with security best practice standards such as NIST, SANS, etc.
  • Knowledge of incident categories, incident responses, and timelines for responses.
  • Knowledge of security best practice standards such as NIST CSF, NIST 800-53, ISO 27001, etc.
  • Familiarity with a standardized incident response framework (SANS/NIST).
  • Knowledge of different classes of attacks (e.g., passive, active, insider, distribution attacks).
  • Knowledge of cyberattack vectors and stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, etc.).
  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of the basics of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection).
  • Knowledge of Cyber Kill Chain methodology and/or MITRE ATT&CK framework, including the ability to map detection content to attacker techniques and identify visibility gaps.
  • Experience working with APIs, automation, integrations, telemetry pipelines, collectors, agents, event hubs, syslog, and cloud-native telemetry services.
  • Able to manage multiple projects and initiatives concurrently.
  • Ability to work independently and with others.
  • Highly organized with strong time-management skills.
  • Candidates should be prepared to discuss SIEM, security data lake, observability platform, or telemetry pipeline they personally implemented or operated, including specific examples of data source onboarding, parser development, troubleshooting, detection engineering, automation, and operational ownership.
  • The individual is required to follow all applicable safety precautions.
  • Work is performed almost entirely in controlled (i.e., inside) environment and does not typically subject the incumbent to any hazardous/ extreme elements; some positions may require regularly moving or transporting items weighing up to 25 lbs. around the office for various needs.
  • The successful candidate must be able to complete all essential physical requirements of the job with or without reasonable accommodation.

Nice To Haves

  • Preferred certifications include Microsoft Security Operations Analyst, Microsoft Sentinel certifications, Cribl Certified User / Administrator, Datadog certifications, Splunk certifications, Azure Security certifications, GIAC certifications (GCIH, GCFA, GMON), and CISSP. Certifications are preferred but do not replace recent hands-on engineering experience demonstrated.
  • Minimum 2 years’ experience working in a managed SOC environment, ideally including integrations between managed SOC/MDR services and internally controlled logging or analytics platforms.
  • Experience supporting SOC operations across onshore and offshore resources, with emphasis on hands-on technical enablement, telemetry quality, alert fidelity, and detection engineering rather than formal people leadership.
  • Hands-on cyber incident response experience including prior experience responding to large scale incidents such as a Ransomware attack, supply chain attack, or data breach.
  • Recent hands-on experience implementing, administering, or operating industry-leading SIEM, security analytics, observability, or log management platforms such as Microsoft Sentinel, Google Security Operations (Chronicle), Splunk, Elastic, Cribl, Databricks, Datadog, or Microsoft Fabric.
  • Strong experience managing large-scale telemetry and detections from Microsoft 365 Defender, Defender for Identity, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Conditional Access, Azure Defender/Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Intune, AWS, network devices, EDR, and SaaS platforms.
  • Experience deploying Security Orchestration, Automation and Response (SOAR) solutions and implementing automation opportunities that improve monitoring, detection, triage, enrichment, and response efficiency.
  • Experience writing scripts and production queries, such as PowerShell, Python, KQL, SPL, SQL, or similar languages, to parse large data files, automate manual tasks, fetch and process data, develop detections, and troubleshoot platform or ingestion issues.
  • Experience building or managing security data lakes, telemetry pipelines, log management platforms, detection engineering programs, or migrations from provider-hosted SIEM solutions to internally controlled logging and analytics platforms.
  • Experience working within the Oil/Gas industry, Critical Infrastructure, or OT/ICS monitoring environments.
  • Knowledge of network security implementations (e.g., host-based IDS, IPS, access control lists), including their function and placement in a network.
  • Knowledge of system administration, network, and operating system hardening techniques.

Responsibilities

  • Contribute to cybersecurity vision, roadmap, and execution plan, with emphasis on security monitoring, logging, telemetry, SIEM engineering, and detection engineering capabilities.
  • Lead and mature technical incident response enablement, including updating plans, documenting playbooks, facilitating cyber drills, improving security telemetry, coordinating with Incident Response vendors, setting up alternate communication channels, and implementing automation to reduce response time.
  • Respond to security-related incidents by creating queries, validating telemetry, assisting with forensic analysis, determining scope, urgency, potential impact, and materiality, identifying relevant vulnerabilities, and making recommendations that enable expeditious remediation.
  • Support day-to-day SOC operations by partnering with Murphy’s managed SOC provider to optimize monitoring, alert quality, response workflows, help desk tickets, incidents, cases, and visibility across security data sources.
  • Provide technical support for on-call and after-hours security response by ensuring required telemetry, detection logic, queries, dashboards, and runbooks are available to support timely investigation and escalation.
  • Collaborate with service desk, infrastructure, cloud, OT, and application teams to deploy critical security patches in a timely, risk-based manner, formalize vulnerability management processes, improve telemetry coverage, and introduce automation.
  • Collaborate with the Head of IT Security to implement security architecture best practices within incident response, daily SOC activities, logging architecture, detection coverage, and security data platform design.
  • Support the Head of IT Security by providing technical guidance to the cybersecurity team in managing day-to-day security operations, improving detection content, strengthening telemetry coverage, and responding to incidents.
  • Establish and maintain technical metrics to measure SOC and security data platform effectiveness, including detection coverage, telemetry quality, ingestion health, false positive rate, MTTD, MTTR, and SLA adherence.
  • Establish relationships between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies, vendors, public relations professionals).
  • Keep current with latest cyber security developments, threat intelligence, attacker techniques, emerging tools, technologies, and security monitoring best practices, and translate relevant developments into detection use cases and hunting content.
  • Manage the lifecycle, configuration, health, and operational effectiveness of security-related products, including SIEM, log management, security analytics, observability, SOAR, and telemetry pipeline technologies.
  • Design, implement, administer, and maintain enterprise SIEM, security analytics, security data lake, observability, and log management capabilities.
  • Configure and manage log collection, normalization, enrichment, routing, filtering, retention, and ingestion pipelines using APIs, syslog, collectors, agents, event hubs, and cloud-native telemetry services.
  • Onboard new log sources from cloud, endpoint, identity, infrastructure, network, application, SaaS, and OT environments; troubleshoot ingestion issues, missing telemetry, parsing failures, duplicate events, and logging gaps.
  • Develop, tune, and maintain SIEM correlation rules, detections, alerts, dashboards, queries, hunting content, and automation workflows; map detections to MITRE ATT&CK and continuously reduce false positives.
  • Actively identify, recommend, and implement cybersecurity and risk management solutions that ensure business needs are met while enhancing the organization’s security posture, and maturing the cybersecurity function.
  • Ensure cloud security considerations are integrated into overall security operations, including appropriate telemetry onboarding, detection coverage, monitoring dashboards, alerting, and response workflows for Azure, AWS, Microsoft Defender, Entra ID, SaaS, and cloud-native services.
  • Lead special projects as assigned.
  • Coordinate with relevant teams and managed SOC/MDR providers to manage risks associated with third-party relationships and optimize integrations between provider monitoring services and Murphy-controlled logging and analytics platforms.

Benefits

  • We believe in providing energy that empowers people.
  • We challenge the norm, tap into our strong legacy and use our foresight and financial discipline to deliver inspired energy solutions.
  • We see a future where we are an industry leader who is positively impacting lives for the next 100 years and beyond.
  • Do Right Always
  • Respect people, safety, environment and the law
  • Follow through on commitments
  • Make it better
  • Think Beyond Possible
  • Offer solution
  • Step up and lead
  • Don’t settle for “good enough”
  • Embrace new opportunities
  • Stay With It
  • Show resilience
  • Lean into challenges
  • Support each other
  • Consider the implications
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service