Security Operations Center Analyst

OceaneeringHouston, TX
Hybrid

About The Position

The Security Operations Center Analyst is responsible for the administration, support, optimization, and expansion of the organization's security monitoring and log management platforms, including Splunk and Cribl. This role serves as a key contributor to security operations by ensuring reliable collection, processing, and analysis of security telemetry across both IT and Operational Technology (OT) environments. The role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
  • Minimum 3 years of experience supporting security monitoring, SIEM, or security engineering platforms.
  • Minimum 1 year’s experience administering Splunk Enterprise.
  • Minimum 1 year’s experience supporting Cribl or similar log management technologies.
  • Minimum 1 year’s experience with Syslog architecture and log ingestion technologies.
  • Minimum 1 year’s experience supporting Managed Detection and Response (MDR) services or Security Operations Centers.
  • Minimum 1 year’s experience working with Windows, Linux, network, and cloud log sources.
  • Familiarity with Operational Technology (OT) and Industrial Control System (ICS) environments.

Nice To Haves

  • Splunk Certified Administrator or Splunk Certified Architect certification.
  • Experience with industrial networking and OT/ICS environments.
  • Experience integrating enterprise logging platforms with MDR providers.
  • Knowledge of NIST Cybersecurity Framework, IEC 62443, or ISA/IEC industrial security standards.
  • Experience with scripting and automation using PowerShell, Python, or similar tools.
  • Familiarity with Microsoft Azure and cloud security monitoring.

Responsibilities

  • Support the integration and ongoing operation of the Managed Detection and Response (MDR) Security Operations Center (SOC), enabling effective threat detection, incident investigation, and security monitoring capabilities.
  • Design, implement, and maintain secure log forwarding infrastructure, including Syslog collectors and forwarders within the OT DMZ (Level 3.5) of the Purdue Model, ensuring visibility into critical industrial control system environments while maintaining required segmentation and security controls.
  • Administer and maintain Splunk infrastructure, including search heads, indexers, forwarders, and supporting services.
  • Configure and optimize data ingestion, indexing, retention, and storage management for Splunk.
  • Troubleshoot Splunk platform issues and coordinate remediation activities.
  • Develop and maintain Splunk dashboards, alerts, reports, and operational monitoring content.
  • Ensure Splunk system availability, performance, scalability, and compliance with organizational requirements.
  • Coordinate Splunk upgrades, patching, and lifecycle management activities.
  • Administer and support Cribl Stream infrastructure and associated log pipelines.
  • Develop and maintain Cribl log routing, filtering, enrichment, masking, and normalization workflows.
  • Optimize data collection in Cribl to improve security visibility while controlling storage and licensing costs.
  • Monitor and troubleshoot ingestion issues across multiple log sources in Cribl.
  • Collaborate with infrastructure, network, and security teams to onboard new data sources into Cribl.
  • Support deployment and integration activities associated with the managed security operations center (MDR SOC).
  • Coordinate onboarding of log sources and security telemetry required for threat monitoring.
  • Partner with MDR analysts to improve detection coverage and data quality.
  • Validate alerting, event correlation, and incident workflows.
  • Assist with tuning security use cases to reduce false positives and improve operational effectiveness.
  • Participate in ongoing operational reviews and continuous improvement activities.
  • Design, implement, and support Syslog forwarding architecture within OT environments.
  • Deploy and maintain log collectors and forwarders within the Level 3.5 OT DMZ in accordance with the Purdue Model.
  • Work with OT, Infrastructure, and Network teams to onboard industrial and manufacturing systems into enterprise monitoring platforms.
  • Ensure security monitoring solutions align with OT segmentation and regulatory requirements.
  • Troubleshoot connectivity, log collection, and data quality issues across OT environments.
  • Support secure transmission and retention of OT security events.
  • Investigate platform-generated alerts and assist with security incident response activities.
  • Validate integrity and availability of security monitoring infrastructure.
  • Support audit, compliance, and regulatory reporting requirements.
  • Maintain engineering documentation, architecture diagrams, and operational procedures.
  • Participate in after-hours support activities when required.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service