Job DescriptionThe Security Operations Center Analyst is responsible for the administration, support, optimization, and expansion of the organization's security monitoring and log management platforms, including Splunk and Cribl. This role serves as a key contributor to security operations by ensuring reliable collection, processing, and analysis of security telemetry across both IT and Operational Technology (OT) environments.
- Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
ResponsibilitiesFunctions- The position is responsible for supporting the integration and ongoing operation of the Managed Detection and Response (MDR) Security Operations Center (SOC), enabling effective threat detection, incident investigation, and security monitoring capabilities.
- Additionally, the role designs, implements, and maintains secure log forwarding infrastructure, including Syslog collectors and forwarders within the OT DMZ (Level 3.5) of the Purdue Model, ensuring visibility into critical industrial control system environments while maintaining required segmentation and security controls.
Splunk Administration & Engineering- Administer and maintain Splunk infrastructure, including search heads, indexers, forwarders, and supporting services.
- Configure and optimize data ingestion, indexing, retention, and storage management.
- Troubleshoot platform issues and coordinate remediation activities.
- Develop and maintain Splunk dashboards, alerts, reports, and operational monitoring content.
- Ensure system availability, performance, scalability, and compliance with organizational requirements.
- Coordinate upgrades, patching, and lifecycle management activities.
Cribl Administration & Engineering- Administer and support Cribl Stream infrastructure and associated log pipelines.
- Develop and maintain log routing, filtering, enrichment, masking, and normalization workflows.
- Optimize data collection to improve security visibility while controlling storage and licensing costs.
- Monitor and troubleshooting of ingestion issues across multiple log sources.
- Collaborate with infrastructure, network, and security teams to onboard new data sources
MDR SOC Integration & Operations- Support deployment and integration activities associated with the managed security operations center (MDR SOC).
- Coordinate onboarding of log sources and security telemetry required for threat monitoring.
- Partner with MDR analysts to improve detection coverage and data quality.
- Validate alerting, event correlation, and incident workflows.
- Assist with tuning security use cases to reduce false positives and improve operational effectiveness.
- Participate in ongoing operational reviews and continuous improvement activities.
OT Security Monitoring & Syslog Infrastructure- Design, implement, and support Syslog forwarding architecture within OT environments.
- Deploy and maintain log collectors and forwarders within the Level 3.5 OT DMZ in accordance with the Purdue Model.
- Work with OT, Infrastructure, and Network teams to onboard industrial and manufacturing systems into enterprise monitoring platforms.
- Ensure security monitoring solutions align with OT segmentation and regulatory requirements.
- Troubleshoot connectivity, log collection, and data quality issues across OT environments.
- Support secure transmission and retention of OT security events.
Security Operations Support- Investigate platform-generated alerts and assist with security incident response activities.
- Validate integrity and availability of security monitoring infrastructure.
- Support audit, compliance, and regulatory reporting requirements.
- Maintain engineering documentation, architecture diagrams, and operational procedures.
- Participate in after-hours support activities when required.
QualificationsREQUIRED- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
- Minimum 3 years of experience supporting security monitoring, SIEM, or security engineering platforms.
- Minimum 1 years' experience administering Splunk Enterprise.
- Minimum 1 years' experience supporting Cribl or similar log management technologies.
- Minimum 1 years' experience with Syslog architecture and log ingestion technologies.
- Minimum 1 years' experience supporting Managed Detection and Response (MDR) services or Security Operations Centers.
- Minimum 1 years' experience working with Windows, Linux, network, and cloud log sources.
- Familiarity with Operational Technology (OT) and Industrial Control System (ICS) environments.
DESIRED- Splunk Certified Administrator or Splunk Certified Architect certification.
- Experience with industrial networking and OT/ICS environments.
- Experience integrating enterprise logging platforms with MDR providers.
- Knowledge of NIST Cybersecurity Framework, IEC 62443, or ISA/IEC industrial security standards.
- Experience with scripting and automation using PowerShell, Python, or similar tools.
- Familiarity with Microsoft Azure and cloud security monitoring.
About the TeamOur regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high-quality support that ensures our operations run efficiently and safely. Having these teams based locally allows us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.