Murphy Oil Corporation

Staff, IT Security Specialist - Security Operations Center (SOC)

Murphy Oil Corporation$110K — $130K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity or related field, or equivalent experience
  • Minimum 15 years of experience in cybersecurity with at least 3 years in hands-on SIEM or security analytics
  • Proficient in investigating incidents using SIEM and analyzing logs from various sources
  • Experience onboarding log sources and developing detection content using KQL, SQL, or similar languages
  • Knowledge of security best practices and incident response frameworks (NIST, SANS)

Responsibilities

  • Contribute to and execute the cybersecurity vision, focusing on SOC capabilities.
  • Lead incident response initiatives and improve technical readiness.
  • Respond to security incidents and perform forensic analysis as needed.
  • Support daily SOC operations with managed service providers to enhance security monitoring.
  • Develop automation workflows and documentation for incident response.

Benefits

  • Hybrid work schedule with flexibility for remote work two days a week.
  • Opportunities for professional development in cybersecurity disciplines.
  • Engagement in hands-on technical projects for career progression.
  • Collaborative environment with cross-functional teams in a global company.
Full Job Description
Job Summary

Murphy Oil Corporation is looking for an IT Security Specialist to support our growing Global Cybersecurity team. The ideal candidate is a highly technical and hands-on cybersecurity professional who will support the design, implementation, administration, and continuous improvement of Murphy's security monitoring, logging, detection, and incident response capabilities. This role supports the Security Operations Center (SOC) function with a primary focus on SIEM engineering, detection engineering, security telemetry management, and security operations enablement.

The right candidate has recent hands-on experience deploying, configuring, operating, and troubleshooting SIEM platforms, security data lakes, observability platforms, and log management solutions. This individual remains actively involved in technical implementation work, including onboarding data sources, creating data pipelines, developing detection content, writing queries, automating workflows, troubleshooting production issues, and working with stakeholders in the business, internal IT, Operations, and third-party service providers to securely enable the business.

This is an individual contributor role requiring strong technical depth and hands-on engineering experience. Candidates whose recent experience has primarily been focused on people leadership, program management, governance, or vendor management may not be the best fit.

The IT Security Specialist will work in our Houston Corporate office and may work two (2) days a week remote.

Responsibilities

  • Contribute to cybersecurity vision, roadmap, and execution plan, with emphasis on security monitoring, logging, telemetry, SIEM engineering, and detection engineering capabilities.
  • Lead and mature technical incident response enablement, including updating plans, documenting playbooks, facilitating cyber drills, improving security telemetry, coordinating with Incident Response vendors, setting up alternate communication channels, and implementing automation to reduce response time.
  • Respond to security-related incidents by creating queries, validating telemetry, assisting with forensic analysis, determining scope, urgency, potential impact, and materiality, identifying relevant vulnerabilities, and making recommendations that enable expeditious remediation.
  • Support day-to-day SOC operations by partnering with Murphy's managed SOC provider to optimize monitoring, alert quality, response workflows, help desk tickets, incidents, cases, and visibility across security data sources.
  • Provide technical support for on-call and after-hours security response by ensuring required telemetry, detection logic, queries, dashboards, and runbooks are available to support timely investigation and escalation.
  • Collaborate with service desk, infrastructure, cloud, OT, and application teams to deploy critical security patches in a timely, risk-based manner, formalize vulnerability management processes, improve telemetry coverage, and introduce automation.
  • Collaborate with the Head of IT Security to implement security architecture best practices within incident response, daily SOC activities, logging architecture, detection coverage, and security data platform design.
  • Support the Head of IT Security by providing technical guidance to the cybersecurity team in managing day-to-day security operations, improving detection content, strengthening telemetry coverage, and responding to incidents.
  • Establish and maintain technical metrics to measure SOC and security data platform effectiveness, including detection coverage, telemetry quality, ingestion health, false positive rate, MTTD, MTTR, and SLA adherence.
  • Establish relationships between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies, vendors, public relations professionals)
  • Keep current with latest cyber security developments, threat intelligence, attacker techniques, emerging tools, technologies, and security monitoring best practices, and translate relevant developments into detection use cases and hunting content.
  • Manage the lifecycle, configuration, health, and operational effectiveness of security-related products, including SIEM, log management, security analytics, observability, SOAR, and telemetry pipeline technologies.
  • Design, implement, administer, and maintain enterprise SIEM, security analytics, security data lake, observability, and log management capabilities.
  • Configure and manage log collection, normalization, enrichment, routing, filtering, retention, and ingestion pipelines using APIs, syslog, collectors, agents, event hubs, and cloud-native telemetry services.
  • Onboard new log sources from cloud, endpoint, identity, infrastructure, network, application, SaaS, and OT environments; troubleshoot ingestion issues, missing telemetry, parsing failures, duplicate events, and logging gaps.
  • Develop, tune, and maintain SIEM correlation rules, detections, alerts, dashboards, queries, hunting content, and automation workflows; map detections to MITRE ATT&CK and continuously reduce false positives.
  • Actively identify, recommend, and implement cybersecurity and risk management solutions that ensure business needs are met while enhancing the organization's security posture, and maturing the cybersecurity function
  • Ensure cloud security considerations are integrated into overall security operations, including appropriate telemetry onboarding, detection coverage, monitoring dashboards, alerting, and response workflows for Azure, AWS, Microsoft Defender, Entra ID, SaaS, and cloud-native services.
  • Lead special projects as assigned
  • Coordinate with relevant teams and managed SOC/MDR providers to manage risks associated with third-party relationships and optimize integrations between provider monitoring services and Murphy-controlled logging and analytics platforms.


Licenses/ Certifications

Preferred certifications include Microsoft Security Operations Analyst, Microsoft Sentinel certifications, Cribl Certified User / Administrator, Datadog certifications, Splunk certifications, Azure Security certifications, GIAC certifications (GCIH, GCFA, GMON), and CISSP. Certifications are preferred but do not replace recent hands-on engineering experience demonstrated.

Qualifications/Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, Data Engineering, Computer Engineering, or a related technical field; or equivalent combination of education and hands-on experience
  • Minimum 15 years' experience in cybersecurity, infrastructure engineering, cloud engineering, platform engineering, or security engineering, including at least 3 years of hands-on experience administering or engineering SIEM, security analytics, logging, or observability platforms.
  • Hands-on experience investigating potential security incidents using SIEM, telemetry, and log analytics platforms, including analyzing high volumes of logs, network data, endpoint data, identity data, and other attack artifacts
  • Demonstrated experience onboarding log sources, troubleshooting data ingestion, developing detection content, and writing production queries or detections using technologies such as KQL, SQL, SPL, Python, or PowerShell
  • Hands-on experience documenting Incident Response plans, playbooks, runbooks, engineering standards, and SOPs in line with security best practice standards such as NIST, SANS, etc.
  • Knowledge of incident categories, incident responses, and timelines for responses
  • Knowledge of security best practice standards such as NIST CSF, NIST 800-53, ISO 27001, etc.
  • Familiarity with a standardized incident response framework (SANS/NIST)
  • Knowledge of different classes of attacks (e.g., passive, active, insider, distribution attacks)
  • Knowledge of cyberattack vectors and stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, etc.)
  • Knowledge of penetration testing principles, tools, and techniques
  • Knowledge of the basics of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection)
  • Knowledge of Cyber Kill Chain methodology and/or MITRE ATT&CK framework, including the ability to map detection content to attacker techniques and identify visibility gaps
  • Experience working with APIs, automation, integrations, telemetry pipelines, collectors, agents, event hubs, syslog, and cloud-native telemetry services.
  • Able to manage multiple projects and initiatives concurrently
  • Ability to work independently and with others
  • Highly organized with strong time-management skills
  • Candidates should be prepared to discuss SIEM, security data lake, observability platform, or telemetry pipeline they personally implemented or operated, including specific examples of data source onboarding, parser development, troubleshooting, detection engineering, automation, and operational ownership

The individual is required to follow all applicable safety precautions. Work is performed almost entirely in controlled (i.e., inside) environment and does not typically subject the incumbent to any hazardous/ extreme elements; some positions may require regularly moving or transporting items weighing up to 25 lbs. around the office for various needs. Th successful candidate must be able to complete all essential physical requirements of the job with or without reasonable accommodation.

Desired/Preferred Qualifications

  • Minimum 2 years' experience working in a managed SOC environment, ideally including integrations between managed SOC/MDR services and internally controlled logging or analytics platforms
  • Experience supporting SOC operations across onshore and offshore resources, with emphasis on hands-on technical enablement, telemetry quality, alert fidelity, and detection engineering rather than formal people leadership
  • Hands-on cyber incident response experience including prior experience responding to large scale incidents such as a Ransomware attack, supply chain attack, or data breach
  • Recent hands-on experience implementing, administering, or operating industry-leading SIEM, security analytics, observability, or log management platforms such as Microsoft Sentinel, Google Security Operations (Chronicle), Splunk, Elastic, Cribl, Databricks, Datadog, or Microsoft Fabric.
  • Strong experience managing large-scale telemetry and detections from Microsoft 365 Defender, Defender for Identity, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Conditional Access, Azure Defender/Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Intune, AWS, network devices, EDR, and SaaS platforms
  • Experience deploying Security Orchestration, Automation and Response (SOAR) solutions and implementing automation opportunities that improve monitoring, detection, triage, enrichment, and response efficiency
  • Experience writing scripts and production queries, such as PowerShell, Python, KQL, SPL, SQL, or similar languages, to parse large data files, automate manual tasks, fetch and process data, develop detections, and troubleshoot platform or ingestion issues
  • Experience building or managing security data lakes, telemetry pipelines, log management platforms, detection engineering programs, or migrations from provider-hosted SIEM solutions to internally controlled logging and analytics platforms
  • Experience working within the Oil/Gas industry, Critical Infrastructure, or OT/ICS monitoring environments
  • Knowledge of network security implementations (e.g., host-based IDS, IPS, access control lists), including their function and placement in a network
  • Knowledge of system administration, network, and operating system hardening techniques


#LI-Hybrid

About Murphy Oil Corporation

Murphy Oil Corporation is an oil and gas exploration and production company. It was founded in 1950 and is headquartered in El Dorado, Arkansas. The company operates in the United States, Canada, and other international locations. Murphy Oil Corporation is focused on developing its oil and gas reserves, as well as exploring for new reserves. The company's operations include offshore drilling, onshore drilling, and production of oil and gas. Murphy Oil Corporation is committed to sustainable development and environmental stewardship in all of its operations.
Learn more about Murphy Oil Corporation
Size
696 employees
Market Cap
$6.5 billion
Industry
Net Income
-$1.1 billion
Founded
1950
5 Year Trend
+4.7%
Revenue
$1.9 billion
NASDAQ

Similar Jobs

More Jobs at Murphy Oil Corporation

More Information Technology Jobs

Find similar Staff, IT Security Specialist - Security Operations Center (SOC) jobs: