SIEM Engineering & Insider Risk Analytics SME
We’re seeking a future team member for the role of SIEM Engineering & Insider Risk Analytics SME to join our cybersecurity and insider risk team. This role is in Houston, TX.
The ideal candidate will have a strong background in SIEM engineering, cybersecurity operations, data analytics, and User and Entity Behavior Analytics (UEBA), with experience working across multiple risk domains. They will collaborate with cross-functional teams to integrate monitoring technologies, improve threat visibility, identify High-Risk Users, develop and tune use cases, protect crown jewel assets, strengthen operational processes, and prioritize risk through a combination of user inherent risk and observed user behavior.
Key Responsibilities
SIEM Engineering & Platform Management:
- Design, stand up, configure, deploy, maintain, and support enterprise SIEM platforms for security monitoring, insider risk detection, and threat response.
- Develop and fine-tune correlation rules, use cases, UEBA models, and behavioral analytics to identify High-Risk Users and detect insider risk, fraud, and advanced cyber threats, prioritizing risk through user inherent risk, observed behavior, and potential exposure to crown jewel assets.
- Assist in the management of log ingestion pipelines and optimize data collection from network, endpoint, cloud, identity, workstation monitoring, and other security data sources.
- Deploy, support, and troubleshoot User Enhanced Monitoring workstations and related platform integrations, performance, and data-processing pipelines.
Data Analytics & Threat Intelligence:
• Develop data models, analytics dashboards, reports, and risk-scoring approaches that enhance security monitoring, forensic investigations, and user risk prioritization.
• Apply AI, machine learning, statistical analysis, and behavioral analytics to detect anomalies, identify emerging patterns, and improve insider risk detection.
• Integrate SIEM, threat intelligence, endpoint, identity, case management, and other security applications into a unified insider risk program.
• Conduct trend and threat analysis across multiple risk domains and a broad range of cyber and insider risk scenarios to support High-Risk User identification, crown jewel protection, proactive risk mitigation, early detection, and rapid response.
Incident Detection & Response Support:
• Collaborate with Insider Threat analysts, threat hunters, fraud teams, and other security partners to investigate incidents using SIEM, UEBA, endpoint, identity, and workstation monitoring data.
• Maintain and enhance insider risk workflows through use case development, alert tuning, automation, process improvements, and response orchestration that reduce time to detection and response.
• Assist in root cause analysis and remediation efforts for complex security threats.
Compliance & Optimization:
• Ensure SIEM configurations align with regulatory requirements (e.g., NIST, PCI DSS).
• Maintain documentation for use cases, data flows, integrations, operating procedures, risk-scoring logic, and SIEM policies across the unified insider risk program.
• Identify and implement improvements to log ingestion, data normalization, system scalability, analytic coverage, operational processes, and program effectiveness.
• Provide peer review of use cases and threat models to ensure efficacy and effectiveness.
Qualifications & Experience
• Experience in SIEM engineering, cybersecurity operations, or data analytics.
10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus
• Strong hands-on experience with enterprise SIEM platforms, including platform implementation and support, rule and use case development, log ingestion, integrations, and dashboard development.
• Proficiency in SQL, Python, Splunk, Elastic Stack, or other data analytics tools.
• Experience with threat detection, UEBA development, AI and machine learning in security, and risk prioritization using both user inherent risk and user behavior.
• Familiarity with cloud security monitoring (AWS, Azure, GCP) and integration with SIEM solutions.
• Knowledge of MITRE ATT&CK, insider risk and fraud detection, user and entity behavior analytics, crown jewel protection, and a broad range of cyber threats, attack patterns, adversary techniques, and risk domains.
• Strong understanding of log management, data correlation, and incident response frameworks.
• Certifications such as SANS GIAC, CISSP, CEH, or relevant SIEM, analytics, cloud, or AI certifications are a plus.
Preferred Skills:
• Experience working in the financial sector with a focus on fraud prevention, insider risk, or compliance monitoring.
• Knowledge of big data platforms (Hadoop, Spark, Snowflake), automation tools (SOAR, Python scripting, APIs), and integration patterns for connecting security applications across an insider risk ecosystem.
• Experience applying analytics across multiple risk domains to identify High-Risk Users, assess access and behavioral risk, and protect crown jewel assets and other critical resources.
• Experience deploying and supporting User Enhanced Monitoring workstations, working with large datasets, and building predictive or AI-assisted models for actionable security insights.
- Locations
- Houston, Texas, United States
- Experience
- 10+ years