Skip to main content

Senior Vice President, Information Security

On-siteFull timeSenior

Houston, Texas, United States · Posted 12 hr. ago

SIEM Engineering & Insider Risk Analytics SME 

We’re seeking a future team member for the role of SIEM Engineering & Insider Risk Analytics SME to join our cybersecurity and insider risk team. This role is in Houston, TX.

The ideal candidate will have a strong background in SIEM engineering, cybersecurity operations, data analytics, and User and Entity Behavior Analytics (UEBA), with experience working across multiple risk domains. They will collaborate with cross-functional teams to integrate monitoring technologies, improve threat visibility, identify High-Risk Users, develop and tune use cases, protect crown jewel assets, strengthen operational processes, and prioritize risk through a combination of user inherent risk and observed user behavior.

Key Responsibilities 

 SIEM Engineering & Platform Management: 

  • Design, stand up, configure, deploy, maintain, and support enterprise SIEM platforms for security monitoring, insider risk detection, and threat response. 
  • Develop and fine-tune correlation rules, use cases, UEBA models, and behavioral analytics to identify High-Risk Users and detect insider risk, fraud, and advanced cyber threats, prioritizing risk through user inherent risk, observed behavior, and potential exposure to crown jewel assets. 
  • Assist in the management of log ingestion pipelines and optimize data collection from network, endpoint, cloud, identity, workstation monitoring, and other security data sources. 
  • Deploy, support, and troubleshoot User Enhanced Monitoring workstations and related platform integrations, performance, and data-processing pipelines. 

Data Analytics & Threat Intelligence:

•  Develop data models, analytics dashboards, reports, and risk-scoring approaches that enhance security monitoring, forensic investigations, and user risk prioritization. 

•  Apply AI, machine learning, statistical analysis, and behavioral analytics to detect anomalies, identify emerging patterns, and improve insider risk detection. 

•  Integrate SIEM, threat intelligence, endpoint, identity, case management, and other security applications into a unified insider risk program. 

•  Conduct trend and threat analysis across multiple risk domains and a broad range of cyber and insider risk scenarios to support High-Risk User identification, crown jewel protection, proactive risk mitigation, early detection, and rapid response. 

Incident Detection & Response Support:

•  Collaborate with Insider Threat analysts, threat hunters, fraud teams, and other security partners to investigate incidents using SIEM, UEBA, endpoint, identity, and workstation monitoring data. 

•  Maintain and enhance insider risk workflows through use case development, alert tuning, automation, process improvements, and response orchestration that reduce time to detection and response. 

•  Assist in root cause analysis and remediation efforts for complex security threats. 

Compliance & Optimization:

•  Ensure SIEM configurations align with regulatory requirements (e.g., NIST, PCI DSS).

•  Maintain documentation for use cases, data flows, integrations, operating procedures, risk-scoring logic, and SIEM policies across the unified insider risk program. 

•  Identify and implement improvements to log ingestion, data normalization, system scalability, analytic coverage, operational processes, and program effectiveness. 

•  Provide peer review of use cases and threat models to ensure efficacy and effectiveness. 

Qualifications & Experience

•  Experience in SIEM engineering, cybersecurity operations, or data analytics. 

10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus

•  Strong hands-on experience with enterprise SIEM platforms, including platform implementation and support, rule and use case development, log ingestion, integrations, and dashboard development. 

•  Proficiency in SQL, Python, Splunk, Elastic Stack, or other data analytics tools. 

•  Experience with threat detection, UEBA development, AI and machine learning in security, and risk prioritization using both user inherent risk and user behavior. 

•  Familiarity with cloud security monitoring (AWS, Azure, GCP) and integration with SIEM solutions. 

•  Knowledge of MITRE ATT&CK, insider risk and fraud detection, user and entity behavior analytics, crown jewel protection, and a broad range of cyber threats, attack patterns, adversary techniques, and risk domains. 

•  Strong understanding of log management, data correlation, and incident response frameworks. 

•  Certifications such as SANS GIAC, CISSP, CEH, or relevant SIEM, analytics, cloud, or AI certifications are a plus. 

Preferred Skills:

•  Experience working in the financial sector with a focus on fraud prevention, insider risk, or compliance monitoring. 

•  Knowledge of big data platforms (Hadoop, Spark, Snowflake), automation tools (SOAR, Python scripting, APIs), and integration patterns for connecting security applications across an insider risk ecosystem. 

•  Experience applying analytics across multiple risk domains to identify High-Risk Users, assess access and behavioral risk, and protect crown jewel assets and other critical resources. 

•  Experience deploying and supporting User Enhanced Monitoring workstations, working with large datasets, and building predictive or AI-assisted models for actionable security insights. 

Locations
Houston, Texas, United States
Experience
10+ years

Categories

Skills