> Markdown version of [/jobs/ext/1007492-specialist-cybersecurity-soc](https://www.wearedevelopers.com/jobs/ext/1007492-specialist-cybersecurity-soc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Specialist, Cybersecurity - SOC - **Company:** Sabic Americas, Inc. - **Location:** Houston, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, Intrusion Detection Systems, Security Information and Event Management, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Security Orchestration, Automation & Response, Custom Reports - **Published:** June 30, 2026 - **Apply:** https://jobs.sabic.com/job/Houston-Specialist%2C-Cybersecurity-SOC-TX-77001/857283723/ ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. * 5+ years of experience with regulatory compliance and information security management frameworks (such as International Organization for Standardization [ISO] 27000, COBIT, National Institute of Standards and Technology [NIST] 800) * 8-10 years in SOC /Incident Response * Strong understanding of SIEM, SOAR, EDR * Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one. * An ability to effectively influence others to modify their opinions, plans or behaviors. * An understanding of organizational mission, values, goals and consistent application of this knowledge * Strong problem-solving and troubleshooting skills. * Knowledge of firewalls, intrusion detection systems, intrusion prevention systems, security information and event management (SIEM) systems, security orchestration, automation, and response (SOAR) platforms, and other security tools and technologies * Project Management * Change Management * Personal Leadership * Strong Communication * Drive for Results, * You must submit your application for employment online to be considered. Please submit your resume using the "Apply Now/Apply" option on this page. * You must be 18 years or older * Applicants must be currently authorized to work for SABIC in the United States on a full-time basis. ## Description Provides governance and operational performance oversight of detect, respond, and recovery cybersecurity functions. The primary function is to govern and provider oversight to managed services SOC operations, ensuring effective threat detection, response, and continuous improvement across IT and OT environments. The role includes management of cybersecurity controls, platforms, tooling, and managed services related to threat management and incident detection, response, and recovery. Key responsibilities include incident governance, threat detection, threat intelligence, threat hunting, and managing and maintaining operational playbooks, metrics, exercises, and incident reporting. This role acts as the domain authority for cybersecurity operations relate to cybersecurity incidents, and identifies, analyzes, communicates, contains, and recovers from cyber incidents as they occur. The role is responsible to run, manage, and maintain existing cybersecurity control platforms and tooling, as well as to plan and execute projects to improve existing solutions and to introduce new capabilities and controls in alignment with the department's strategy and roadmap., * Service owner for managed security service provider performance, SLAs, and service quality across all capabilities related to cybersecurity threat detection, incident response, and recovery, including service reviews and overseeing SOC operations on a daily basis. * Govern major incident response, including identification, containment, eradication, recovery, root cause identification, and post-incident reviews. * Focal point for coordinating communications related to cybersecurity threats, events, incidents, and recovery activities. * Escalation point for any issues with SOC-related services and controls * Define use cases, detection rules, and threat coverage priorities. * Define standards and use cases for IT and OT log integrations with SOC operations. * Manage and maintain log management and SIEM ingestion platforms and process. * Manage and maintain SIEM use cases, standards, operational playbooks, and reporting. * Ensure threat intel is operationalized into SOC processes. * Review threat intel sources for integration * Deliver threat intelligence advisories and briefings to key stakeholders based on their areas of interest, such as OT threats to manufacturing cybersecurity focal points. * Deliver executive reporting on incidents, trends, and risks. * Deliver executive reporting on threats and state of cybersecurity internally, within the industry, and of interest to the business. * Provide custom reports and dashboards to cybersecurity, IT, and OT stakeholders driven by cybersecurity log and SIEM tooling., Regular, predictable attendance is an essential function of this position. Applicants must be regularly available and willing to work (e.g. Monday - Friday)] during assigned hours of operation and such other hours as the company determines are necessary or desirable to meet business needs ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [C# 9 Source Generators - let the machine do the programming](https://www.wearedevelopers.com/videos/192-c-9-source-generators-let-the-machine-do-the-programming) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)