Senior Vice President, Information Security
BNY Mellon | |
United States, Texas, Houston | |
Sep 23, 2026 | |
|
SIEM Engineering & Insider Risk Analytics SME We're seeking a future team member for the role of SIEM Engineering & Insider Risk Analytics SME to join our cybersecurity and insider risk team. This role is in Houston, TX. The ideal candidate will have a strong background in SIEM engineering, cybersecurity operations, data analytics, and User and Entity Behavior Analytics (UEBA), with experience working across multiple risk domains. They will collaborate with cross-functional teams to integrate monitoring technologies, improve threat visibility, identify High-Risk Users, develop and tune use cases, protect crown jewel assets, strengthen operational processes, and prioritize risk through a combination of user inherent risk and observed user behavior. Key Responsibilities SIEM Engineering & Platform Management:
Data Analytics & Threat Intelligence: * Develop data models, analytics dashboards, reports, and risk-scoring approaches that enhance security monitoring, forensic investigations, and user risk prioritization. * Apply AI, machine learning, statistical analysis, and behavioral analytics to detect anomalies, identify emerging patterns, and improve insider risk detection. * Integrate SIEM, threat intelligence, endpoint, identity, case management, and other security applications into a unified insider risk program. * Conduct trend and threat analysis across multiple risk domains and a broad range of cyber and insider risk scenarios to support High-Risk User identification, crown jewel protection, proactive risk mitigation, early detection, and rapid response. Incident Detection & Response Support: * Collaborate with Insider Threat analysts, threat hunters, fraud teams, and other security partners to investigate incidents using SIEM, UEBA, endpoint, identity, and workstation monitoring data. * Maintain and enhance insider risk workflows through use case development, alert tuning, automation, process improvements, and response orchestration that reduce time to detection and response. * Assist in root cause analysis and remediation efforts for complex security threats. Compliance & Optimization: * Ensure SIEM configurations align with regulatory requirements (e.g., NIST, PCI DSS). * Maintain documentation for use cases, data flows, integrations, operating procedures, risk-scoring logic, and SIEM policies across the unified insider risk program. * Identify and implement improvements to log ingestion, data normalization, system scalability, analytic coverage, operational processes, and program effectiveness. * Provide peer review of use cases and threat models to ensure efficacy and effectiveness. Qualifications & Experience * Experience in SIEM engineering, cybersecurity operations, or data analytics. 10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus * Strong hands-on experience with enterprise SIEM platforms, including platform implementation and support, rule and use case development, log ingestion, integrations, and dashboard development. * Proficiency in SQL, Python, Splunk, Elastic Stack, or other data analytics tools. * Experience with threat detection, UEBA development, AI and machine learning in security, and risk prioritization using both user inherent risk and user behavior. * Familiarity with cloud security monitoring (AWS, Azure, GCP) and integration with SIEM solutions. * Knowledge of MITRE ATT&CK, insider risk and fraud detection, user and entity behavior analytics, crown jewel protection, and a broad range of cyber threats, attack patterns, adversary techniques, and risk domains. * Strong understanding of log management, data correlation, and incident response frameworks. * Certifications such as SANS GIAC, CISSP, CEH, or relevant SIEM, analytics, cloud, or AI certifications are a plus. Preferred Skills: * Experience working in the financial sector with a focus on fraud prevention, insider risk, or compliance monitoring. * Knowledge of big data platforms (Hadoop, Spark, Snowflake), automation tools (SOAR, Python scripting, APIs), and integration patterns for connecting security applications across an insider risk ecosystem. * Experience applying analytics across multiple risk domains to identify High-Risk Users, assess access and behavioral risk, and protect crown jewel assets and other critical resources. * Experience deploying and supporting User Enhanced Monitoring workstations, working with large datasets, and building predictive or AI-assisted models for actionable security insights. | |
Sep 23, 2026