Now hiring

SOC Detection Engineer (Houston, TX, US, 77002) @ CenterPoint Energy Service Co., LLC

Houston, TX, US, 77002OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>CenterPoint Energy and its predecessor companies have been in business for more than 150 years. </strong></span></span></p> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Our Vision:</strong> Our vision is to become the most admired utility in the United States through the execution of our long-term growth strategy. We have an unwavering commitment to safely and reliably deliver electricity and natural gas to millions of people. </span></span></p> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Our Commitment: </strong>CenterPoint Energy is committed to creating an inclusive work environment where business results are achieved through the skills, abilities and talents of our diverse workforce.</span></span></p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">At CenterPoint Energy, individuals are respected for their contributions toward our company objectives. We strive for an inclusive work environment across all levels that is reflective of the available workforce in the communities we serve.</span></span> </p> <p> </p><div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Job Summary</b></H2> </div><div><p style="margin:0.0in;font-family:Arial;font-size:12.0pt">The SOC Detection Engineer is responsible for enhancing and maintaining cybersecurity detection capabilities across Operational Technology (OT) and Industrial Control System (ICS) environments. This role focuses on the design, development, implementation, and continuous improvement of detection rules, analytics, and automated workflows to identify and respond to cyber threats targeting critical infrastructure.</p> <p style="margin:0.0in;font-family:Arial;font-size:12.0pt"> </p> <p style="margin:0.0in;font-family:Arial;font-size:12.0pt">The engineer will work closely with key stakeholders to protect critical infrastructure, maintain real-time visibility into network activity, and support the safety, reliability and continuity of operational systems.</p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Essential Functions</b></H2> </div><div><ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Design, develop, implement, and maintain detection rules, analytics, and signatures within SIEM and SOAR platforms. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Engineer and tune detection logic using network telemetry, and monitoring data to identify anomalous behavior, indicators of compromise (IOCs), and threat activity within ICS environments. Integrate and optimize data ingestion from security platforms, network devices, and control system assets to improve detection coverage and fidelity. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Collaborate with SOC analysts to refine alert logic, reduce false positives, and ensure detections are actionable and operationally safe. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Develop and maintain SOAR workflows to automate alert enrichment, contextualization, and response actions in accordance with SOC playbooks and approval requirements. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Perform root-cause analysis on missed detections or detection gaps and implement corrective improvements. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Support incident response activities by providing detection context, analytics, and technical expertise during investigations. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Maintain documentation for detection logic, analytics, and automation workflows, including rationale, data sources, and dependencies. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Partner with OT engineering, operations, IT security, and compliance teams to ensure detection capabilities align with operational constraints and regulatory expectations. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Maintain awareness of emerging threats, attack techniques, and adversary behaviors relevant to industrial and critical infrastructure environments.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Education Description</b></H2> </div><div><ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field is preferred, or equivalent practical experience.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Experience</b></H2> </div><div><ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">3–5 years of experience in cybersecurity detection engineering, SOC engineering, or security operations roles, with a strong focus on detection development and analytics.</span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Extensive hands-on experience with SIEM and SOAR platforms, preferably Splunk, including the design and implementation of automated workflows, data models, and operational dashboards. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Experience supporting OT or industrial control system environments is strongly preferred, including exposure to SCADA, PLCs, RTUs, or related systems. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Experience configuring passive monitoring and threat detection tools, such as Nozomi, Dragos, and Claroty. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Solid understanding of networking fundamentals, including TCP/IP, routing, firewalls, network segmentation, and common protocols such as Modbus and DNP3. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Familiarity with NERC CIP and TSA cybersecurity requirements and how detection engineering and monitoring support regulatory obligations within environments. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Strong analytical and communication skills, with attention to detail and the ability to clearly document detection logic and collaborate across technical and non-technical teams. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Experience supporting cybersecurity, detection engineering, or security operations within regulated critical infrastructure environments is highly desirable. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Hands-on experience designing, tuning, and maintaining SIEM and SOAR detections in an operational security environment. </span></li> <li style="margin-top:0.0;margin-bottom:0.0;vertical-align:middle"><span style="font-family:Arial;font-size:12.0pt">Relevant Splunk SIEM/SOAR and GIAC certifications, including GICSP, are highly desirable.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Physical Requirements</b></H2> </div><ul style="margin-top:0.0;margin-bottom:0.0"></ul></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Working Conditions</b></H2> </div><ul style="margin-top:0.0;margin-bottom:0.0"></ul></div></div><p style="margin-bottom:12.0px;text-align:start"> </p> <p style="margin-bottom:12.0px;text-align:start"><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:#000000"><span style="font-style:normal"><span style="white-space:normal"><span style="background-color:#ffffff"><strong style="font-weight:bold">We want you to know</strong></span></span></span></span><br><span style="color:#000000"><span style="font-style:normal"><span style="white-space:normal"><span style="background-color:#ffffff">Being a part of the CenterPoint Energy team is more than a career alone. It&apos;s an opportunity to make a positive impact. You will be an integral part of enabling everyday life and the pursuit of possibilities for the customers we serve and the communities we share. The vital services we provide are at the core of making our world work, and by sharing your energy with us, we&apos;ll create a better tomorrow together. </span></span></span></span></span></span><br> </p> <p style="margin-bottom:12.0px;text-align:start"><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>What we bring to you</strong></span></span></p> <ul> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Competitive pay</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Paid training</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Benefits eligibility begins on your first day</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Transit subsidies</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Flexible work schedule, paid holidays and paid time off</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Access to discounts at fitness clubs and an on-site wellness center at our headquarters in Houston</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Professional growth and development programs including tuition reimbursement</span></span></li> <li><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">401(k) Savings Plan featuring a company match dollar-for-dollar up to 6% and a company contribution of 3% regardless of your contribution</span></span></li> </ul> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Job Type:</strong> Full Time <br><strong>Posting Start Date:</strong> 04/02/2026​<br><strong>Posting End Date:</strong> 04/17/2026</span></span></p> <p><br><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">This contractor and subcontractor shall abide by the requirements of 41 CFR §§ 60-1.4(a), 60-300.5(a), and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, or national origin. Moreover, these regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability.</span></span></p> <p><span style="font-size:8.0px"><span style="font-family:Arial, Helvetica, sans-serif">#LI-CNP</span></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores