Home
/
Comprehensive
/
Cybersecurity Analyst
Cybersecurity Analyst-September 2024
Findlay
Sep 19, 2024
About Cybersecurity Analyst

  An exciting career awaits you

  At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

  Position Summary

  This is a position on the Cybersecurity and IT Compliance team within the Cybersecurity Governance, Risk, and Compliance organization. The successful candidate must be knowledgeable of Oil and Gas federal regulations, regulating bodies, operational technology (OT), and general compliance and control concepts. The candidate will assist in providing guidance and recommendations to improve IT and OT processes and control environments. This position works closely with business partners including IT and OT (including field sites), process owners, regulatory officials, internal senior level leadership, and internal/external audit groups to ensure appropriate implementation and representation of control practices and postures.

  This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate’s experience and qualifications.

  Key Responsibilities

  Conducts detailed analyses on controls related to complex business processes and systems and relationship to other internal and external systems to assess business impact of the security issues.

  Drives the resolution of routine multi-functional technical issues. Oversees, advises on and manages Cybersecurity assessments and associated risks.

  Develops and evaluates efficiency and effectiveness of security processes and controls through creation and maintenance of detailed security and/or compliance reports, as necessary.

  Analyzes and maintains security audits and reports, monitors security advisory groups, and assist with security incidents and intrusions.

  Performs Incident Detection, Analysis, Response Planning, Containment, Eradication, Forensics and Reporting. Assists in the development of innovative and creative ideas to formulate risk mitigation and remediation plans and approaches to ensure compliance.

  Leads implementation of global security initiatives, policies, and compliance requirements. Develops and tracks metrics related to cybersecurity; uses existing cybersecurity tools for running web application scanning, vulnerability scanning and external pentests and help with the remediation effort.

  Manages cyber security-related consulting, guidance, and support to customers and stakeholders.

  Translates security principles to assist configuration teams with incorporating security into build and configuration processes.

  Monitors emerging Information Technology/Operations Technology and cybersecurity technologies as well as their impact on the security landscape.

  Education and Experience

  Bachelor’s Degree in Information Technology, related field or equivalent experience.

  Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred.

  5+ years of relevant experience required.

  Skills

  Cybersecurity Research - Applies technical knowledge of the latest data, developments, and trends in the cybersecurity world to identify cybersecurity vulnerabilities within an organization or industry.

  Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.

  DevSecOps - A set of practices that automates the integration of security at every phase of the software development lifecycle, from initial design through integration, testing, deployment, and software delivery, with an aim towards shortening the systems development life cycle and pas well as continuous delivery and a security first approach.

  Digital Forensics - Develop and manage digital forensic investigation and reporting plan which specifiesthe tools, methods, procedures and practices to be used. This includes the collection, analysis and preservation of digital evidence in line with standard procedures and reporting of findings for legal proceedings.

  Ethical Hacking - The act of locating weaknesses and vulnerabilities of computer and information systems by duplicating the intent and actions of malicious hackers. Ethical hacking is also known as penetration testing, intrusion testing, or red teaming.

  Identity and Access Management (IAM) - Identity and access management (IAM) is a framework of business processes, policies and technologies that facilitates the management of electronic or digital identities, ensuring that the right users have the appropriate access to technology resources.

  Incident Response Management - An organized approach to addressing and managing the aftermath of a security breach or cyberattack, also known as an IT incident, computer incident or security incident.

  Intrusion Detection & Analysis - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.

  Malware Analysis - Software intentionally designed to cause damage to a computer, server, client, or computer network. A wide variety of types of malware exist, common categories include computer viruses, worms, Trojan horses, ransomware, spyware, adware, and scareware.

  Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.

  Root Cause Analysis - An iterative process, designed to investigate and categorize the root causes of events or failures that may have negative impacts to the overall performance of a system and establish a flexible and effective framework for the necessary corrective and preventive actions.

  Secure Software Development Lifecycle (SSDL) - Involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.

  Security Controls Management - Manages and maintains an information system that focus on the management of risk and the management of information systems security.

  Security Governance - The process of developing and disseminating corporate security policies, frameworks, and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats, and vulnerabilities.

  Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.

  Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.

  Threat Analysis & Modeling - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.

  Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.

  Threat Intelligence Analysis - Enable and conduct analysis of malicious threats, to examine their characteristics, behaviors, capabilities, intent and interactions with the environment as well as the development of defense and mitigation strategies and techniques to effectively combat such threats.

  As an energy industry leader, our career opportunities fuel personal and professional growth.

  Location:

  Findlay, Ohio

  Additional locations:

  San Antonio, Texas

  Job Requisition ID:

  00010207

  Location Address:

  539 S Main St

  Education:

  Bachelors: Information Technology

  Employee Group:

  Full time

  Employee Subgroup:

  Regular

  Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship or any other status protected by applicable federal, state, or local laws. If you would like more information about your EEO rights as an applicant, click here (https://marathonpetroleum.brandextract.com/staged/marathonpetroleum.com/content/documents/Jobs_/Department_of_Labor_EEOC_.pdf) . If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at [email protected] . Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at https://mympcbenefits.com.The hired candidate will also be eligible for a discretionary company-sponsored annual bonus program. Equal Opportunity Employer: Veteran / Disability

  About Marathon Petroleum Corporation

  Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Materials Specialist - Meridian
This position supports all of Mississippi Power with metering, PPE and AMI materials for work being performed in the field. This position ensures inventory levels are accurate and is responsible for p
Health Information Management Specialist 1
This is a full-time position working M-F, 8am-4:30pm Job Purpose or Objective(s): As the health Information Management Specialist 1, you will maintain and securely storing confidential patient records
AVP, Growth Issues Management
Job Description: Role Summary/Purpose: As a member of the Growth Engagement Excellence team, this role coordinates issue management projects and is responsible for oversight and facilitation of all re
Armed Protection Officer(Ontario)
Description/Job Summary Armed Protection Officer Pay: On-Site Role Travel required: Travel on an occasional basis with some overnight stays. Must have reliable transportation and be available for unpl
Alternant Chef de Chantier - H/F - Libourne
Alternant Chef de Chantier - H/F - Libourne Votre mission Notre agenceCOLAS Libourne(Saint Denis de Pile) est à la recherche de ses futurs talents ! En tant qu’Apprenti Chef de chantier, vous allez po
Production Supervisor I (Fabrication)
OverviewLong Prairie Packing Company LLC, an American Foods Group Company has an opportunity for a Fabrication Supervisor.As Fabrication Supervisor you will: Maintain adequate crewing to meet producti
Suicide Prevention Grant Program- Case Manager
With the belief that they were there when we needed them, so we must be there now that they need us, Veterans Inc., the largest provider of supportive services to Veterans and their families in New En
Biostatistician Senior
Biostatistician Senior Apply Now Summary The biostatistician will support a highly interactive research team in the Michigan Kidney Translational Medicine Core (MiKTMC), Department of Nephrology at th
3rd Shift Warehouse Operator
3rd Shift Warehouse Operator Wiscasset, ME, US Ref. number: 7458 Looking for a career that matters? Join Mölnlycke! We design, manufacture, and supply medical solutions that enhance performance in hea
Baker/Pizza Prep – Bubbas 33
Join our team! As a Bubba’s 33 team member, you’ll take pride in hand-crafted food and friendly service. Bubba’s 33 is looking for a rock star Baker who believes in made-from-scratch food and loves ba
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved