Marathon Petroleum Corporation Logo

Marathon Petroleum Corporation

Senior Cybersecurity Analyst, OT Compliance

Posted 2 Days Ago
Be an Early Applicant
In-Office
Denver, CO, USA
107K-184K Annually
Senior level
In-Office
Denver, CO, USA
107K-184K Annually
Senior level
Leads OT cybersecurity compliance, governance, risk management, control assessments, audit readiness, remediation, and regulatory support. Partners with Operations, Engineering, Audit, Digital, and Cybersecurity teams to evaluate controls, manage evidence, resolve issues, and improve compliance processes. Supports incident response, vulnerability scanning, penetration testing, SOX audits, security metrics, access certifications, and implementation of cybersecurity policies across industrial control systems and critical infrastructure environments.
The summary above was generated by AI
An exciting career awaits you

At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

Position Summary

The Senior Cybersecurity Analyst, OT Compliance is responsible for leading cybersecurity compliance, governance, and risk management activities across Operational Technology (OT) environments. This role ensures compliance with corporate cybersecurity standards, regulatory requirements, and industry frameworks while supporting the secure and reliable operation of industrial control systems, process control networks, and critical infrastructure assets.

The position serves as a subject matter expert on OT cybersecurity compliance and works closely with Operations, Engineering, Digital, Audit, and Cybersecurity teams to assess security controls, conduct compliance evaluations, manage remediation efforts, and support audit readiness activities. The Senior Cybersecurity Analyst drives continuous improvement initiatives by identifying compliance gaps, coordinating corrective actions, and monitoring the implementation of OT security requirements aligned with applicable standards and regulations.

This role provides guidance on cybersecurity risks, control effectiveness, and regulatory obligations while supporting enterprise initiatives related to governance, asset inventory, identity access management, and security monitoring within OT environments. The position plays a critical role in maintaining a resilient and compliant cybersecurity posture that protects operational assets, ensures regulatory compliance, and supports safe and reliable business operations.

This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate’s experience and qualifications.

Key Responsibilities
  • Conducts detailed analyses on controls related to complex business processes and systems and relationship to other internal and external systems to assess business impact of the security issues.
  • Drives the resolution of routine multi-functional technical issues. Oversees, advises on and manages Cybersecurity assessments and associated risks.
  • Develops and evaluates efficiency and effectiveness of security processes and controls through creation and maintenance of detailed security and/or compliance reports, as necessary. Support user access certification and attestation programs by collecting and validating evidence, facilitating reviewer approvals, resolving exceptions, and maintaining documentation to support audit and compliance activities.
  • Drive continuous improvement of OT cybersecurity compliance processes, tools, and controls to enhance regulatory compliance, audit readiness, and risk management.
  • Analyzes and maintains security audits and reports, monitors security advisory groups, and assist with security incidents and intrusions. Support regulatory inspections, internal audits and external audits through evidence management, coordination activities, and issue resolution.
  • Performs Incident Detection, Analysis, Response Planning, Containment, Eradication, Forensics and Reporting. Assists in the development of innovative and creative ideas to formulate risk mitigation and remediation plans and approaches to ensure compliance.
  • Leads implementation of global security initiatives, policies, and compliance requirements. Develops and tracks metrics related to cybersecurity; use existing cybersecurity tools for running web application scanning, vulnerability scanning and external pentests and help with the remediation effort.
  • Lead cybersecurity activities supporting SOX audits, including control testing coordination, evidence management, auditor engagement, issue resolution, and remediation tracking to ensure timely and successful audit outcomes.
  • Manages cyber security-related consulting, guidance, and support to customers and stakeholders.
  • Translates security principles to assist configuration teams with incorporating security into build and configuration processes.
  • Monitors emerging Information Technology/Operations Technology and cybersecurity technologies as well as their impact on the security landscape.
Education and Experience
  • Bachelor’s degree in information technology, related field or equivalent experience.
  • Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH, CISA, CISM CISSP preferred.
  • 5+ years of relevant experience required.
Skills
  • Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful.
  • AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination.
  • Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change.
  • Authentic Communicator -Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.
  • Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
  • General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks.
  • Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.
  • Penetration Testing -  The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.
  • Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management.
  • Security Controls -  Manages and maintains an information system that focus on the management of risk and the management of information systems security.
  • Security Governance -  The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities.
  • Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.
  • Security Policy Management -  The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.
  • Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.
  • Threat Hunting -  Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.
  • Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business.

As an energy industry leader, our career opportunities fuel personal and professional growth.

Location:

Findlay, Ohio

Job Requisition ID:

00023992

Pay Min/Max:

$106,900.00 - $184,300.00 Salary

Grade:

11 - 12

Location Address:

539 S Main St

Additional locations:

Denver, Colorado, San Antonio, Texas

Education:

Employee Group:

Full time

Employee Subgroup:

Regular

Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship  or any other status protected by applicable federal, state, or local laws.  If you would like more information about your EEO rights as an applicant, click here.
If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at [email protected]. Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at mympcbenefits.com. The hired candidate will also be eligible for a discretionary company-sponsored annual bonus program.
 
Equal Opportunity Employer: Veteran / Disability

We will consider all qualified Applicants for employment, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws. In reviewing criminal history in connection with a conditional offer of employment, Marathon will consider the key responsibilities of the role.

Marathon Petroleum Corporation Parachute, Colorado, USA Office

Parachute, United States

Similar Jobs

10 Minutes Ago
Remote or Hybrid
United States
50K-55K Annually
Entry level
50K-55K Annually
Entry level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Provides business-to-business client support by answering inquiries, resolving issues, fulfilling requests, managing workflows, navigating databases, and maintaining strong customer relationships. The role requires accurate multitasking, process-improvement awareness, effective communication, and proficiency with Microsoft Office. Representatives also identify opportunities to retain and grow existing client business through outstanding service.
Top Skills: ExcelMS OfficeMicrosoft WordSalesforce
35 Minutes Ago
Remote or Hybrid
United States
Senior level
Senior level
AdTech • Consumer Web • Digital Media • eCommerce • Marketing Tech • SEO
Build and support scalable data platforms and pipelines, leading migrations such as Snowflake to BigQuery and transitioning reporting to Looker. Responsibilities include data architecture, ETL/ELT, API and marketing integrations, data quality, production troubleshooting, warehousing, performance optimization, and platform modernization. The role partners with analytics and business teams, owns projects through production, documents solutions, and provides technical guidance.
Top Skills: AWSAzureBigQueryConfluenceDraw.IoGCPGitJIRAKafkaLookerLucidchartMiroModeNotionPower BIPythonSnowflakeSparkSQLTableauTalend
An Hour Ago
Remote or Hybrid
USA
Senior level
Senior level
Cloud • Real Estate • Software • PropTech
Leads district facilities operations across multiple trades, overseeing Facility Managers, CSRs, vendors, work orders, financial performance, compliance, KPIs, and client outcomes. Develops facilities strategies, improves processes, manages risks and budgets, mentors staff, analyzes service trends, and collaborates cross-functionally to optimize capacity, fulfillment, and operational efficiency.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account