Senior Cybersecurity Engineer, OT Cybersecurity
3 days ago
An exciting career awaits you
At MPC, we're committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.
Position Summary
The Senior Cybersecurity Engineer, OT Cybersecurity plays a critical role in safeguarding Marathon Petroleum Corporation's digital and operational assets across enterprise IT and industrial control systems (ICS/OT). This position is responsible for the use, maintenance, and enhancement of the Dragos platform optimizing threat and vulnerability management to identify, analyze, and respond to emerging cyber threats targeting both business and field operations, including refineries, pipelines, terminals, and remote industrial facilities.
Working as part of the Cyber Threat and Vulnerability Management team within the Cyber Fusion Center, the engineer will ensure the proper operation and use of the Dragos platform and associated field equipment across the OT enterprise environment allowing for the enhancement of TVM processes within the OT environment. The role requires close coordination with internal teams including threat hunting, incident response, threat intelligence, and infrastructure to ensure alignment between detection strategy, risk posture, and operational resiliency. The ideal candidate is technically proficient, collaborative, and mission-driven, with a strong understanding of IT/OT security principles and a passion for protecting critical infrastructure within the energy sector.
Key Responsibilities
- Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess business impact and cybersecurity risk. Resolves complex multi-functional technical issues.
- Leverages cybersecurity assessments, standards and ensures compliance across security systems.
- Improves the efficiency and effectiveness of Security solutions, processes and controls in place.
- Analyzes existing processes and procedures and leads efforts for implementing improvements or remediation.
- Responsible for development and submission of Standard Operating Procedures.
- Analyzes business impacting events, performs initial investigation. Monitors networks, systems, and applications for signs of potential cybersecurity incidents.
- Investigates and analyzes the nature and scope of cyber incidents. Assists in the development of innovative and creative ideas to formulate risk mitigation and remediation plans and approaches to ensure regulatory compliance.
- Leads implementation of global security initiatives, policies, and compliance requirements. Collects and validates all security metrics and any remediation efforts associated with them.
- Manages cyber security-related consulting, guidance, and support to customers and stakeholders.
- Translates security principles to assist configuration teams with incorporating security into build and configuration processes.
- Monitors emerging IT/OT and cybersecurity technologies as well as their impact on the security landscape.
Education and Experience
- Bachelor's Degree in Information Technology, related field or equivalent experience.
- Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred.
- 5+ years of relevant experience required
- Dragos Platform Certified User Certification required.
- Dragos ICS/OT Cybersecurity Training Certification required.
- ICS/OT Cybersecurity certifications such as GCISP and GRID preferred.
Skills
- Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.
- Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
- General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks.
- Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.
- Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.
- Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management.
- Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security.
- Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities.
- Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.
- Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.
- Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.
- Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.
- Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business.
As an energy industry leader, our career opportunities fuel personal and professional growth.
Location:
San Antonio, Texas
Additional locations:
Job Requisition ID:
Location Address:
19100 Ridgewood Pkwy
Education:
Employee Group:
Full time
Employee Subgroup:
Regular
Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship or any other status protected by applicable federal, state, or local laws. If you would like more information about your EEO rights as an applicant, click here.
If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at hired candidate will also be eligible for a discretionary company-sponsored annual bonus program.
Equal Opportunity Employer: Veteran / Disability
We will consider all qualified Applicants for employment, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws. In reviewing criminal history in connection with a conditional offer of employment, Marathon will consider the key responsibilities of the role.
-
Cybersecurity Engineer, Senior
4 days ago
San Antonio, Texas, United States Booz Allen Hamilton Full time $86,800 - $198,000Cybersecurity Engineer, SeniorThe Opportunity: As a cyber mission specialist, you understand the value of hunt-forward operations, and you know that battles are won in the grey. At Booz Allen, you can use your cyberspace operations experience to create solutions that will be executed on a worldwide stage. We're looking for an experienced cyber mission...
-
Cybersecurity Engineer
8 hours ago
San Antonio, Texas, United States Marathon Petroleum Full time $110,000 - $180,000 per yearAn exciting career awaits youAt MPC, we're committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.Position SummaryWe are seeking a skilled and motivated Cybersecurity Engineer to join our Cyber Operations team, supporting both IT and OT...
-
Cybersecurity Analyst
24 hours ago
San Antonio, Texas, United States Bridgewater Consulting Group Full time $60,000 - $120,000 per yearPosition: Cybersecruity Analyst (1487)Location: Onsite - San Antonio, TX - LOCAL CANDIDATES ONLY**NO 3rd PARTIES or C2C CONSULTANTS** W2 ONLY APPLICANTSCompany OverviewBridgewater Consulting Group, Inc. is a full-service management consulting company dedicated to serving clients in the Utilities industry. We pride ourselves on delivering dynamic solutions...
-
Sr. Network Engineer
4 days ago
San Antonio, Texas, United States EVOTECH LLC Full time $120,000 - $180,000 per yearCompany DescriptionEvoTech, LLC is an Economically Disadvantaged Woman-Owned Small Business (EDWOSB) providing strategic thought leadership, program management, application development, and cybersecurity services to federal government agencies and commercial clients. We are committed to advancing innovative technologies and fostering a culture of creativity....
-
Cyber System Engineer
4 days ago
San Antonio, Texas, United States Booz Allen Hamilton Full time $61,900 - $141,000Cyber System EngineerThe Opportunity: Are you looking for an opportunity to advance your experience as a systems security and network security engineer. You can identify the capability needed to assess vulnerabilities and recommend the best solution and security strategy. We need your experience to develop and implement security solutions that will meet the...
-
PKI Senior Engineer
4 days ago
San Antonio, Texas, United States X Technologies ,Inc Full time $100,000 - $180,000 per yearJob Title: PKI Senior EngineerLocation – San Antonio, TX / HybridDegree - BA/BSExperience - 7 yearsClearance - SecretSummary of PositionThe PKI Senior Engineer provides advanced engineering and technical support to the Air Force Public Key Infrastructure (AFPKI) System Program Office (SPO) within the Cryptologic and Cyber Systems Division. The engineer...
-
Senior Project Manager
4 days ago
San Antonio, Texas, United States The University of Texas at San Antonio Full time $60,000 - $80,000 per yearLocation: San Antonio, TXRegular/Temporary: RegularJob ID: 14354Full/Part Time: Full Time Position Information The University of Texas at San Antonio (UT San Antonio) is a nationally recognized, top-tier public research university that unites the power of higher education, biomedical discovery and healthcare within one visionary institution. As the...
-
Sr Cyber Engineer
5 days ago
San Antonio, Texas, United States Pingwind Full time $100,000 - $120,000 per yearFull-time Description Pingwind is hiring for a Senior Cyber Engineer located in San Antonio, Texas. RequirementsExtensive knowledge of policies/directives/regulatory guidance in the Cybersecurity field.Minimum of five (5) years RMF experience in a complex network and systems environment consisting of a large diverse population of users, computers,...
-
IT SPECIALIST
5 days ago
San Antonio, Texas, United States Southwest Research Institute Full time $60,000 - $120,000 per yearWho We Are:Cybersecurity Operations' mission is to secure the enterprise by evaluating, implementing, and operating a full suite of tools and services. We are responsible for configuring, engineering, administering, and supporting network and endpoint security systems. Operations include firewalls, intrusion prevention and incident response as well as...
-
Platform Engineer with Security Clearance
10 hours ago
San Antonio, Texas, United States ClearanceJobs Full time $104,000 - $189,175 per yearR Description Job Description Launch Your Next Mission: Platform Engineer – San Antonio, TX Step into the future of national defense technology with Leidos We're searching for a driven Platform Engineer ready to take on high-stakes migration projects in the DAF CLOUDworks environment. Located in San Antonio, TX, this hybrid role offers flexibility,...