Marathon Petroleum Corporation

Senior Cybersecurity Analyst, SOX

LocationFindlay, OH
Job Typefull_time

About This Job

An exciting career awaits you

At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

Position Summary

The IT SOX Senior Cybersecurity Analyst is a critical member of the Cybersecurity and Infrastructure Compliance team, responsible for driving the execution and maturity of the company’s IT SOX compliance program. This role blends deep knowledge of IT general controls and audit readiness with the ability to advise on technical implementations of such controls across cloud, on-premises, and hybrid environments. The ideal candidate brings a strong background in IT SOX testing and control monitoring, and serves as a key liaison between internal stakeholders, external auditors, and control owners.

In this role, you will evaluate, develop, and enhance controls related to access, change management, and system development lifecycle (SDLC); support audit and risk assessment activities; and provide guidance on integrating SOX security into systems and processes, including emerging technologies such as AI and cloud-based platforms. You will play a vital role in identifying compliance risks, supporting remediation efforts, and promoting a strong control environment that aligns with regulatory requirements and corporate cybersecurity standards.

Key Responsibilities

Conducts detailed analyses on controls related to complex business processes and systems, including IT general controls and application controls, and their relationship to other internal and external systems to assess business and compliance impact of security issues.

Drives the resolution of routine multi-functional technical and compliance issues. Oversees, advises on and manages Cybersecurity assessments and IT Compliance (eg: SOX or PCI) related risks across the environment.
Develops and evaluates efficiency and effectiveness of security and compliance processes and controls through the creation and maintenance of detailed security and/or SOX/PCI compliance reports, as necessary.
Analyzes and maintains security and compliance audit documentation, monitors relevant advisory groups, and assist with security incidents and audit-driven investigations.
Performs Incident Detection, Analysis, Response Planning, Containment, Eradication, Forensics and Reporting. Assists in the development of innovative ideas to formulate risk mitigation and remediation plans for compliance activities including SOX/PCI and approaches to ensure adherence.
Leads implementation of global security and compliance initiatives, policies, and control requirements. Develops and tracks metrics related to compliance (eg: SOX/PCI) posture and testing status.
Manages cyber security-related consulting, guidance, and compliance support to customers and stakeholders.
Translates security principles to assist configuration teams with incorporating security into build and configuration processes.
Monitors emerging Information Technology/Operations Technology and cybersecurity technologies as well as their impact on control frameworks, compliance requirements, and risk posture.


Education and Experience

Bachelor’s Degree in Information Technology, related field or equivalent experience.
5+ years of relevant experience required.
Experience with ITGC frameworks and SOX 404 testing requirements, including change management, access management, and SDLCs, is required.
Strong understanding of cybersecurity risk frameworks (e.g., NIST CSF, NIST 800-53, COBIT) and their application within a SOX-controlled environment is required.
Experience interfacing with internal and external auditors, including preparing formal audit responses and control documentation, is required.
Professional certification, e.g. Security+, CISA, Network+, OSCP, GIAC, CEH preferred.
Familiarity with cloud environments and SaaS platforms, including cloud security controls relevant to IT SOX compliance, is preferred.
Hands-on experience with GRC platforms such as ServiceNow GRC or Archer is preferred.
Awareness of emerging technologies such as AI/ML, particularly regarding data governance, accountability, and compliance risk is preferred.
Experience with the PCI (Payment Card Industry) framework is preferred.


Skills

Authentic Communicator -Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.
Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks.
Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.
Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.
Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management.
Security Controls - Manages and maintains an information system that focus on the management of risk and the management of information systems security.
Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities.
Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.
Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.
Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.
Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.
Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business.

As an energy industry leader, our career opportunities fuel personal and professional growth.

Location:

San Antonio, Texas

Additional locations:

Findlay, Ohio

Job Requisition ID:

00017458

Location Address:

19100 Ridgewood Pkwy

Education:

Employee Group:

Full time

Employee Subgroup:

Regular

Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship or any other status protected by applicable federal, state, or local laws. If you would like more information about your EEO rights as an applicant, click here.

If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at talentacquisition@marathonpetroleum.com. Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at https://mympcbenefits.com.The hired candidate will also be eligible for a discretionary company-sponsored annual bonus program.

Equal Opportunity Employer: Veteran / Disability

We will consider all qualified Applicants for employment, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws. In reviewing criminal history in connection with a conditional offer of employment, Marathon will consider the key responsibilities of the role.

Similar Jobs

company-logo

Data Analyst

logo
River City Science Academy
Job TypeFull-time
Salary
$20 - $45
Jacksonville, FL
4 months ago
company-logo

Senior Division Order Analyst

logo
Formentera
Job TypeFull-time
Salary
$110000 - $130000
Austin, TX
about 1 year ago
company-logo

Senior Cybersecurity Analyst, SOX

Marathon Petroleum Corporation
Job Typefull_time
 
Findlay, OH
9 days ago
company-logo

Senior Cybersecurity Analyst, SOX

Marathon Petroleum
Job TypeFull-time
 
San Antonio, TX
10 days ago
company-logo

Senior Cybersecurity Analyst

NextEra Energy
Job TypeFull-time
 
Hialeah, FL
18 days ago
company-logo

SOX Compliance Analyst

Bonnell Aluminum
Job Typefull_time
 
Newnan, GA
about 1 month ago
company-logo

Cybersecurity Analyst

Golden State Water Company
Job Typefull_time
 
San Dimas, CA
10 days ago
company-logo

Cybersecurity Analyst I

Arizona Public Service (APS)
 
Phoenix, AZ
10 days ago
company-logo

Associate Ops Cybersecurity Analyst

Duke Energy Corporation
Job Typefull_time
 
St. Petersburg, FL
11 days ago
company-logo

Associate Ops Cybersecurity Analyst

Duke Energy
Job TypeFull-time
 
Saint Petersburg, FL
11 days ago
company-logo

Cybersecurity Operations Center Analyst I

Alliant Energy
Job TypeFull-time
Salary
$58000 - $76000
Cedar Rapids, IA
18 days ago
company-logo

Senior Specialist, Cyber Security

Elk Valley Resources
Job Typefull_time
Salary
$105735.07 - $130406.586
Calgary, AB
4 days ago
company-logo

Cyber Security Analyst

New York Power Authority
Salary
$94000 - $117000
White Plains, NY
6 days ago
company-logo

Cyber Security Analyst

Cape Fear Public Utility Authority
Job Typefull_time
 
Wilmington, NC
8 days ago
company-logo

Cyber Security Analyst

Eldorado Gold
Job Typefull_time
Salary
$53572.434 - $73662.09
Vancouver, BC
10 days ago
company-logo

Cyber Security Analyst

Nebraska Public Power District
Job TypeFull-time
Salary
$75456 - $140076
Columbus, NE
26 days ago
company-logo

SENIOR CYBER SECURITY PROGRAM SPECIALIST

Manitoba Hydro
Job TypeTemporary, Fixed term contract
 
Winnipeg, MB
17 days ago
company-logo

Cyber Security Analyst II

New Jersey Resources
Salary
$87700 - $111800
Township of Wall, NJ
4 days ago
company-logo

Cybersecurity Specialist

Switchgear Power Systems
 
Winneconne, WI
5 days ago
company-logo

Cybersecurity Operations Center, Senior Specialist

Southern California Edison (SCE)
Job Typefull_time
Salary
$140400 - $210500
Rosemead, CA
6 days ago

Trending Jobs

company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, PA
5 months ago
company-logo

Division Order Analyst

Coronado Resources
Job TypeFull-time
 
Dallas, TX
about 2 months ago
company-logo

Professional Landman

Penterra Services, LLC
Job TypeContract
 
Lovington, NM
25 days ago
company-logo

Accounts Payable Clerk

LPR Energy
Job TypeFull-time
Salary
$65000 - $65000
Dallas, TX
2 months ago
company-logo

Division Order Landman

R. Lacy Services, Ltd.
Job TypeFull-time
 
Longview, TX
about 1 month ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Lafayette, LA
4 months ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull-time
 
Dallas, TX
3 months ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull-time
 
Houston, TX
over 1 year ago
company-logo

Title Landman

Sustain Land Services
Job TypeFull-time
 
Norman, OK
3 months ago
company-logo

Senior Landman

Greenlake Energy
Job TypeFull-time
 
Austin, TX
3 months ago
company-logo

Electrical Designer

Dudley Staffing
Job TypeFull-time
Salary
$45 - $60
Canonsburg, PA
5 months ago
company-logo

Title Reviewer

Innovation Land Services
Job TypeFull-time
 
Pittsburgh, PA
5 months ago
company-logo

Oil and Gas Title Attorney

Oliva Gibbs PLLC
Job TypeFull-time
 
Houston, TX
2 months ago
company-logo

Civil/Structural Designer

Dudley Staffing
Job TypeFull-time
Salary
$30 - $60
Canonsburg, PA
5 months ago
company-logo

Landman

Stockyards Energy Land Services
Job TypeContract
 
Akiachak, TX
6 months ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Midland, TX
4 months ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Cheyenne, WY
4 months ago
company-logo

E & I - Office/Field Administration

Surepoint Group
Job Typefull_time
 
Grande Prairie, AB
27 days ago
company-logo

Senior Division Order Analyst

Formentera
Job TypeFull-time
Salary
$110000 - $130000
Austin, TX
about 1 year ago
company-logo

Mechanical/Piping Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, PA
5 months ago

Notice: The inclusion of job postings or company information on our platform does not imply endorsement, partnership, or affiliation. Listings may include publicly available roles from various sources, and companies shown may not have a direct relationship with Energy Hire.