Enable job alerts via email!

CYBERSECURITY RISK ANALYST

CITGO Petroleum Corporation

Charlotte (NC)

Remote

USD 90,000 - 120,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

CITGO Petroleum Corporation is seeking a Cybersecurity Risk Analyst to identify and manage cybersecurity risks across IT and OT environments. This role includes conducting risk assessments, leading vulnerability management, and ensuring compliance with cybersecurity frameworks. The analyst will collaborate with teams to enhance the organization's security posture and support incident response efforts. Remote work options are available for eligible positions, along with various employee benefits.

Benefits

Remote Work options
Annual Vacation Incentive
Paid Vacation Time
Company-Paid Holidays
Excellent 401(k) Match
Pension Plan
Medical, Dental, & Vision Plans
Educational Assistance Plan
Employee Discount Programs

Qualifications

  • 8 years of job-related experience required.
  • In-depth understanding of cybersecurity frameworks.
  • Expertise in vulnerability management processes.

Responsibilities

  • Conduct comprehensive risk assessments of IT and OT systems.
  • Lead vulnerability scans and penetration tests.
  • Present risk reports to stakeholders.

Skills

Analytical Skills
Problem Solving
Communication

Education

Bachelor's Degree

Tools

NIST
ISO 27001
FAIR

Job description

CITGO PETROLEUM CORPORATION

CITGO Petroleum Corporation is a recognized leader in the refining industry and operates under the well-known CITGO brand. CITGO owns and operates three refineries located in Lake Charles, LA.; Lemont, IL.; and Corpus Christi, TX, and wholly and/or jointly owns 38 active terminals, six pipelines and three lubricants blending and packaging plants. With approximately 3,300 employees and a combined crude capacity of approximately 807,000 barrels-per-day (bpd), positions CITGO as one of the best-branded supplier companies in the industry.

At CITGO our people are our most important resource. Our core values are Safety, Integrity, Respect, Accountability, and Care.

Job Summary

The Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing cybersecurity risks across the organization's IT and OT environments. This role involves conducting comprehensive risk assessments, leading vulnerability management efforts, and ensuring compliance with industry frameworks and regulations. The analyst will work closely with cross-functional teams to design and implement effective risk mitigation strategies, evaluate third-party risks, and support incident response and post-incident evaluations. By leveraging data-driven methods and tracking key performance indicators, the Cybersecurity Risk Analyst plays a critical role in enhancing the organization's security posture and aligning cybersecurity efforts with business objectives.

Minimum Qualifications

Degree:

  • Bachelor's Degree
The minimum number of years of job related experience required by this job is:
  • 8 years.
List any specialized training or unique skills required / preferred:
  • In-depth understanding of cybersecurity frameworks such as NIST, ISO 27001, and FAIR.
  • Strong familiarity with IT and OT environments, including cloud platforms, IoT devices, data centers, and software applications.
  • Expertise in vulnerability management processes, penetration testing, and threat modeling.
  • Awareness of emerging technologies and their associated risks.
  • Advanced analytical and problem-solving skills for assessing and prioritizing risks.
  • Effective communication and presentation skills to translate technical risks into business impacts for stakeholders.
  • Proficiency in creating detailed documentation, including risk reports, policies, and compliance evidence.
  • Preferred CISSP, CRISC or other security certifications.

Job Duties

1. Comprehensive Infrastructure Risk Assessment

  • Perform regular risk assessments of IT and OT systems, including networks, cloud platforms, IoT devices, and software, aligned with NIST and CIS Controls.
  • Ensure compliance with security regulations (e.g., GDPR, CCPA, PCI DSS) and manage third-party risks.
2. Vulnerability Management
  • Lead vulnerability scans, penetration tests, and threat modeling.
  • Assess and address vulnerabilities, prioritize patches, and adapt to new threats in collaboration with teams.
3. Risk Reporting & Communication
  • Present risk reports to stakeholders, translating technical details into business impacts.
  • Use methods like FAIR to prioritize risks and provide updates on risks, incidents, and mitigation efforts.
4. Collaboration on Risk Mitigation
  • Partner with governance and IT teams to develop and implement risk mitigation strategies aligned with security and business goals.
5. Incident Response & Risk Evaluation
  • Act as a key incident response team member, offering expertise during security incidents.
  • Conduct post-incident evaluations, identify root causes, and participate in simulations to enhance response readiness.

Job Duties II

6. Cybersecurity Framework & Policy Development

  • Contribute to developing and refining cybersecurity policies, standards, and procedures aligned with risk management strategies.
  • Provide input on creating technical security standards supporting risk management goals.
7. Regulatory Compliance and Audit Support
  • Ensure compliance with regulatory requirements through risk assessments, vulnerability management, and mitigation efforts.
  • Support cybersecurity audits by providing documentation, reports, and evidence of remediation activities.
8. KPI Tracking & Reporting
  • Monitor KPIs to evaluate the effectiveness of risk and vulnerability management programs.
  • Leverage metrics, automated tools, and dashboards to report on security posture and provide real-time insights.
9. Emerging Technology Risk Management
  • Evaluate risks tied to adopting emerging technologies (e.g., AI, blockchain) and integrate them securely.
  • Develop strategies to address risks linked to digital transformation initiatives.

Job duties displayed above are not all-inclusive, site-specific responsibilities may be assigned.

Here are the incentives we offer:

• Remote Work options available for eligible positions
• Options are department and/or location specific
• 9/80 Work Schedule Option (where applicable)
• Annual Vacation Incentive (40-120 hours of additional pay) for Eligible Employees
• Paid Vacation Time
• Company-Paid Holidays
• Caregiver Leave
• Excellent 401(k) Match
• Pension Plan
• Company-Paid Sick Leave and Long-Term Disability
• Medical, Dental, & Vision Plans; FSA and HSA options
• Company-Paid Life Insurance for Active Employees
• Healthy Rewards Program
• Service Awards Program
• Educational Assistance Plan
• Dependent Children Scholarships
• Reimbursement for Gym Membership
• Employee Discount Programs
• On-site Health Clinic (select locations)
• On-site Cafeteria (select locations)
• On-site Credit Union and ATM (Corporate office only)
• On-site Fitness Center (select locations)

PLEASE NOTE ALL JOBS DO NOT QUALIFY FOR ALL PERKS

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.

Requisition ID - 1129

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cybersecurity and Risk Consultant

Reactforce

Hyde Park Township

Remote

USD 60,000 - 100,000

7 days ago
Be an early applicant

Privacy Analyst - Risk

Mayo Clinic Healthcare

Rochester

Remote

USD 78,000 - 111,000

2 days ago
Be an early applicant

Senior information Security Risk Analyst

enexusglobal

California

Remote

USD 90,000 - 140,000

6 days ago
Be an early applicant

Cyber Risk Analyst - Remote

501 CSAA Insurance Services, Inc.

Georgia

Remote

USD 80,000 - 110,000

12 days ago

Third Party Risk Analyst 2

Twilio

Remote

USD 70,000 - 110,000

6 days ago
Be an early applicant

Cyber Risk Analyst - Remote

501 CSAA Insurance Services, Inc.

Town of Texas

Remote

USD 80,000 - 110,000

3 days ago
Be an early applicant

Senior Information Security Risk Analyst

System One

Vienna

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

Risk and Medical Underwriting Lead Analyst (Hybrid)

Cigna

Franklin

Remote

USD 74,000 - 124,000

10 days ago

AML/BSA Special Risk Analyst - ISO/TPPP (Onsite/Hybrid/Remote - within AL, FL, GA, SC or TN)

Freddie Mac

Atlanta

Remote

USD 60,000 - 95,000

3 days ago
Be an early applicant