Get more replies from employers
Send a job-specific resume in minutes.
CITGO Petroleum Corporation is seeking a Risk Management Analyst to oversee cybersecurity risks across IT and OT environments. The role involves conducting risk assessments and collaborating on policy development.
The ideal candidate will have strong analytical and problem-solving skills, and a background in risk management. Perks include remote work options, vacation incentives, and a comprehensive benefits package.
CITGO Petroleum Corporation is a recognized leader in the refining industry and operates under the well-known CITGO brand. CITGO owns and operates three refineries located in Lake Charles, LA.; Lemont, IL.; and Corpus Christi, TX, and wholly and/or jointly owns 38 active terminals, six pipelines and three lubricants blending and packaging plants. With approximately 3,300 employees and a combined crude capacity of approximately 807,000 barrels-per-day (bpd), positions CITGO as one of the best-branded supplier companies in the industry.
At CITGO our people are our most important resource. Our core values are Safety, Integrity, Respect, Accountability, and Care.
The Risk Management Analyst is responsible for identifying, assessing, and managing cybersecurity risks across the organization's IT and OT environments. The analyst leads CITGO efforts in hardware / software and systems risk assessments, Risk Management, cybersecurity policy and procedure management, and cybersecurity governance. In this dynamic role, the employee oversees critical areas such as cyber risk assessments, policy and procedure rollout to system owners, and incident response planning, ensuring our business remains resilient and secure. As a key contributor, the employee collaborates with cross-functional teams to drive compliance initiatives, protect sensitive data, and help maintain the trust of CITGO's information.
Required:
Preferred:
Comprehensive Infrastructure Risk Assessment: Conduct regular and thorough cybersecurity risk assessments across the organization's entire IT and OT infrastructure, including networks, cloud environments, data centers, endpoints, IoT devices, and software applications. Ensure risk assessments are aligned with industry frameworks like NIST, and CIS Controls to identify and prioritize risks. Regularly review security configurations and controls for effectiveness and compliance with organizational policies and external regulations (e.g., GDPR, CCPA, PCI DSS). Assist in evaluating cybersecurity risks posed by third‑party vendors, contractors, and service providers, including supply chain risks. Perform regular assessments of exposure and coordinate security reviews ensuring adherence to organizational security standards.
Hardware / Software Risk Assessments for IT and OT: Coordinate the risk assessment process, meeting with IT and Business Coordinators. Ensure the assessment process moves quickly to prevent delays in the implementation of new hardware and software. Utilize external threat platforms to assess other risks. Utilizes the GRC platform to control the assessment process.
Governance Policy / Procedure Rollout to System Owners: Collaborate on developing policies, standards, and procedures to enhance risk management structure. Meet with system owners to review changes to policies, procedures, and controls. Meet with new system owners to review their responsibilities. Utilizes the GRC platform to control and document system owner responsibilities.
Supply Chain and Third-Party Cyber Risk Management: Evaluate and collaborate with Legal and Procurement to ensure supply chain risk is mitigated. Utilize cyber risk platforms to document and follow up on 3rd party risk.
Incident Response Plans (IRP): Responsible for maintaining the IT and OT IRP. Works with the Manager InfoSec and consultants to continuously update the IRP. Participate in tabletop exercises related to IT and OT IRPs.
Job duties displayed above are not all‑inclusive, site‑specific responsibilities may be assigned.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.