Marathon Petroleum Corporation

Associate Cybersecurity Engineer

Marathon Petroleum Corporation Findlay, Ohio, United States

Oil and Gas · 10,001+ employees

19 h ago Closes in 1d
security Junior (0-2 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves securing enterprise applications, data, AI tools, and cloud environments through proactive risk management and automated governance. The associate will collaborate with stakeholders to implement security solutions, participate in audits, and manage cybersecurity metrics.

What they look for

Cybersecurity risk management DevSecOps Identity and access management Incident response management Intrusion detection and analysis Malware analysis Penetration testing Root cause analysis Secure software development lifecycle Security controls management Security governance Security information and event management Security policy management Threat analysis and modeling Threat hunting Threat intelligence analysis

Requirements

Candidates must hold a Bachelor’s Degree in Information Technology or a related field. The position requires zero to two years of relevant experience and a strong aptitude for learning and adapting to new cybersecurity technologies.

Benefits

Health insurance Vision insurance Dental insurance Paid time off 401k matching program Paid parental leave Educational reimbursement Annual bonus program

Full description

An exciting career awaits you

At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

Position Summary

This is a technical and dynamic role, responsible for enterprise capabilities within our platforms to secure our applications, data, AI tools, and cloud environment. The role focuses on our tooling and processes to innovate through proactive risk management, continuous visibility, automated governance, and protection-by-design practices that reduce exposure, strengthen compliance, and build trust across the organization.

This position is within Digital Protection Services, falling under our Digital Technology Services organization to provide secure, compliant, and performant tools and environments to the enterprise. This will require a significant amount of collaboration with our stakeholders and peers, within an evolving ecosystem of maturity and growth for MPC. An individual in the position should be technically adept, adaptable, and eager to learn and innovate.

Key Responsibilities

  • Gains familiarity with methods to understand business requirements and ability to identify risk and risk mitigations.
  • Assists with the resolution of routine multi-functional technical issues. Learns to interpret established cybersecurity assessments, standards and develops an understanding of how they relate to security systems.
  • Develops an understanding of the efficiency and effectiveness of Security solutions, processes and controls in place.
  • Participates in analysis of the efficiency and effectiveness of Security solutions, processes and controls in place.
  • Learns to identify business impacting events, while maintaining operational reliability and managing risk.
  • Participates in security audits and documents evidence as needed. Assists with global security initiatives, policies, and compliance requirements.
  • Learns about cybersecurity metrics and their applicability for various teams.
  • Takes action through collaboration to improve metric results. Supports business consulting, guidance, and support for Cybersecurity solutions.
  • Collates insights on solution technical roadmaps, emerging cybersecurity technology and their impact on the security landscape.

Education and Experience

  • Bachelor’s Degree in Information Technology, related field or equivalent experience.
  • Zero (0) to two (2) years of relevant experience required

Skills

  • Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful.
  • AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination.
  • Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change.
  • Cybersecurity Research - Applies technical knowledge of the latest data, developments, and trends in the cybersecurity world to identify cybersecurity vulnerabilities within an organization or industry.
  • Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
  • DevSecOps - A set of practices that automates the integration of security at every phase of the software development lifecycle, from initial design through integration, testing, deployment, and software delivery, with an aim towards shortening the systems development life cycle and pas well as  continuous delivery and a security first approach.
  • Digital Forensics - Develop and manage digital forensic investigation and reporting plan which specifiesthe tools, methods, procedures and practices to be used. This includes the collection, analysis and preservation of digital evidence in line with standard procedures and reporting of findings for legal proceedings.
  • Ethical Hacking - The act of locating weaknesses and vulnerabilities of computer and information systems by duplicating the intent and actions of malicious hackers. Ethical hacking is also known as penetration testing, intrusion testing, or red teaming.
  • Identity and Access Management (IAM) - Identity and access management (IAM) is a framework of business processes, policies and technologies that facilitates the management of electronic or digital identities, ensuring that the right users have the appropriate access to technology resources.
  • Incident Response Management - An organized approach to addressing and managing the aftermath of a security breach or cyberattack, also known as an IT incident, computer incident or security incident.
  • Intrusion Detection & Analysis - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.
  • Malware Analysis - Software intentionally designed to cause damage to a computer, server, client, or computer network. A wide variety of types of malware exist, common categories include computer viruses, worms, Trojan horses, ransomware, spyware, adware, and scareware.
  • Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.
  • Root Cause Analysis - An iterative process, designed to investigate and categorize the root causes of events or failures that may have negative impacts to the overall performance of a system and establish a flexible and effective framework for the necessary corrective and preventive actions.
  • Secure Software Development Lifecycle (SSDL) - Involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.
  • Security Controls Management - Manages and maintains an information system that focus on the management of risk and the management of information systems security.
  • Security Governance - The process of developing and disseminating corporate security policies, frameworks, and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats, and vulnerabilities.
  • Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.
  • Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.
  • Threat Analysis & Modeling - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.
  • Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.
  • Threat Intelligence Analysis - Enable and conduct analysis of malicious threats, to examine their characteristics, behaviors, capabilities, intent and interactions with the environment as well as the development of defense and mitigation strategies and techniques to effectively combat such threats.

As an energy industry leader, our career opportunities fuel personal and professional growth.

Location:

Findlay, Ohio

Additional locations:

Job Requisition ID:

00023404

Location Address:

539 S Main St

Education:

Employee Group:

Full time

Employee Subgroup:

Regular

Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship  or any other status protected by applicable federal, state, or local laws.  If you would like more information about your EEO rights as an applicant, click here.

If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at talentacquisition@marathonpetroleum.com. Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at https://mympcbenefits.com.The hired candidate will also be eligible for a discretionary company-sponsored annual bonus program.

Equal Opportunity Employer: Veteran / Disability

We will consider all qualified Applicants for employment, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws. In reviewing criminal history in connection with a conditional offer of employment, Marathon will consider the key responsibilities of the role.

Similar roles