Chevron

IT Risk Analyst / Cybersecurity DevOps Engineer

Chevron Makati City, National Capital District, Philippines

Oil and Gas · 1,001-5,000 employees

13 h ago Closes in 1d
devops Senior (5-10 yrs) Full-time Philippines
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves developing and maintaining software solutions for digital forensics and insider threat operations while assessing cyber risks and compliance. You will lead cloud-based security initiatives and collaborate with technical teams to protect the organization from cyber threats.

What they look for

Java Python C++ JavaScript Azure Ansible Docker Kubernetes Jenkins CI/CD Linux Network Security Risk Assessment Cybersecurity Agile Scrum

Requirements

Candidates must have strong proficiency in multiple programming languages and experience with DevOps tools, cloud infrastructure, and network security. A background in risk management, compliance auditing, and software development methodologies like Agile is required.

Full description

Total Number of Openings

5

For Cybersecurity DevOps Engineer

Job Description Summary

Chevron's Cyber Investigation team is seeking a skilled Integration Software Engineer. In this role, you will be responsible for developing innovative in-house code, integrations, and solutions that directly support Chevron’s Forensics and Insider Threat Operations teams. You will contribute significantly to our security initiatives by supporting DevOps in Chevron's Cyber investigations and working on various projects. Join us to be part of a team where your expertise and creativity will be valued.

Job Description

As an Integration Software Engineer focused on enabling capabilities in support of Digital Forensics and Insider Threat Operations, you will be responsible for developing, implementing, optimizing, and maintaining critical software solutions. You must possess expertise in multiple programming languages and DevOps tools, while demonstrating a robust skill set in network and security software development methodologies. Your role will include integrating various systems to enhance forensic analysis capabilities and supporting insider threat detection efforts through advanced software solutions.

 

Required Education / Degrees

 

Other preferred skills / competencies

  • Maintain and troubleshoot Azure environments and services via ansible playbooks.
  • Deploy and manage modern and legacy environments through automation and IaC DevOps approach.
  • Design and implement application security for Azure cloud native solutions.
  • Lead and mentor software engineering and development teams to evaluate and identify optimal cloud solutions.
  • Modify and improve existing systems.
  • Educate teams on the implementation of new cloud technologies and initiatives.
  • Design, develop, and deploy modular cloud-based systems.
  • Develop and maintain cloud solutions in accordance with best practices.
  • Work closely with the cyber investigations PO, Insider threat analyst, and forensic investigators to develop and maintain capabilities that will help protect Chevron for bad actors. 

 

Experience

  • Proficiency in languages like Java, Python, C++, and JavaScript
  • Experience with software development methodologies, such as Agile and Scrum.
  • Familiar with Tools like Docker, Kubernetes, Jenkins, RabbitMQ, and CI/CD pipelines
  • Experience deploying solutions into azure via Ansible playbooks.
  • In-depth experience architecting, deploying, and supporting cloud infrastructure.
  • Experience with cloud methodologies, automation, orchestration
  • Strong experience in Linux OS administration and security (Windows is a plus).
  • Demonstrated experience in the following areas: Network engineering, Network security, or System/Network monitoring.
  • Strong experience with Microsoft Windows Server Technologies (Server 2022, Server Core, etc.)
  • Experience in the design and implementation of distributed applications
  • Experience in architecting and implementing cloud-based solutions with robust BCP and DR requirements.
  • SAFe Agile framework experience preferred.

For Cybersecurity Risk Analyst

The Cybersecurity Risk Analyst position is responsible for assessing risks, analyzing cyber threats, and assisting in preventing cyber-attacks before they occur. They provide guidance on tools to measure and manage risk, identify/mitigate threats, and protect against unauthorized disclosure of confidential information. Risk Analysts duties include assessing the adequacy of security strategies, adherence to security guardrails and calculating the impact of adverse events or threats. Ideal candidates will assist in ensuring effective execution of cybersecurity strategies and our risk management framework by managing relationships with key stakeholders, verifying that IT risks are appropriately mitigated, as well as providing periodic updates on the state of compliance.

Key job responsibilities

  • Advises leadership on cybersecurity initiatives that supports the latest trends in IT & OT security, risk, and controls.
  • Maintains cybersecurity documentation including Business Continuity and Disaster Recovery Plans
  • Facilitate risk assessment exercises, perform compliance and risk monitoring/validation, and other compliance assurance exercises as required.
  • Leads awareness and training for the information technology risk program elements to ensure responsibilities are understood and executed.
  • Coordinates external and internal assurance or advisory audits, representing information technology throughout the lifecycle of the audit (from planning through remediation strategy).
  • Monitors, tracks, and reports mitigation and resolution of IT risks.
  • Facilitates compliance of all equipment utilized in the Process Control Network (PCN)/Operational Technology (OT) and Demilitarized Zone (DMZ), including timely remediation of critical vulnerabilities.
  • Supports and integrates IT standards into the PCN environment.
  • Serves as site representative for internal and external cyber initiatives.
  • Serves as Process Advisor for the Operations Technology Incident Response Process (OTIRP)
  • Works closely with other technical, incident management, and forensic personnel to develop a broader understanding of the intent, objectives, and activities of cyber threat actors and supports the cyber defense program.

Chevron participates in E-Verify in certain locations as required by law.

Similar roles