it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice

Modal title

4 jobs found in San Antonio

Senior Contract Analyst
VivSoft Technologies San Antonio, Texas
Job Description Job Description Job Title: Senior Contract Analyst Location: San Antonio, TX Clearance Required: Public Trust Clearance Position Type: Full-Time About the company: At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high-performance, effective software, with a focus on impactful organisational design and software delivery dynamics. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies Job Summary: We are seeking a Senior Contract Analyst to support the Defense Health Agency (DHA) in managing acquisition and procurement activities within a mission-driven environment. This role involves supporting the full contract lifecycle, including planning, analysis, and execution, while ensuring compliance with Federal and DoD regulations. The ideal candidate will provide analytical and advisory support to ensure effective contract management and timely, accurate, and compliant procurement operations. Key Responsibilities: Lead and manage end-to-end acquisition lifecycle activities, from planning through contract closeout Perform price and cost analysis to evaluate proposals and support negotiation strategies Interpret and apply FAR, DFARS, and DoD acquisition policies to ensure compliance Provide expert advisory support to program offices on acquisition strategies and contract execution Conduct complex problem-solving and fact-finding analysis to resolve procurement challenges Develop, review, and manage contract documentation, solicitations, and modifications Collaborate with cross-functional stakeholders to ensure acquisition alignment with mission goals Support implementation of new acquisition initiatives, policies, and process improvements Utilize acquisition systems and tools to manage procurement data and reporting Qualifications & Required Skills: Clearance Required: active Public Trust clearance Bachelor's degree in finance, accounting, law, or related fields Minimum 10 years of Federal procurement experience, including at least 5 years as a Federal Government employee (1102 series or equivalent) and 5 additional years supporting Federal acquisitions in a similar role (Federal or contractor) Expert-level knowledge of Federal and DoD acquisition regulations, including FAR, DFARS, and applicable policies, directives, and procedures Strong experience in price and cost analysis, including evaluating proposals, assessing historical data, and developing negotiation positions Proven ability to handle complex acquisition issues, perform detailed analysis, and implement effective resolution strategies Demonstrated capability to provide senior-level advisory support, including technical guidance, policy interpretation, and stakeholder coordination Proficiency in Microsoft Office Suite, MS Project, and Adobe Acrobat Hands-on experience with Integrated Acquisition Environment (IAE) and DoD Acquisition Systems Strong organizational, analytical, and problem-solving skills in a highly regulated Federal contracting environment Excellent written and verbal communication skills, with the ability to develop clear documentation and present complex information effectively Benefits: Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only) Life Insurance Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays) 401K Retirement Plan with employer match Professional Development Training Reimbursement.
08/16/2026
Full time
Job Description Job Description Job Title: Senior Contract Analyst Location: San Antonio, TX Clearance Required: Public Trust Clearance Position Type: Full-Time About the company: At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high-performance, effective software, with a focus on impactful organisational design and software delivery dynamics. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies Job Summary: We are seeking a Senior Contract Analyst to support the Defense Health Agency (DHA) in managing acquisition and procurement activities within a mission-driven environment. This role involves supporting the full contract lifecycle, including planning, analysis, and execution, while ensuring compliance with Federal and DoD regulations. The ideal candidate will provide analytical and advisory support to ensure effective contract management and timely, accurate, and compliant procurement operations. Key Responsibilities: Lead and manage end-to-end acquisition lifecycle activities, from planning through contract closeout Perform price and cost analysis to evaluate proposals and support negotiation strategies Interpret and apply FAR, DFARS, and DoD acquisition policies to ensure compliance Provide expert advisory support to program offices on acquisition strategies and contract execution Conduct complex problem-solving and fact-finding analysis to resolve procurement challenges Develop, review, and manage contract documentation, solicitations, and modifications Collaborate with cross-functional stakeholders to ensure acquisition alignment with mission goals Support implementation of new acquisition initiatives, policies, and process improvements Utilize acquisition systems and tools to manage procurement data and reporting Qualifications & Required Skills: Clearance Required: active Public Trust clearance Bachelor's degree in finance, accounting, law, or related fields Minimum 10 years of Federal procurement experience, including at least 5 years as a Federal Government employee (1102 series or equivalent) and 5 additional years supporting Federal acquisitions in a similar role (Federal or contractor) Expert-level knowledge of Federal and DoD acquisition regulations, including FAR, DFARS, and applicable policies, directives, and procedures Strong experience in price and cost analysis, including evaluating proposals, assessing historical data, and developing negotiation positions Proven ability to handle complex acquisition issues, perform detailed analysis, and implement effective resolution strategies Demonstrated capability to provide senior-level advisory support, including technical guidance, policy interpretation, and stakeholder coordination Proficiency in Microsoft Office Suite, MS Project, and Adobe Acrobat Hands-on experience with Integrated Acquisition Environment (IAE) and DoD Acquisition Systems Strong organizational, analytical, and problem-solving skills in a highly regulated Federal contracting environment Excellent written and verbal communication skills, with the ability to develop clear documentation and present complex information effectively Benefits: Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only) Life Insurance Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays) 401K Retirement Plan with employer match Professional Development Training Reimbursement.
Senior Contract Analyst
VivSoft Technologies San Antonio, Texas
Job Description Job Description Job Title: Senior Contract Analyst Location: San Antonio, TX Clearance Required: Public Trust Clearance Position Type: Full-Time About the company: At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high-performance, effective software, with a focus on impactful organisational design and software delivery dynamics. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies Job Summary: We are seeking a Senior Contract Analyst to support the Defense Health Agency (DHA) in managing acquisition and procurement activities within a mission-driven environment. This role involves supporting the full contract lifecycle, including planning, analysis, and execution, while ensuring compliance with Federal and DoD regulations. The ideal candidate will provide analytical and advisory support to ensure effective contract management and timely, accurate, and compliant procurement operations. Key Responsibilities: Lead and manage end-to-end acquisition lifecycle activities, from planning through contract closeout Perform price and cost analysis to evaluate proposals and support negotiation strategies Interpret and apply FAR, DFARS, and DoD acquisition policies to ensure compliance Provide expert advisory support to program offices on acquisition strategies and contract execution Conduct complex problem-solving and fact-finding analysis to resolve procurement challenges Develop, review, and manage contract documentation, solicitations, and modifications Collaborate with cross-functional stakeholders to ensure acquisition alignment with mission goals Support implementation of new acquisition initiatives, policies, and process improvements Utilize acquisition systems and tools to manage procurement data and reporting Qualifications & Required Skills: Clearance Required: active Public Trust clearance Bachelor's degree in finance, accounting, law, or related fields Minimum 10 years of Federal procurement experience, including at least 5 years as a Federal Government employee (1102 series or equivalent) and 5 additional years supporting Federal acquisitions in a similar role (Federal or contractor) Expert-level knowledge of Federal and DoD acquisition regulations, including FAR, DFARS, and applicable policies, directives, and procedures Strong experience in price and cost analysis, including evaluating proposals, assessing historical data, and developing negotiation positions Proven ability to handle complex acquisition issues, perform detailed analysis, and implement effective resolution strategies Demonstrated capability to provide senior-level advisory support, including technical guidance, policy interpretation, and stakeholder coordination Proficiency in Microsoft Office Suite, MS Project, and Adobe Acrobat Hands-on experience with Integrated Acquisition Environment (IAE) and DoD Acquisition Systems Strong organizational, analytical, and problem-solving skills in a highly regulated Federal contracting environment Excellent written and verbal communication skills, with the ability to develop clear documentation and present complex information effectively Benefits: Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only) Life Insurance Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays) 401K Retirement Plan with employer match Professional Development Training Reimbursement.
08/16/2026
Full time
Job Description Job Description Job Title: Senior Contract Analyst Location: San Antonio, TX Clearance Required: Public Trust Clearance Position Type: Full-Time About the company: At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high-performance, effective software, with a focus on impactful organisational design and software delivery dynamics. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies Job Summary: We are seeking a Senior Contract Analyst to support the Defense Health Agency (DHA) in managing acquisition and procurement activities within a mission-driven environment. This role involves supporting the full contract lifecycle, including planning, analysis, and execution, while ensuring compliance with Federal and DoD regulations. The ideal candidate will provide analytical and advisory support to ensure effective contract management and timely, accurate, and compliant procurement operations. Key Responsibilities: Lead and manage end-to-end acquisition lifecycle activities, from planning through contract closeout Perform price and cost analysis to evaluate proposals and support negotiation strategies Interpret and apply FAR, DFARS, and DoD acquisition policies to ensure compliance Provide expert advisory support to program offices on acquisition strategies and contract execution Conduct complex problem-solving and fact-finding analysis to resolve procurement challenges Develop, review, and manage contract documentation, solicitations, and modifications Collaborate with cross-functional stakeholders to ensure acquisition alignment with mission goals Support implementation of new acquisition initiatives, policies, and process improvements Utilize acquisition systems and tools to manage procurement data and reporting Qualifications & Required Skills: Clearance Required: active Public Trust clearance Bachelor's degree in finance, accounting, law, or related fields Minimum 10 years of Federal procurement experience, including at least 5 years as a Federal Government employee (1102 series or equivalent) and 5 additional years supporting Federal acquisitions in a similar role (Federal or contractor) Expert-level knowledge of Federal and DoD acquisition regulations, including FAR, DFARS, and applicable policies, directives, and procedures Strong experience in price and cost analysis, including evaluating proposals, assessing historical data, and developing negotiation positions Proven ability to handle complex acquisition issues, perform detailed analysis, and implement effective resolution strategies Demonstrated capability to provide senior-level advisory support, including technical guidance, policy interpretation, and stakeholder coordination Proficiency in Microsoft Office Suite, MS Project, and Adobe Acrobat Hands-on experience with Integrated Acquisition Environment (IAE) and DoD Acquisition Systems Strong organizational, analytical, and problem-solving skills in a highly regulated Federal contracting environment Excellent written and verbal communication skills, with the ability to develop clear documentation and present complex information effectively Benefits: Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only) Life Insurance Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays) 401K Retirement Plan with employer match Professional Development Training Reimbursement.
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Marathon Petroleum San Antonio, Texas
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
08/12/2026
Full time
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Marathon Petroleum San Antonio, Texas
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
08/12/2026
Full time
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board