Houston, TX, US, 77077
CITGO PETROLEUM CORPORATION
CITGO Petroleum Corporation is a recognized leader in the refining industry and operates under the well-known CITGO brand. CITGO owns and operates three refineries located in Lake Charles, LA.; Lemont, IL.; and Corpus Christi, TX, and wholly and/or jointly owns 38 active terminals, six pipelines and three lubricants blending and packaging plants. With approximately 3,300 employees and a combined crude capacity of approximately 807,000 barrels-per-day (bpd), positions CITGO as one of the best-branded supplier companies in the industry.
At CITGO our people are our most important resource. Our core values are Safety, Integrity, Respect, Accountability, and Care.
Job Summary
Minimum Qualifications
Required:
- Bachelor’s degree and 8 years of experience; or associate’s degree and 10 years of experience; or high school diploma and 12 years of experience.
- Awareness of emerging technologies and their associated risks.
- Advanced analytical and problem-solving skills for assessing and prioritizing risks.
- Compliance Standards: Familiarity with standards like ISO 27001 and NIST 800.53, 800.144 and 800.82.
- IT and OT Risks: General knowledge of risks that impact IT and OT systems.
- Supply Chain and Third-Party Cyber Risk Management (TPRM): Knowledge of best practices for TPRM, including highest priority risk mitigation practices.
- Attention to Detail: Precision in managing risk assessments and governance to ensure adherence to compliance standards.
Preferred:
- CISSP, CRISC or other security or compliance certifications.
Job Duties
- Comprehensive Infrastructure Risk Assessment:
- Conduct regular and thorough cybersecurity risk assessments across the organization's entire IT and OT infrastructure, including networks, cloud environments, data centers, endpoints, IoT devices, and software applications.
- Ensure risk assessments are aligned with industry frameworks like NIST, and CIS Controls to identify and prioritize risks.
- Regularly review security configurations and controls for effectiveness and compliance with organizational policies and external regulations (e.g., GDPR, CCPA, PCI DSS).
- Assist in evaluating cybersecurity risks posed by third-party vendors, contractors, and service providers, including supply chain risks.
- Perform regular assessments of exposure and coordinate security reviews ensuring adherence to organizational security standards.
- Hardware / Software Risk Assessments for IT and OT:
- Coordinates the risk assessment process, meeting with IT and Business Coordinators.
- Ensure the assessment process moves quickly to prevent delays in the implementation of new hardware and software.
- Utilize external threat platforms to assess other risks.
- Utilizes the GRC platform to control the assessment process..
- Governance Policy / Procedure Rollout to System Owners:
- Collaborate on developing policies, standards, and procedures to enhance risk management structure. Meets with system owners to review changes to policies, procedures, and controls.
- Meets with new system owners to review their responsibilities.
- Utilizes the GRC platform to control and document system owner responsibilities.
- Supply Chain and Third-Party Cyber Risk Management:
- Evaluate and collaborate with Legal and Procurement to ensure supply chain risk is mitigated.
- Utilize cyber risk platforms to document and follow up on 3rd party risk.
- Incident Response Plans (IRP):
- Responsible for maintaining the IT and OT IRP.
- Works with the Manager InfoSec and consultants to continuously update the IRP.
- Participate in tabletop exercises related to IT and OT IRPs.
Job Duties II
Job duties displayed above are not all-inclusive, site-specific responsibilities may be assigned.
Here are the incentives we offer:
• Remote Work options available for eligible positions
• Options are department and/or location specific
• 9/80 Work Schedule Option (where applicable)
• Annual Vacation Incentive (40-120 hours of additional pay) for Eligible Employees
• Paid Vacation Time
• Company-Paid Holidays
• Caregiver Leave
• Excellent 401(k) Match
• Pension Plan
• Performance Incentive
• Company-Paid Sick Leave and Long-Term Disability
• Medical, Dental, & Vision Plans; FSA and HSA options
• Company-Paid Life Insurance for Active Employees
• Healthy Rewards Program
• Service Awards Program
• Educational Assistance Plan
• Dependent Children Scholarships
• Reimbursement for Gym Membership
• Employee Discount Programs
• On-site Health Clinic (select locations)
• On-site Cafeteria (select locations)
• On-site Credit Union and ATM (Corporate office only)
• On-site Fitness Center (select locations)
PLEASE NOTE ALL JOBS DO NOT QUALIFY FOR ALL PERKS
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.
Requisition ID - 1920
Nearest Major Market: Houston