CYBERSECURITY RISK ANALYST
CITGO Petroleum Corporation
Cybersecurity Risk Analyst
Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing cybersecurity risks across the organization's IT and OT environments. This role involves conducting comprehensive risk assessments, leading vulnerability management efforts, and ensuring compliance with industry frameworks and regulations. The analyst will work closely with cross-functional teams to design and implement effective risk mitigation strategies, evaluate third-party risks, and support incident response and post-incident evaluations. By leveraging data-driven methods and tracking key performance indicators, the Cybersecurity Risk Analyst plays a critical role in enhancing the organization's security posture and aligning cybersecurity efforts with business objectives.
Minimum Qualifications:
- Degree: Bachelor's Degree
- The minimum number of years of job related experience required by this job is: 8 years.
- In-depth understanding of cybersecurity frameworks such as NIST, ISO 27001, and FAIR.
- Strong familiarity with IT and OT environments, including cloud platforms, IoT devices, data centers, and software applications.
- Expertise in vulnerability management processes, penetration testing, and threat modeling.
- Awareness of emerging technologies and their associated risks.
- Advanced analytical and problem-solving skills for assessing and prioritizing risks.
- Effective communication and presentation skills to translate technical risks into business impacts for stakeholders.
- Proficiency in creating detailed documentation, including risk reports, policies, and compliance evidence.
- Preferred CISSP, CRISC or other security certifications.
Job Duties:
- Comprehensive Infrastructure Risk Assessment: Perform regular risk assessments of IT and OT systems, including networks, cloud platforms, IoT devices, and software, aligned with NIST and CIS Controls. Ensure compliance with security regulations (e.g., GDPR, CCPA, PCI DSS) and manage third-party risks.
- Vulnerability Management: Lead vulnerability scans, penetration tests, and threat modeling. Assess and address vulnerabilities, prioritize patches, and adapt to new threats in collaboration with teams.
- Risk Reporting & Communication: Present risk reports to stakeholders, translating technical details into business impacts. Use methods like FAIR to prioritize risks and provide updates on risks, incidents, and mitigation efforts.
- Collaboration on Risk Mitigation: Partner with governance and IT teams to develop and implement risk mitigation strategies aligned with security and business goals.
- Incident Response & Risk Evaluation: Act as a key incident response team member, offering expertise during security incidents. Conduct post-incident evaluations, identify root causes, and participate in simulations to enhance response readiness.
- Cybersecurity Framework & Policy Development: Contribute to developing and refining cybersecurity policies, standards, and procedures aligned with risk management strategies. Provide input on creating technical security standards supporting risk management goals.
- Regulatory Compliance and Audit Support: Ensure compliance with regulatory requirements through risk assessments, vulnerability management, and mitigation efforts. Support cybersecurity audits by providing documentation, reports, and evidence of remediation activities.
- KPI Tracking & Reporting: Monitor KPIs to evaluate the effectiveness of risk and vulnerability management programs. Leverage metrics, automated tools, and dashboards to report on security posture and provide real-time insights.
- Emerging Technology Risk Management: Evaluate risks tied to adopting emerging technologies (e.g., AI, blockchain) and integrate them securely. Develop strategies to address risks linked to digital transformation initiatives.
Job duties displayed above are not all-inclusive, site-specific responsibilities may be assigned.
Here are the incentives we offer:
- Remote Work options available for eligible positions
- Options are department and/or location specific
- 9/80 Work Schedule Option (where applicable)
- Annual Vacation Incentive (40-120 hours of additional pay) for Eligible Employees
- Paid Vacation Time
- Company-Paid Holidays
- Caregiver Leave
- Excellent 401(k) Match
- Pension Plan
- Company-Paid Sick Leave and Long-Term Disability
- Medical, Dental, & Vision Plans; FSA and HSA options
- Company-Paid Life Insurance for Active Employees
- Healthy Rewards Program
- Service Awards Program
- Educational Assistance Plan
- Dependent Children Scholarships
- Reimbursement for Gym Membership
- Employee Discount Programs
- On-site Health Clinic (select locations)
- On-site Cafeteria (select locations)
- On-site Credit Union and ATM (Corporate office only)
- On-site Fitness Center (select locations)
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability. Requisition ID - 1129
- ...Cybersecurity Risk Analyst Date: May 28, 2026 Location: Houston, TX, US, 77010 Company: NRG As an NRG employee, we encourage you to take charge of your career and development journey. We invite you to explore exciting opportunities across our businesses. You'll find...SuggestedContract workWork at office
- ...aspects of our business. Join our highly experienced network of professionals and connect with our creative team. The Cybersecurity Threats & Risk Analyst will work within the IT Security & Compliance organization to identify, analyze, and help mitigate cybersecurity...Suggested
- AP Recruiters is seeking a Senior IT Business Systems Analyst to focus on cybersecurity and risk management. This on-site role in Houston requires over 10 years of experience. The ideal candidate will analyze complex technical risks, support decision-making, and work with...Suggested
- ...Information Risk Strategy Management Vulnerability Management Role This position supports the Information Risk Strategy Management... ...assessments, as needed. Gain foundational knowledge in cybersecurity and apply that knowledge toward remediation initiatives. Build...SuggestedRemote work
- ...their satisfaction throughout their tenure with Collabera. As a result of these efforts, we have been recognized by Staffing Industry Analysts (SIA) as the “Best Staffing Firm to Work For” for four consecutive years since 2012. With over forty offices globally and a...SuggestedRemote work
- ...Cybersecurity Analyst Location: Houston, TX 77002 Duration: 6 months contract to hire Description of Duties/Essential Functions:... ...critical HPW systems Responsible for communicating cyber risks and recommendations to mitigate risks to the COH CISO, COH CIO...Contract work
- ...Cybersecurity Analyst Core Focus Areas ~40% - Security Operations and Monitoring ~30% - Compliance and Documentation ~20% - User Support and Security Awareness ~10% - Incident Response Support Key Responsibilities Monitor security alerts, investigate...
- ...Position Title: Senior Security Analyst | Location: HOUSTON, TX | FLSA Class: EXEMPT |... ...and advanced analytics to uncover hidden risks in hybrid cloud and on-prem environments... ...sector Qualifications Bachelor’s degree in Cybersecurity, Computer Science, or related field (or...Local area
- ...Cybersecurity Analyst About PROENERGY PROENERGY is an engineering, R&D, and manufacturing powerhouse. The company addresses every need... ...security technologies and capabilities. Compliance and Risk Management: Support compliance activities for NERC CIP...Work experience placementWork at officeLocal areaWorldwideWork visa
- ...Nrg Bluewater Wind is seeking a Cybersecurity Risk Analyst in Houston, Texas to support the organization's cyber risk management program. The analyst will conduct risk assessments, evaluate vulnerabilities, and recommend risk treatment solutions. A minimum of five years...
- ...About the job Cyber Risk Analyst - Senior Associate HORNE is a professional services firm founded on a cornerstone of public... ...beyond regulatory requirements to truly strengthen a company's cybersecurity posture. Position Description: All IT Audit Senior...Local area
$105.79k - $141.05k
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments...Full timeTemporary workRemote work- Manhattan Life Group in Houston, TX, is seeking a Senior IT Security Analyst to safeguard information systems through effective threat... ...years' professional experience in IT security and relevant cybersecurity certifications like CompTIA Security+ or CISSP. Responsibilities...
- MetroNational in Houston is seeking a Cybersecurity Analyst to monitor and support the cybersecurity of its IT systems. The role involves assessing threats and vulnerabilities, documenting incidents, and ensuring compliance with security policies. The ideal candidate will...
- ...Cybersecurity Operations Analyst Houston, TX About Intuitive Machines: Intuitive Machines is an innovative and cutting-edge space company making... ...of vulnerabilities and security findings Contribute to risk management efforts by documenting and communicating...
- NRG Energy in Houston is seeking a Cybersecurity Risk Analyst to support its cyber risk management program. This role involves conducting risk assessments, identifying cyber threats, and engaging with various stakeholders to ensure informed decision-making. The ideal candidate...Work at office
- The Jupiter Group, Inc is seeking a Cybersecurity Threats & Risk Analyst in Houston, Texas. This role involves identifying and mitigating cybersecurity risks and threats through robust analysis. The ideal candidate will collaborate with various IT and business teams while...
- A leading energy services provider is seeking a Cybersecurity Threats & Risk Analyst to join their IT security team in Houston, Texas. The ideal candidate will assess cyber risk and monitor threats while supporting incident response efforts. Required qualifications include...
- ...Director of Cybersecurity and Privacy Risk Advisor About the Company Prestigious international law firm Industry Law Practice Type Privately Held About the Role The Company is in search of a Director, Cybersecurity and Privacy Risk Advisor...Work experience placement
$69.5k - $133.1k
A leading healthcare company is seeking a Senior Risk Analyst to enhance risk management and internal controls. The role requires a Bachelor’s degree in accounting or finance, CPA certification, and minimum 2 years experience in public accounting or finance/audit. Responsibilities...$95k - $110k
...Job Description Risk Analyst - Houston Who: A growing auto finance company building out its credit risk team. What: Analyze and forecast repossessions, origination risks, servicing exposure, and overall credit performance. When: Newly created position due...Work at office$90 per hour
...Freelance Cybersecurity Analyst - AI Trainer2 days ago Be among the first 25 applicantsThis opportunity is only for candidates currently residing in the specified country. Your location may affect eligibility and rates. Please submit your resume in English and indicate...Part timeFreelanceWork at officeRemote work$90 per hour
...A leading AI company is seeking a Freelance Cybersecurity Analyst to analyze security alerts, conduct threat hunting, and assess AI-generated reports. The ideal candidate will have significant experience in cybersecurity operations and SOC backgrounds. This fully remote...FreelanceRemote work- ...Title: Cybersecurity Compliance Analyst (GRC) Location: Houston, TX, 77024 (hybrid) Duration: 6-month contract-to-hire Work Requirements:... ...27001, COBIT, etc.) Provide high-level summaries and risk - based recommendations for an improved IT controls environment...Contract workLocal areaFlexible hours
- ...that matches your skills? We'd love to connect! This posting is part of our Talent Pipeline Program for future Commodity Trading Risk Analyst opportunities. We are actively building a network of talented professionals we'd like to consider for upcoming positions ....Permanent employmentFull timeTemporary work
- • Track progress of integrity assessments during the year and provide annual reporting metrics • Assist with document migration and apply meta data to all digital files • Initiate and lead interaction with appropriate subject matter experts and other stakeholders for...
- A cutting-edge space company based in Houston is seeking a Cybersecurity Operations Analyst to enhance its security posture in a regulated aerospace environment. The ideal candidate should possess extensive experience in security operations, incident management, and endpoint...
- ...Aramco Trading Americas Risk Analyst(1919) Information Technology Staff - Houston TX. - Full Time Job Description Summary Assist in tasks related to the analysis and assessment of existing systems, supporting the identification of business, organizational...Full time
- NRG Energy, Inc. is seeking a Cybersecurity Risk Analyst who will support the organization's cyber risk management program by identifying, assessing, and communicating cyber risks across various technologies and business initiatives. This role requires strong analytical...
- ...Cyber Security Compliance Analyst Software Guidance & Assistance, Inc., (SGA), is searching... ...: Own the lifecycle management of cybersecurity and regulatory policies, including... ...identify gaps, misalignment, or emerging risk areas, and propose practical corrective...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CYBERSECURITY RISK ANALYST. Be the first to apply!
- cyber security consultant Houston, TX
- cyber security specialist Houston, TX
- cybersecurity analyst remote Houston, TX
- transaction risk analyst Houston, TX
- operational risk consultant Houston, TX
- it risk analyst Houston, TX
- information risk analyst Houston, TX
- operational risk specialist Houston, TX
- risk analyst Houston, TX
- third party risk analyst Houston, TX


