Title:  IT Security Analyst

Date:  Aug 24, 2026
Location: 

Dallas, TX, US, 75219

Basic Function

The IT Security Architect defines and governs enterprise cybersecurity architecture standards and secure design practices across IT and OT environments. Provides strategic architecture guidance, aligns security decisions with business objectives and cyber risk priorities, and supports secure adoption of emerging technologies while driving risk reduction and operational resilience.

Job Duties

Enterprise Cybersecurity Architecture Strategy and Standards

  • Define, maintain, and improve cybersecurity architecture principles, standards, guardrails, patterns, and reference architectures.
  • Establish reusable architecture patterns that enable secure-by-design delivery, reduce inconsistent solution decisions, limit architectural drift, and address avoidable control gaps.
  • Use the enterprise cybersecurity taxonomy to organize architecture decisions, standards, roadmaps, risks, controls, metrics, and capability maturity discussions.

 

Security Architecture Governance and Design Reviews

  • Lead or facilitate security architecture reviews for major technology initiatives, cyber portfolio projects, OT modernization, cloud solutions, application modernization, identity patterns, data platforms, integrations, automation, and AI-enabled capabilities.
  • Identify architecture risks, design gaps, control weaknesses, and standards deviations; document tradeoffs, recommendations, decisions, and residual risk implications.
  • Define architecture dependencies, design constraints, runway needs, standards readiness, and risk reduction outcomes for major IT and cyber initiatives.

 

Cyber Risk, Control, and Capability Traceability

  • Support risk register accuracy by mapping technology and architecture risks to affected capabilities, root-cause design gaps, maturity gaps, and practical mitigation approaches.
  • Advise on architecture implications of policy exceptions, control gaps, risk acceptances, third-party dependencies, and emerging technology adoption decisions.

 

Technology Domain Architecture Guidance

  • Guide security architecture for IT/OT convergence, industrial digital platforms, cyber-physical systems, network segmentation, secure remote access, monitoring, identity, data exchange, cloud, SaaS, application, API, automation, and AI-enabled solutions.
  • Evaluate emerging technologies and industry trends for applicability, risk, architecture impact, control requirements, and adoption guardrails.

 

Stakeholder Partnership and Continuous Improvement

  • Influence strategic initiatives by explaining architecture options, risk tradeoffs, design implications, and recommended paths forward.
  • Facilitate alignment where ownership is shared or ambiguous by clarifying architecture boundaries, decision rights, and execution expectations.
  • Support continuous improvement of architecture governance, standards adoption, exception management, security design quality, and measurable security outcomes.

 

Special assignments or tasks may be assigned to the employee by their supervisor, as determined from time to time in the supervisor’s sole and complete discretion.

 

Experience

A minimum of 8 years of experience in IT infrastructure, cybersecurity, cloud security, security engineering, enterprise architecture, solution architecture, OT security, or related technology domains.

  • Minimum of 4 years of experience in an architecture function, including development of standards, reference architectures, design patterns, architecture governance, or technology roadmaps.
  • Demonstrated experience translating business, risk, regulatory, and technical requirements into practical security architecture guidance.
  • Demonstrated ability to operate as a senior technical advisor across multiple teams, domains, and levels of leadership.
  • Experience leading architecture reviews, producing architecture decision records, documenting design tradeoffs, and influencing risk-informed discussions across technical and business stakeholders.
  • Experience working across multiple technology domains including some combination of identity, network, cloud, endpoint, data, application, SaaS, infrastructure, integrations, OT, or cyber-physical systems.
  • Experience supporting cyber risk reduction, control alignment, maturity improvement, or security roadmap development.

Education Level

A bachelor’s degree in Information Technology, Information Security, Cybersecurity, Computer Science, Engineering, or a related field is required. Equivalent experience may be considered in lieu of a degree.

 

Preferred Educational Level: 

Master’s degree in Information Technology, Cybersecurity, Information Security, Engineering, Business Administration, or a related field.

Required Skills

  • Enterprise security architecture and secure-by-design principles.
  • Architecture frameworks and methods such as TOGAF, SABSA, DoDAF, NIST, C2M2, SAFe for Architects, or similar approaches.
  • Architecture governance methods, including standards management, design review facilitation, architecture decision records, and architecture review forums.
  • Systems thinking and ability to analyze complex cross-domain dependencies.
  • Cyber risk analysis, control alignment, maturity assessment, and risk-informed roadmap development.
  • Ability to translate strategy, risk, and control requirements into practical architecture standards and engineering-ready guardrails.
  • Security architecture concepts across IT, OT, cyber-physical systems, cloud, SaaS, application, API, data, identity, network, monitoring, automation, and resilience domains.
  • Strong communication, facilitation, stakeholder management, and executive-facing presentation skills.
  • Continuous improvement mindset with ability to establish reusable patterns, feedback loops, and measurable outcomes.

 

Preferred Skills: 

  • Oil and gas, critical infrastructure, industrial cybersecurity, or OT security architecture experience.
  • Experience with NIST CSF, C2M2, CIS, ISO 27001, NERC CIP, TSA security directives, or other cybersecurity and regulatory frameworks.
  • Experience aligning security architecture to enterprise cyber taxonomies, capability models, maturity models, control libraries, or unified controls frameworks.
  • Experience supporting cyber portfolio planning, investment prioritization, roadmap development, OKRs, KPIs, KRIs, or value/risk-based planning.
  • Experience with security architecture for AI, analytics, automation, machine identities, APIs, data platforms, cloud-native architectures, and SaaS ecosystems.
  • Familiarity with SSE/SASE, Zero Trust, cyber-physical systems, and digital transformation security patterns.
  • Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, GIAC, ISA/IEC 62443, cloud security, or similar credentials.

 

Supervisory/Managerial Responsibility

This role has no direct supervisory responsibilities but is expected to provide senior technical leadership, architecture direction, mentoring, and cross-functional influence across cybersecurity, IT, and OT.

 

Work Conditions

Office-based, with up to 20% travel by land or air is required. Subject to all weather and varying road conditions.

Benefits

HF Sinclair offers a comprehensive benefits package designed to support the well-being of our employees and their families. Our benefits include, but are not limited to, the following:

 

  • Medical Insurance
  • Vision Insurance
  • Dental Insurance
  • Paid Time-Off
  • 401(k) Retirement Plan with match
  • Educational Reimbursement
  • Parental Bonding Time
  • Employee Discounts

 

We are committed to fostering a supportive and inclusive work environment, ensuring our employees have the resources needed to thrive professionally and personally. Benefit eligibility is governed by official plan documents, for more details visit Total Rewards.

Our One HF Sinclair Culture:

At HF Sinclair, we are united through our One HF Sinclair Culture, which is underpinned by our five core values of Safety, Integrity, Teamwork, Ownership and Inclusion. Developed to empower our people, our five core cultural values are at the heart of everything we do and extend to how we engage our stakeholders. These values influence our decisions, shape our behaviors and keep us connected across the entire organization. We maintain a true Safety culture for our employees, communities, environments and customers. Our goal is to make sure everyone returns home safely each day. We have a long-standing commitment to Integrity and ethical behavior and do what is right for our employees, investors, communities and the environment. We encourage employees to Step Up and Stand Out by championing a culture of Teamwork and Ownership. We foster a culture of Inclusion by encouraging diversity of experiences, viewpoints and backgrounds. What makes each of us different, together makes us stronger.

About HF Sinclair Corporation

HF Sinclair Corporation, headquartered in Dallas, Texas, is an independent energy company that produces and markets high-value light products such as gasoline, diesel fuel, jet fuel, renewable diesel and other specialty products. HF Sinclair owns and operates refineries located in Kansas, Oklahoma, New Mexico, Wyoming, Washington and Utah and markets its refined products principally in the Southwest U.S., the Rocky Mountains extending into the Pacific Northwest and in other neighboring Plains states. HF Sinclair supplies high-quality fuels to more than 1,500 branded stations and licenses the use of the Sinclair brand at more than 300 additional locations throughout the country. In addition, subsidiaries of HF Sinclair produce and market base oils and other specialized lubricants in the U.S., Canada and the Netherlands, and export products to more than 80 countries. Through its subsidiaries, HF Sinclair produces renewable diesel at two of its facilities in Wyoming and also at its facility in Artesia, New Mexico. HF Sinclair provides petroleum product and crude oil transportation, terminalling, storage and throughput services to its refineries and the petroleum industry.

Equal Opportunity Employer

HF Sinclair Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other prohibited ground of discrimination.


Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth