Title: IT Security Analyst
Dallas, TX, US, 75219
Basic Function
Job Duties
Enterprise Cybersecurity Architecture Strategy and Standards
- Define, maintain, and improve cybersecurity architecture principles, standards, guardrails, patterns, and reference architectures.
- Establish reusable architecture patterns that enable secure-by-design delivery, reduce inconsistent solution decisions, limit architectural drift, and address avoidable control gaps.
- Use the enterprise cybersecurity taxonomy to organize architecture decisions, standards, roadmaps, risks, controls, metrics, and capability maturity discussions.
Security Architecture Governance and Design Reviews
- Lead or facilitate security architecture reviews for major technology initiatives, cyber portfolio projects, OT modernization, cloud solutions, application modernization, identity patterns, data platforms, integrations, automation, and AI-enabled capabilities.
- Identify architecture risks, design gaps, control weaknesses, and standards deviations; document tradeoffs, recommendations, decisions, and residual risk implications.
- Define architecture dependencies, design constraints, runway needs, standards readiness, and risk reduction outcomes for major IT and cyber initiatives.
Cyber Risk, Control, and Capability Traceability
- Support risk register accuracy by mapping technology and architecture risks to affected capabilities, root-cause design gaps, maturity gaps, and practical mitigation approaches.
- Advise on architecture implications of policy exceptions, control gaps, risk acceptances, third-party dependencies, and emerging technology adoption decisions.
Technology Domain Architecture Guidance
- Guide security architecture for IT/OT convergence, industrial digital platforms, cyber-physical systems, network segmentation, secure remote access, monitoring, identity, data exchange, cloud, SaaS, application, API, automation, and AI-enabled solutions.
- Evaluate emerging technologies and industry trends for applicability, risk, architecture impact, control requirements, and adoption guardrails.
Stakeholder Partnership and Continuous Improvement
- Influence strategic initiatives by explaining architecture options, risk tradeoffs, design implications, and recommended paths forward.
- Facilitate alignment where ownership is shared or ambiguous by clarifying architecture boundaries, decision rights, and execution expectations.
- Support continuous improvement of architecture governance, standards adoption, exception management, security design quality, and measurable security outcomes.
Special assignments or tasks may be assigned to the employee by their supervisor, as determined from time to time in the supervisor’s sole and complete discretion.
Experience
A minimum of 8 years of experience in IT infrastructure, cybersecurity, cloud security, security engineering, enterprise architecture, solution architecture, OT security, or related technology domains.
- Minimum of 4 years of experience in an architecture function, including development of standards, reference architectures, design patterns, architecture governance, or technology roadmaps.
- Demonstrated experience translating business, risk, regulatory, and technical requirements into practical security architecture guidance.
- Demonstrated ability to operate as a senior technical advisor across multiple teams, domains, and levels of leadership.
- Experience leading architecture reviews, producing architecture decision records, documenting design tradeoffs, and influencing risk-informed discussions across technical and business stakeholders.
- Experience working across multiple technology domains including some combination of identity, network, cloud, endpoint, data, application, SaaS, infrastructure, integrations, OT, or cyber-physical systems.
- Experience supporting cyber risk reduction, control alignment, maturity improvement, or security roadmap development.
Education Level
A bachelor’s degree in Information Technology, Information Security, Cybersecurity, Computer Science, Engineering, or a related field is required. Equivalent experience may be considered in lieu of a degree.
Preferred Educational Level:
Master’s degree in Information Technology, Cybersecurity, Information Security, Engineering, Business Administration, or a related field.
Required Skills
- Enterprise security architecture and secure-by-design principles.
- Architecture frameworks and methods such as TOGAF, SABSA, DoDAF, NIST, C2M2, SAFe for Architects, or similar approaches.
- Architecture governance methods, including standards management, design review facilitation, architecture decision records, and architecture review forums.
- Systems thinking and ability to analyze complex cross-domain dependencies.
- Cyber risk analysis, control alignment, maturity assessment, and risk-informed roadmap development.
- Ability to translate strategy, risk, and control requirements into practical architecture standards and engineering-ready guardrails.
- Security architecture concepts across IT, OT, cyber-physical systems, cloud, SaaS, application, API, data, identity, network, monitoring, automation, and resilience domains.
- Strong communication, facilitation, stakeholder management, and executive-facing presentation skills.
- Continuous improvement mindset with ability to establish reusable patterns, feedback loops, and measurable outcomes.
Preferred Skills:
- Oil and gas, critical infrastructure, industrial cybersecurity, or OT security architecture experience.
- Experience with NIST CSF, C2M2, CIS, ISO 27001, NERC CIP, TSA security directives, or other cybersecurity and regulatory frameworks.
- Experience aligning security architecture to enterprise cyber taxonomies, capability models, maturity models, control libraries, or unified controls frameworks.
- Experience supporting cyber portfolio planning, investment prioritization, roadmap development, OKRs, KPIs, KRIs, or value/risk-based planning.
- Experience with security architecture for AI, analytics, automation, machine identities, APIs, data platforms, cloud-native architectures, and SaaS ecosystems.
- Familiarity with SSE/SASE, Zero Trust, cyber-physical systems, and digital transformation security patterns.
- Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, GIAC, ISA/IEC 62443, cloud security, or similar credentials.
Supervisory/Managerial Responsibility
This role has no direct supervisory responsibilities but is expected to provide senior technical leadership, architecture direction, mentoring, and cross-functional influence across cybersecurity, IT, and OT.
Work Conditions
Office-based, with up to 20% travel by land or air is required. Subject to all weather and varying road conditions.
Benefits
- Medical Insurance
- Vision Insurance
- Dental Insurance
- Paid Time-Off
- 401(k) Retirement Plan with match
- Educational Reimbursement
- Parental Bonding Time
- Employee Discounts
We are committed to fostering a supportive and inclusive work environment, ensuring our employees have the resources needed to thrive professionally and personally. Benefit eligibility is governed by official plan documents, for more details visit Total Rewards.
Our One HF Sinclair Culture:
About HF Sinclair Corporation
Equal Opportunity Employer
HF Sinclair Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other prohibited ground of discrimination.
Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth