Title: OT Cyber Analyst
Dallas, TX, US, 75219 Tulsa, OK, US, 74107 Artesia, NM, US, 88210 El Dorado, KS, US, 67042
Basic Function
HF Sinclair is seeking for a OT Cyber Analyst in the following locations Dallas,TX, Arestia,NM, El Dorado, KS ,Tulsa,OK, Casper,WY, Sinclair, WY, Salt Lake City, UT, Woods Cross, or Anacortes, WA .The OT Cybersecurity Analyst serves as a fleet-wide Operational Technology (OT) cybersecurity specialist responsible for strengthening the security, visibility, and resilience of Industrial Automation and Control Systems (IACS) across HF Sinclair sites. The position applies specialized depth and breadth of OT cybersecurity expertise to independently interpret security telemetry, threat and vulnerability information, control gaps, and operational risk; recommend and drive improvements to monitoring, incident response, vulnerability management, asset visibility, secure access, and ISA/IEC 62443-aligned practices; and provide expert guidance to site and enterprise stakeholders. The role leads complex cross-functional cybersecurity workstreams and projects of moderate risk, resource requirements, and complexity, exercises independent judgment within established governance, and drives measurable fleet-wide risk reduction and continuous improvement in coordination with the OT Infrastructure & Cybersecurity Lead, OT System & Infrastructure Specialist, regional support teams, site OT teams, IT, vendors, and business stakeholders.
Job Duties
- Own and oversee OT cybersecurity monitoring and telemetry health across fleet environments, including SIEM, Syslog, endpoint protection, security dashboards, and approved monitoring platforms.
- Serve as the primary liaison with the 24/7 SOC team to review, investigate, correlate, and escalate OT cybersecurity alerts, suspicious activity, authentication anomalies, remote access events, and policy violations.
- Lead and support OT cybersecurity incident response activities, including investigations, root cause analysis, risk assessments, containment planning, recovery efforts, and corrective actions.
- Develop, maintain, and enhance OT security monitoring use cases, alerting, dashboards, reporting, detection logic, and escalation procedures.
- Identify and resolve gaps in OT asset visibility, monitoring coverage, vulnerability management, and asset inventory systems to improve fleet-wide security posture.
- Lead vulnerability management efforts by reviewing findings, assessing operational risk, prioritizing remediation activities, tracking corrective actions, and reporting results.
- Analyze threat intelligence, security advisories, patches, and vendor notifications to assess operational impact and recommend appropriate mitigation strategies.
- Develop and report cybersecurity metrics related to monitoring coverage, endpoint protection, vulnerability management, asset inventory, and overall fleet visibility.
- Support cybersecurity audits, compliance initiatives, risk assessments, and regulatory readiness activities by validating controls, reviewing evidence, and driving corrective actions.
- Serve as a subject matter expert on OT cybersecurity best practices, including asset visibility, security monitoring, incident response, vulnerability management, and risk management.
- Evaluate vendor risk, third-party connectivity, and secure remote access practices, recommending risk-based controls and improvements.
- Maintain governance of OT asset inventories, network documentation, system records, and cybersecurity documentation to ensure accuracy and enterprise visibility.
- Partner with OT, operations, maintenance, IT, cybersecurity, and vendor stakeholders to improve cybersecurity controls, monitoring effectiveness, and asset visibility across fleet locations.
- Lead cybersecurity projects and workstreams, coordinating stakeholders, managing risks, and delivering operational and cybersecurity objectives.
- Provide technical guidance, mentoring, and cybersecurity expertise to site and enterprise teams while translating emerging threats and vulnerabilities into actionable improvements.
Special assignments or tasks assigned to the employee by their supervisor, as determined from time to time in their sole and complete discretion.
Experience
- At least 5 years of progressively responsible experience in cybersecurity, OT security, IT security operations, systems or network administration, industrial control systems, or equivalent technical disciplines, with demonstrated ownership of complex security activities or programs.
- Demonstrated specialized knowledge of Operational Technology, Industrial Automation and Control Systems (IACS), distributed control systems, PLC/SCADA environments, industrial networks, and refinery/process control environments, with the ability to assess cybersecurity risk in the context of safety, reliability, and operations.
- Advanced hands-on experience with security telemetry and operational security tools such as Syslog collection, SIEM, endpoint protection, vulnerability management, asset visibility, dashboards, ticketing, and reporting, including the ability to improve tool coverage, data quality, detections, and operational use.
- Experience owning or materially improving enterprise or fleet-wide asset inventories, endpoint coverage, logging coverage, configuration records, vulnerability visibility, or cybersecurity monitoring capabilities in OT, industrial, or complex infrastructure environments.
- Applied knowledge of ISA/IEC 62443 principles, especially asset inventory, zones and conduits, security monitoring, incident response, vulnerability management, risk management, secure access, and secure operation of IACS environments; experience translating framework requirements into practical controls and processes preferred.
- Demonstrated ability to interpret internal and external cybersecurity challenges, develop risk-based recommendations, and communicate complex technical findings, remediation options, operational impacts, and business risk to technical teams, site leadership, and enterprise stakeholders.
- Experience leading or coordinating audits, compliance activities, risk assessments, control testing, evidence validation, corrective action programs, or other governance activities across multiple stakeholders or locations preferred.
- Demonstrated ability to make independent, risk-based decisions within established governance, work calmly under pressure, prioritize competing cybersecurity and operational demands, and escalate material risks appropriately.
- Proven ability to lead cross-functional teams or projects through influence rather than direct authority, including work with moderate resource requirements, risk, dependencies, and/or complexity.
- Possesses strong written and verbal communication skills, sound judgment, integrity, accountability, analytical thinking, and a continuous-improvement mindset; demonstrates the ability to provide expert guidance and thought leadership within the OT cybersecurity discipline.
Education Level
A minimum of a bachelor’s degree in cybersecurity, computer science, information assurance, management information systems, engineering technology, industrial technology, or related field is preferred. Equivalent cybersecurity, OT, military, technical, or industrial experience may be considered in lieu of degree requirements.
Required Skills
- 5+ years of progressively responsible cybersecurity, security operations, OT support, industrial control systems, or infrastructure experience, including demonstrated ownership of complex cybersecurity work.
- ISA/IEC 62443 Cybersecurity Fundamentals, Security+, SSCP, GICSP, CySA+, GIAC, Microsoft, endpoint protection, SIEM, vulnerability management, or comparable OT/cybersecurity certifications are a plus.
- Advanced proficiency with security telemetry and monitoring capabilities for Syslog, SIEM, endpoint protection, vulnerability management, asset visibility, dashboards, metrics, and reporting, including the ability to diagnose coverage gaps and recommend or implement improvements.
- Strong applied knowledge of OT cybersecurity concepts including alert triage and correlation, log analysis, incident response, vulnerability and patch risk prioritization, secure remote access, third-party risk, asset visibility, ISA/IEC 62443 principles, compliance controls, and compensating safeguards.
- Ability to independently interpret complex technical and business challenges, exercise expert judgment, and develop risk-based recommendations that improve OT cybersecurity processes, controls, services, and measurable business outcomes.
- Ability to lead cross-functional cybersecurity projects and functional workstreams with moderate resource requirements, risk, and/or complexity; influence stakeholders, establish priorities, coordinate dependencies, and drive decisions without direct supervisory authority.
- Ability to serve as a subject matter expert and escalation resource, communicate effectively with technical and non-technical leaders, mentor less-experienced personnel, and promote consistent fleet-wide OT cybersecurity practices.
- Ability to support fleet-wide sites with up to 40% travel by land or air.
Supervisory/Managerial Responsibility
Work Conditions
Benefits
- Medical Insurance
- Vision Insurance
- Dental Insurance
- Paid Time-Off
- 401(k) Retirement Plan with match
- Educational Reimbursement
- Parental Bonding Time
- Employee Discounts
Physical Requirements
Our One HF Sinclair Culture:
About HF Sinclair Corporation
Equal Opportunity Employer
HF Sinclair Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other prohibited ground of discrimination.
Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth