Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Marathon Petroleum

Confirmed live today High trust

Quick summary

Work type
On-site
Location
San Antonio, TXHouston, TXFindlay, OH
Employment
Full-time
Posted
17 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $175k
$121k most similar roles pay here $218k

This listing doesn't post a salary. Most similar roles pay $147,000–$203,500.

Based on 240 similar postings.

Employer

About Marathon Petroleum

Marathon Petroleum Corporation is one of the largest petroleum refining, marketing, retail, and transportation companies in the United States, operating an extensive refining network and Speedway convenience stores. Industry: Oil Refining & Energy

Marathon Petroleum currently has 13 open roles on FindRole.

Most-posted roles

View all roles at Marathon Petroleum

At a glance

TL;DR · Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring serves as the technical focal for GRC automation to reduce audit friction and improve risk visibility. Working within a team involving Cyber Fusion and Enterprise Architecture, you will develop automated evidence collection, control testing, and AI-enabled governance capabilities across cloud, on-premises, identity, and operational technology platforms. You will build deterministic control-testing logic and LLM-backed workflows for tasks like drift detection and audit-package assembly. The role requires proficiency in Python, REST API integrations, and experience with tools such as CNAPP, CSPM, SIEM, XDR, and ITSM. You will manage security controls, conduct threat analysis, and perform vulnerability management to ensure compliance across various systems. Key technical requirements include integrating security-control data into evidence pipelines and utilizing frameworks like NIST AI RMF or OWASP LLM Top 10.

What you'll do

  • Develop automated evidence collection, control testing, and risk intelligence capabilities across cloud and on-premises platforms.
  • Build AI-enabled governance workflows using LLMs for tasks like evidence mapping, drafting attestations, and detecting drift.
  • Design and implement deterministic control-testing logic to reduce audit friction and improve risk visibility.
  • Integrate security-control data sources into a GRC pipeline by normalizing API, telemetry, and configuration data.
  • Develop Python-based automated workflows and REST API integrations across multiple enterprise systems.
  • Analyze business-impacting events and conduct investigations into cyber incidents and control failures.
  • Create and maintain Standard Operating Procedures (SOPs) for security governance and compliance processes.
  • Translate security principles into actionable requirements for configuration teams to ensure compliant builds.

What we're looking for

  • Bachelor's Degree in Information Technology, a related field, or equivalent experience.
  • Professional certifications such as Security+, Network+, OSCP, GIAC, or CEH (preferred).
  • 5+ years of relevant experience required.
  • Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required.
  • Proficiency in Python or comparable technologies for developing automated workflows and REST API-based data integrations across enterprise systems required.
  • Hands-on experience integrating security-control data sources into a GRC/CCM evidence pipeline for continuous control testing required.
  • Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks (preferred).
  • Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks (preferred).

More like this

Similar roles

Security Engineer, GRC

Plaid

San Francisco, CA +2 80 days ago $156,000–$213,600
Python SQL AWS Terraform CI/CD OPA Rego Sentinel Policy-as-Code OpenAI Claude SOC 2 ISO 27001 NIST CSF FedRAMP Mode GitHub API

Cybersecurity Engineer

Booz Allen Hamilton

Annapolis Junction, MD +1 5 days ago $86,900–$198,000
CMMC NIST 800-171 FedRAMP REST APIs Git Jira ServiceNow Terraform CloudFormation CDK Policy-as-Code OPA AWS Cybersecurity Compliance Secrets Management

Cybersecurity Engineer

Booz Allen Hamilton

Charleston, SC 46 days ago $69,400–$158,000
Cybersecurity Network Security Vulnerability Assessment Big Data Analytics Information Assurance Security+ Event Correlation Cyber Defense IAM IAT IASAE
10+ yrs exp

Cybersecurity Engineer

Visa

Austin, TX 157 days ago $123,700–$191,300
AWS Azure GCP Kubernetes Terraform CloudFormation ARM CI/CD IAM mTLS KMS HSM CSPM OAuth OIDC SAST SCA SBOM PCI DSS ISO 27001 SOC 2 GDPR NIST Anthropic Claude OpenAI ChatGPT
2+ yrs exp Hybrid

Lead Cybersecurity Engineer

Visa

Foster City, CA 38 days ago $200,000–$320,000
Python Go Azure AWS Terraform GenAI LLM GitOps Infrastructure‑as‑Code policy‑as‑code CSPM CNAPP Wiz Prisma Cloud Microsoft Defender for Cloud Sumo Logic ADX API‑driven architecture
10+ yrs exp Hybrid

Senior Cybersecurity Engineer

General Dynamics

Springfield, VA 28 days ago $164,382–$209,420
RMF ATO AI Machine Learning ACAS Splunk HBSS eMASS Vulnerability Scanning Cyber Threat Intelligence STIGs Configuration Management Patch Management SIEM SOAR ITILv4 AWS Linux
10+ yrs exp