Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Senior
Agent
Ai Security
Aspm
Cloud Native Application Protection Platform
Cloud Platforms
Cloud Security Posture Management
Continuous Control Monitoring
Cybersecurity Tools
Data Security
Dspm
Endpoint Security
Engineer
Facilities Management
Grc Automation
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
It Service Management
IT Services
Management
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Job Description
Join Marathon Petroleum as a Senior Cybersecurity Engineer focused on GRC automation and continuous control monitoring. This onsite role in San Antonio, TX turns governance into an operational “trust engine” by building automated evidence collection, control testing, risk intelligence, and AI-enabled governance across cloud, on-premises, identity, OT, and security platforms.
What you’ll work on
- Analyze changes to cybersecurity solutions and how they affect internal and external systems to assess control effectiveness and cybersecurity risk, resolving complex multi-functional technical issues.
- Apply cybersecurity assessments, standards, control testing methods, and compliance frameworks to help ensure compliance across security systems.
- Improve the efficiency and effectiveness of security solutions, governance processes, automated controls, and monitoring capabilities.
- Review existing processes and procedures, then lead improvement, automation opportunities, and remediation efforts.
- Develop and submit Standard Operating Procedures.
- Perform initial investigation of business-impacting events and evaluate control performance, exceptions, and risk indicators through continuous monitoring.
- Investigate and analyze the nature and scope of cyber incidents, control failures, and compliance exceptions, then support risk mitigation and remediation planning to meet regulatory and internal compliance needs.
- Lead implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices, including collecting, validating, and reporting security metrics, control performance results, and remediation progress.
- Provide cyber security-related consulting, guidance, and support to customers and stakeholders.
- Translate security principles to assist configuration teams in incorporating security and compliance requirements into build and configuration processes.
- Track emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies and assess their impact on security, risk, and compliance.
Required experience
- Bachelor’s degree in Information Technology (or related field) or equivalent experience.
- 5+ years of relevant experience.
- Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions in a regulated environment.
- Experience with Python (or comparable automation technologies), including building, integrating, and supporting automated workflows and REST API-based data integrations across enterprise systems.
- Hands-on experience integrating security-control data sources into a GRC/CCM evidence pipeline for continuous control testing, including normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into audit-ready control-level evidence, exception logic, ownership, frequency, and records across at least three domains (examples provided: CNAPP/CSPM, SIEM/security data lake/XDR, CTEM/VM/ASPM, DSPM, ITSM, IAM, GRC/CCM, or AI/agent governance).
Preferred
- Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks.
- Familiarity with NIST AI RMF, OWASP LLM Top 10, or comparable AI risk frameworks.
Tools and technologies
Python, REST API, Azure AI Foundry, GitHub, NIST AI RMF, OWASP LLM Top 10, CNAPP, CSPM, SIEM, XDR, CTEM, VM, ASPM, DSPM, ITSM, IAM, AI/agent governance.
Benefits
- Health, vision, and dental insurance
- Paid time off
- 401k matching program
- Paid parental leave
- Educational reimbursement
- Discretionary company-sponsored annual bonus program
Additional minimum qualifications
Professional certification (examples: Security+, Network+, OSCP, GIAC, CEH) is preferred, in addition to the Bachelor’s degree and 5+ years of relevant experience.
Key skills
- Adaptability
- AI Fundamentals
- Change Management
- Authentic Communicator
- Cybersecurity Risk Management
- General Programming
- Intrusion Detection
- Penetration Testing
- Relationship Management
- Security Controls
- Security Governance
- Security Information & Event Management (SIEM)
- Security Policy Management
- Threat Analysis
- Threat Hunting
- Vulnerability Management