OT Cyber Analyst

HF SinclairTulsa, OK
Hybrid

About The Position

HF Sinclair is seeking an OT Cyber Analyst to serve as a fleet-wide Operational Technology (OT) cybersecurity specialist. This role is responsible for strengthening the security, visibility, and resilience of Industrial Automation and Control Systems (IACS) across HF Sinclair sites. The position requires specialized depth and breadth of OT cybersecurity expertise to interpret security telemetry, threat and vulnerability information, control gaps, and operational risk. The analyst will recommend and drive improvements in monitoring, incident response, vulnerability management, asset visibility, secure access, and ISA/IEC 62443-aligned practices, while providing expert guidance to site and enterprise stakeholders. This role leads complex cross-functional cybersecurity workstreams and projects of moderate risk, resource requirements, and complexity, exercising independent judgment within established governance, and driving measurable fleet-wide risk reduction and continuous improvement in coordination with the OT Infrastructure & Cybersecurity Lead, OT System & Infrastructure Specialist, regional support teams, site OT teams, IT, vendors, and business stakeholders.

Requirements

  • At least 5 years of progressively responsible experience in cybersecurity, OT security, IT security operations, systems or network administration, industrial control systems, or equivalent technical disciplines, with demonstrated ownership of complex security activities or programs.
  • Demonstrated specialized knowledge of Operational Technology, Industrial Automation and Control Systems (IACS), distributed control systems, PLC/SCADA environments, industrial networks, and refinery/process control environments, with the ability to assess cybersecurity risk in the context of safety, reliability, and operations.
  • Advanced hands-on experience with security telemetry and operational security tools such as Syslog collection, SIEM, endpoint protection, vulnerability management, asset visibility, dashboards, ticketing, and reporting, including the ability to improve tool coverage, data quality, detections, and operational use.
  • Experience owning or materially improving enterprise or fleet-wide asset inventories, endpoint coverage, logging coverage, configuration records, vulnerability visibility, or cybersecurity monitoring capabilities in OT, industrial, or complex infrastructure environments.
  • Applied knowledge of ISA/IEC 62443 principles, especially asset inventory, zones and conduits, security monitoring, incident response, vulnerability management, risk management, secure access, and secure operation of IACS environments; experience translating framework requirements into practical controls and processes preferred.
  • Demonstrated ability to interpret internal and external cybersecurity challenges, develop risk-based recommendations, and communicate complex technical findings, remediation options, operational impacts, and business risk to technical teams, site leadership, and enterprise stakeholders.
  • Experience leading or coordinating audits, compliance activities, risk assessments, control testing, evidence validation, corrective action programs, or other governance activities across multiple stakeholders or locations preferred.
  • Demonstrated ability to make independent, risk-based decisions within established governance, work calmly under pressure, prioritize competing cybersecurity and operational demands, and escalate material risks appropriately.
  • Proven ability to lead cross-functional teams or projects through influence rather than direct authority, including work with moderate resource requirements, risk, dependencies, and/or complexity.
  • Possesses strong written and verbal communication skills, sound judgment, integrity, accountability, analytical thinking, and a continuous-improvement mindset; demonstrates the ability to provide expert guidance and thought leadership within the OT cybersecurity discipline.
  • 5+ years of progressively responsible cybersecurity, security operations, OT support, industrial control systems, or infrastructure experience, including demonstrated ownership of complex cybersecurity work.
  • Advanced proficiency with security telemetry and monitoring capabilities for Syslog, SIEM, endpoint protection, vulnerability management, asset visibility, dashboards, metrics, and reporting, including the ability to diagnose coverage gaps and recommend or implement improvements.
  • Strong applied knowledge of OT cybersecurity concepts including alert triage and correlation, log analysis, incident response, vulnerability and patch risk prioritization, secure remote access, third-party risk, asset visibility, ISA/IEC 62443 principles, compliance controls, and compensating safeguards.
  • Ability to independently interpret complex technical and business challenges, exercise expert judgment, and develop risk-based recommendations that improve OT cybersecurity processes, controls, services, and measurable business outcomes.
  • Ability to lead cross-functional cybersecurity projects and functional workstreams with moderate resource requirements, risk, and/or complexity; influence stakeholders, establish priorities, coordinate dependencies, and drive decisions without direct supervisory authority.
  • Ability to serve as a subject matter expert and escalation resource, communicate effectively with technical and non-technical leaders, mentor less-experienced personnel, and promote consistent fleet-wide OT cybersecurity practices.
  • Ability to support fleet-wide sites with up to 40% travel by land or air.

Nice To Haves

  • ISA/IEC 62443 Cybersecurity Fundamentals, Security+, SSCP, GICSP, CySA+, GIAC, Microsoft, endpoint protection, SIEM, vulnerability management, or comparable OT/cybersecurity certifications are a plus.
  • Experience translating ISA/IEC 62443 framework requirements into practical controls and processes preferred.
  • Experience leading or coordinating audits, compliance activities, risk assessments, control testing, evidence validation, corrective action programs, or other governance activities across multiple stakeholders or locations preferred.

Responsibilities

  • Own and oversee OT cybersecurity monitoring and telemetry health across fleet environments, including SIEM, Syslog, endpoint protection, security dashboards, and approved monitoring platforms.
  • Serve as the primary liaison with the 24/7 SOC team to review, investigate, correlate, and escalate OT cybersecurity alerts, suspicious activity, authentication anomalies, remote access events, and policy violations.
  • Lead and support OT cybersecurity incident response activities, including investigations, root cause analysis, risk assessments, containment planning, recovery efforts, and corrective actions.
  • Develop, maintain, and enhance OT security monitoring use cases, alerting, dashboards, reporting, detection logic, and escalation procedures.
  • Identify and resolve gaps in OT asset visibility, monitoring coverage, vulnerability management, and asset inventory systems to improve fleet-wide security posture.
  • Lead vulnerability management efforts by reviewing findings, assessing operational risk, prioritizing remediation activities, tracking corrective actions, and reporting results.
  • Analyze threat intelligence, security advisories, patches, and vendor notifications to assess operational impact and recommend appropriate mitigation strategies.
  • Develop and report cybersecurity metrics related to monitoring coverage, endpoint protection, vulnerability management, asset inventory, and overall fleet visibility.
  • Support cybersecurity audits, compliance initiatives, risk assessments, and regulatory readiness activities by validating controls, reviewing evidence, and driving corrective actions.
  • Serve as a subject matter expert on OT cybersecurity best practices, including asset visibility, security monitoring, incident response, vulnerability management, and risk management.
  • Evaluate vendor risk, third-party connectivity, and secure remote access practices, recommending risk-based controls and improvements.
  • Maintain governance of OT asset inventories, network documentation, system records, and cybersecurity documentation to ensure accuracy and enterprise visibility.
  • Partner with OT, operations, maintenance, IT, cybersecurity, and vendor stakeholders to improve cybersecurity controls, monitoring effectiveness, and asset visibility across fleet locations.
  • Lead cybersecurity projects and workstreams, coordinating stakeholders, managing risks, and delivering operational and cybersecurity objectives.
  • Provide technical guidance, mentoring, and cybersecurity expertise to site and enterprise teams while translating emerging threats and vulnerabilities into actionable improvements.
  • Special assignments or tasks assigned to the employee by their supervisor, as determined from time to time in their sole and complete discretion.

Benefits

  • Medical Insurance
  • Vision Insurance
  • Dental Insurance
  • Paid Time-Off
  • 401(k) Retirement Plan with match
  • Educational Reimbursement
  • Parental Bonding Time
  • Employee Discounts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service