Cybersecurity Architect
Summary
The Cybersecurity Architect will manage and deploy security tools, lead incident response, and ensure compliance across IT and OT infrastructure. The role requires extensive experience in cybersecurity, specifically within the Microsoft ecosystem and industrial control systems.
Gulfport Energy Corporation is an Oklahoma City-based independent oil and natural gas exploration and production company with its principal properties located in the Utica Shale in Eastern Ohio, the SCOOP Woodford and SCOOP Springer plays in Central Oklahoma.
Gulfport aims to create sustainable value through the economic development of our significant resource plays in the Utica and SCOOP operating areas. Our strategy is to develop our assets in an environmentally responsible manner, while generating sustainable cash flow, improving margins and operating efficiencies and returning capital to shareholders. To accomplish these goals, we allocate capital expenditures to projects we believe offer the highest rate of return and we deploy leading drilling and completion techniques and technologies in our development efforts.
Title:
Cybersecurity ArchitectFull-Time/Part-Time:
Full timeFLSA:
United States of America (Exempt)Description:
JOB SUMMARY:
The Cybersecurity Architect will protect and enhance the company’s critical IT and OT infrastructure. This advisor-level position will be responsible for managing and deploying security tools, leading incident response efforts, conducting vulnerability assessments, and ensuring compliance with industry standards. This position will also involve managing third-party relationships and fostering a culture of cybersecurity awareness across the organization.
PRIMARY RESPONSIBILITIES:
- Security Tool Management: Deploy and maintain cybersecurity tools such as Palo Alto, Okta, Dragos, Extrahop, SentinelOne, Google SecOps, Proofpoint, Secret Server, and Abnormal Security.
- Microsoft Ecosystem Security: Advanced experience securing the Microsoft environment, including O365, Azure/Entra, Active Directory, Exchange, and related services. Ensuring identity management, securing cloud environments, and protecting the broader Microsoft ecosystem from threats.
- Incident Response: Lead security incident response, leveraging tools like SentinelOne, Huntruess, and Google SecOps to detect, analyze, and mitigate threats.
- Vulnerability and Risk Management: Perform vulnerability assessments, manage risk, and ensure timely patching of systems across IT and OT environments. Have a working knowledge of Tenable technology.
- Compliance: Ensure compliance with industry standards such as NIST, CIS, and relevant regulations.
- Third-Party Relationships: Manage relationships with MSSPs, consultants, and security vendors to maintain security posture.
- Security Awareness: Conduct training and awareness programs to enhance staff understanding of security best practices and emerging threats.
- Other duties and responsibilities as assigned by management.
KNOWLEDGE, SKILLS, ABILITIES:
- Scripting and Automation: Proficiency in Python and PowerShell to automate security tasks and integrate security tools into workflows.
- Technical Expertise: Experience with cybersecurity tools for network security, endpoint protection, vulnerability management, and threat detection.
- Incident Response and Detection: Experience monitoring, detecting, and responding to security incidents across IT and OT environments.
- Vulnerability Management: Skilled in conducting vulnerability assessments, prioritizing risks, and managing remediation.
- OT Security Expertise: Experience securing and architecting OT security environments (ICS, SCADA, PLCs) and securing protocols like Modbus, DNP3, and OPC. Familiarity with Dragos for threat detection.
REQUIRED EDUCATION/QUALIFICATIONS:
- Education: Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field.
- Experience: 12+ years in cybersecurity, with at least 5 years in a hands-on technical role, preferably within the oil and gas sector.
- Certifications: CISSP, CISM, CISA, CCNA, or equivalent.
- Knowledge: Strong understanding of cybersecurity frameworks, risk management, and compliance regulations (NIST, CIS).
- Analytical Skills: Strong troubleshooting and problem-solving abilities.
PREFERRED EDUCATION/QUALIFICATIONS:
- Advanced Degrees: Master’s degree in Cybersecurity or related field.
- ONG-ISAC: Experience with the Oil and Natural Gas ISAC for threat intelligence sharing.
- Project Management: Experience in managing security projects and cross-functional teams.
PHYSICAL DEMANDS:
Ability to lift files, open filing cabinets, and bend or stand as necessary. Ability to sit and/or stand for long periods of time. The ability to use a computer, tablet or smart phone for extended periods of time. Basic use of standard office equipment. Ability to lift up to 10 pounds occasionally
POSITION TYPE AND EXPECTED HOURS OF WORK:
This is a full-time exempt position. Days and hours of work will vary due to workload and needs of the company.
TRAVEL:
Minimal travel is expected for this position.
Equal Opportunity Employer:
This description is intended to describe the type of work being performed by a person assigned to this position. It is not an exhaustive list of all duties and responsibilities required by the employee.
Gulfport Energy is an Equal Opportunity Employer and is committed to the principles of equal employment opportunity for all employees and applicants for employment. Gulfport also provides reasonable accommodations to qualified individuals with disabilities, except where such an accommodation would cause an undue hardship.