Jobs and Careers
MA

Cybersecurity Analyst, Third Party Risk

Marathon Petroleum Corporation
United Statesfull_timeVerifiedPosted 3 Oct 2025

About the role

An exciting career awaits you


At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

Position Summary

We are seeking a detail-oriented and analytical Cybersecurity Analyst – Third Party Risk to join our cybersecurity team. In this role, you will be responsible for assessing, monitoring, and managing cybersecurity risks associated with third-party vendors, partners, and service providers. You will play a critical role in protecting our organization’s data and systems by ensuring our external relationships meet our security standards and compliance requirements.

Key Responsibilities

  • Perform third-party cybersecurity risk assessments and due diligence for vendors by evaluating security controls through questionnaires, documentation reviews, and ratings tools; collaborate with procurement, legal, and business units to embed cybersecurity requirements into contracts and vendor selection processes.
  • Drive risk remediation and continuous improvement by tracking mitigation efforts, staying informed on emerging threats and regulatory changes, and applying insights to strengthen third-party risk management practices.
  • Conducts controls analysis of business process and systems and reports impact of changes and additions to security systems.
  • Assists with the resolution of routine multi-functional technical issues. Prepares, performs and presents cybersecurity assessments and associated risks.
  • Evaluates the efficiency and effectiveness of Security processes and controls in place ensuring confidentiality, integrity, and availability of data/ information, under guidance of more senior colleagues.
  • Recommends and/or executes remediation and develops cost information for such mitigation measures. Monitors networks, systems, and applications for signs of potential cybersecurity incidents. Investigates and analyzes the nature and scope of cyber incidents.
  • Analyzes security protocols, compliance reviews, administers and maintains security audits and reports of server access and activity; participates in disaster recovery planning per corporate guidelines.
  • Delivers and implements global security initiatives, policies, and compliance requirements. Works with IT and security engineers to produce metrics related to cybersecurity.
  • Takes action through collaboration to improve metric results. Executes cyber security-related consulting, guidance, and support to customers and stakeholders.
  • Effectively communicates emerging Information Technology/Operations Technology and cybersecurity technology trends as well as their impact on the security landscape.

Education and Experience

  • Bachelor’s Degree in Information Technology, related field or equivalent experience.
  • Professional certification, e.g. CISA, CRISC, CISSP, or CTPRP preferred.
  • 2+ years of relevant experience required
  • Experience in cybersecurity, risk management, or vendor risk assessment required.
  • Experience with third-party risk management platforms and tools (e.g., CyberGRX, BitSight) preferred.
  • Experience with cybersecurity risk frameworks (NIST CSF, NIST 800-53, and COBIT) preferred.
  • Experience reviewing and interpreting SOC 2 Type II reports, with the ability to assess control effectiveness, identify relevant findings, and evaluate vendor risk posture preferred.

Skills

Authentic Communicator -Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.

Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.

General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks.

Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.

Penetratio

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Marathon Petroleum Corporation

View company profile →