Enterprise Cybersecurity Architect
Dallas, IA - USA
Job Summary
Enterprise Cybersecurity Architecture Strategy and Standards
- Define maintain and improve cybersecurity architecture principles standards guardrails patterns and reference architectures.
- Establish reusable architecture patterns that enable secure-by-design delivery reduce inconsistent solution decisions limit architectural drift and address avoidable control gaps.
- Use the enterprise cybersecurity taxonomy to organize architecture decisions standards roadmaps risks controls metrics and capability maturity discussions.
Security Architecture Governance and Design Reviews
- Lead or facilitate security architecture reviews for major technology initiatives cyber portfolio projects OT modernization cloud solutions application modernization identity patterns data platforms integrations automation and AI-enabled capabilities.
- Identify architecture risks design gaps control weaknesses and standards deviations; document tradeoffs recommendations decisions and residual risk implications.
- Define architecture dependencies design constraints runway needs standards readiness and risk reduction outcomes for major IT and cyber initiatives.
Cyber Risk Control and Capability Traceability
- Support risk register accuracy by mapping technology and architecture risks to affected capabilities root-cause design gaps maturity gaps and practical mitigation approaches.
- Advise on architecture implications of policy exceptions control gaps risk acceptances third-party dependencies and emerging technology adoption decisions.
Technology Domain Architecture Guidance
- Guide security architecture for IT/OT convergence industrial digital platforms cyber-physical systems network segmentation secure remote access monitoring identity data exchange cloud SaaS application API automation and AI-enabled solutions.
- Evaluate emerging technologies and industry trends for applicability risk architecture impact control requirements and adoption guardrails.
Stakeholder Partnership and Continuous Improvement
- Influence strategic initiatives by explaining architecture options risk tradeoffs design implications and recommended paths forward.
- Facilitate alignment where ownership is shared or ambiguous by clarifying architecture boundaries decision rights and execution expectations.
- Support continuous improvement of architecture governance standards adoption exception management security design quality and measurable security outcomes.
Special assignments or tasks may be assigned to the employee by their supervisor as determined from timeto time in the supervisors sole and complete discretion.
A minimum of 8 years of experience in IT infrastructure cybersecurity cloud security security engineering enterprise architecture solution architecture OT security or related technology domains.
- Minimum of 4 years of experience in an architecture function including development of standards reference architectures design patterns architecture governance or technology roadmaps.
- Demonstrated experience translating business risk regulatory and technical requirements into practical security architecture guidance.
- Demonstrated ability to operate as a senior technical advisor across multiple teams domains and levels of leadership.
- Experience leading architecture reviews producing architecture decision records documenting design tradeoffs and influencing risk-informed discussions across technical and business stakeholders.
- Experience working across multiple technology domains including some combination of identity network cloud endpoint data application SaaS infrastructure integrations OT or cyber-physical systems.
- Experience supporting cyber risk reduction control alignment maturity improvement or security roadmap development.
A bachelors degree in Information Technology Information Security Cybersecurity Computer Science Engineering or a related field is required. Equivalent experience may be considered in lieu of a degree.
Preferred Educational Level:
Masters degree in Information Technology Cybersecurity Information Security Engineering Business Administration or a related field.
- Enterprise security architecture and secure-by-design principles.
- Architecture frameworks and methods such as TOGAF SABSA DoDAF NIST C2M2 SAFe for Architects or similar approaches.
- Architecture governance methods including standards management design review facilitation architecture decision records and architecture review forums.
- Systems thinking and ability to analyze complex cross-domain dependencies.
- Cyber risk analysis control alignment maturity assessment and risk-informed roadmap development.
- Ability to translate strategy risk and control requirements into practical architecture standards and engineering-ready guardrails.
- Security architecture concepts across IT OT cyber-physical systems cloud SaaS application API data identity network monitoring automation and resilience domains.
- Strong communication facilitation stakeholder management and executive-facing presentation skills.
- Continuous improvement mindset with ability to establish reusable patterns feedback loops and measurable outcomes.
Preferred Skills:
- Oil and gas critical infrastructure industrial cybersecurity or OT security architecture experience.
- Experience with NIST CSF C2M2 CIS ISO 27001 NERC CIP TSA security directives or other cybersecurity and regulatory frameworks.
- Experience aligning security architecture to enterprise cyber taxonomies capability models maturity models control libraries or unified controls frameworks.
- Experience supporting cyber portfolio planning investment prioritization roadmap development OKRs KPIs KRIs or value/risk-based planning.
- Experience with security architecture for AI analytics automation machine identities APIs data platforms cloud-native architectures and SaaS ecosystems.
- Familiarity with SSE/SASE Zero Trust cyber-physical systems and digital transformation security patterns.
- Relevant certifications such as CISSP CCSP SABSA TOGAF GIAC ISA/IEC 62443 cloud security or similar credentials.
This role has no direct supervisory responsibilities but is expected to provide senior technical leadership architecture direction mentoring and cross-functional influence across cybersecurity IT and OT.
Office-based with up to 20% travel by land or air is required. Subject to all weather and varying road conditions.
- Medical Insurance
- Vision Insurance
- Dental Insurance
- Paid Time-Off
- 401(k) Retirement Plan with match
- Educational Reimbursement
- Parental Bonding Time
- Employee Discounts
HF Sinclair Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age disability veteran status or any other prohibited ground of discrimination.
Required Experience:
Staff IC
About Company
An independent petroleum refiner in the United States with operations throughout the mid-continent, southwestern and Rocky Mountain regions. Subsidiaries of HollyFrontier produce and market gasoline, diesel, jet fuel, asphalt, heavy products and specialty lubricant products. Additiona ... View more