- Location
- Midland - HQ, United States of America
- Department
- Engineering
- Experience
- 5+ years
- Education
- Master
- Source
- Workday
Description
Job Description:
Under general direction, the Cybersecurity Engineer designs, implements, and maintains the enterprise security controls that protect Permian Resources’ information systems, data, and cloud environments. The role centers on identity and access management (IAM), incident response, vulnerability management, and endpoint/extended detection and response (EDR/XDR), along with security architecture and policy across the corporate IT environment.
About the Role
Permian Resources (NYSE: PR) is a leading independent oil and natural gas company focused on the responsible acquisition, optimization, and development of high-return properties in the core of the Delaware Basin and we are seeking a Cybersecurity Engineer to join our Enterprise Cybersecurity Team in Midland, Texas. In this role, you will help protect the systems, data, users, and cloud environments that power one of the most active operators in the Permian Basin. You will play a critical role in designing, implementing, and maintaining our security infrastructure with a focus on identity and access management, incident response, vulnerability management, and detection and response as well as developing and enforcing security policies and procedures. The ideal candidate has a strong understanding of security principles, threat analysis, and incident response, and works effectively on a multi-disciplinary team in a fast-paced environment. Experience securing operational technology (OT) environments is a plus and offers room to grow as our program matures.
General Responsibilities
Administer and mature identity and access management (IAM) services, including single sign-on (SSO), multi-factor authentication (MFA), conditional access, role-based access control (RBAC), and privileged access management (PAM).
Lead incident response efforts in detection, containment, eradication, and recovery. Drive post-incident reviews and lessons learned.
Operate the vulnerability management program — scanning, risk-based prioritization, and remediation tracking and partnering with IT teams to drive timely patching.
Deploy, tune, and operate endpoint and extended detection and response (EDR/XDR) and SIEM tooling to detect and respond to threats across the environment.
Design and implement security solutions, including firewalls, intrusion detection/prevention systems, data loss prevention (DLP), and cloud security controls.
Develop and maintain security policies, procedures, and standards to ensure the confidentiality, integrity, and availability of company data.
Conduct threat analysis and vulnerability assessments to identify and mitigate potential security risks.
Collaborate with other IT teams to ensure security is integrated into all aspects of the infrastructure.
Research and evaluate new security technologies and provide security awareness training to employees.
Minimum Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
5+ years of experience in cybersecurity engineering or a related role.
Hands-on experience with identity and access management (IAM), including SSO, MFA, conditional access, RBAC, and privileged access management (PAM).
Demonstrated experience leading incident response, including containment, eradication, and recovery.
Experience operating a vulnerability management program — scanning, risk-based prioritization, and remediation.
Experience deploying and operating endpoint and extended detection and response (EDR/XDR) and/or SIEM platforms.
Experience with security policy and procedure development, and a proven ability to design and implement security solutions.
Strong understanding of threat analysis and mitigation techniques.
Familiarity with industry standards such as NIST CSF.
Additional technical expertise in one or more of the following: Firewall Management, Web Application Firewall (WAF), Data Loss Prevention (DLP), and Cloud Security (e.g., Azure, AWS, GCP).
Excellent communication and interpersonal skills, with strong analytical and problem-solving skills.
Preferred Qualifications
Cybersecurity work experience in OT/Industrial Control Systems (SCADA) environments, especially in oil & gas, energy, or another critical-infrastructure sector.
Familiarity with energy-sector and ICS security guidance, such as NIST SP 800-82, API 1164, and TSA pipeline/security directives.
Relevant certifications such as CISSP, Microsoft SC-series (e.g., SC-200, SC-300), or Security+; and, for OT, GICSP or GCIP.
Permian Resource is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.