Cyber Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
The Cyber Security Analyst plays a critical role in protecting LSB Industries’ digital and operational environments across our manufacturing facilities and corporate network. This role safeguards critical IT and OT systems, strengthens the company’s overall security posture through proactive monitoring and incident response, and serves as a driving force behind audit readiness - spearheading cybersecurity and IT general controls audits and acting as the primary liaison to third-party assessors. The successful candidate will also own the configuration, deployment, and continuous improvement of the company’s security awareness training program, helping build a resilient, security-conscious workforce across all sites., * Serve as the primary point of contact for third-party assessors and external auditors - spearheading cybersecurity, IT general controls (ITGC), and framework-based audits from planning through evidence delivery and remediation closure.
- Lead evidence collection, control walkthroughs, and remediation tracking to maintain continuous compliance with SOX, ISO, NIST, and ISA/IEC 62443 requirements.
- Develop and maintain audit-ready cybersecurity documentation, including policies, playbooks, control matrices, and standard operating procedures.
- Configure, deploy, and administer the enterprise security awareness training platform, including role-based curricula, automated assignments, scheduling, and completion tracking.
- Design and execute phishing simulation campaigns, analyze results, and deliver targeted follow-up training to measurably reduce human risk across all sites.
- Monitor and analyze alerts from SIEM, EDR, and other security tools to detect and respond to threats across both IT and OT environments.
- Investigate and remediate security incidents, coordinating with IT and plant operations teams to minimize disruption to manufacturing systems.
- Support vulnerability management, including patch verification, remediation tracking, and risk-based prioritization.
- Conduct third-party and vendor risk assessments and verify that vendors meet LSB’s security standards.
- Support cybersecurity controls and network segmentation for plant networks, DCS, PLCs, and SCADA systems in partnership with OT and engineering teams.
- Evaluate and implement industrial cybersecurity best practices aligned to ISA/IEC 62443 and NIST 800-82.
- Assist in the secure integration of new industrial systems, sensors, and IoT technologies.
- Support tabletop exercises, penetration testing, and red/blue team drills.
- Identify gaps in cybersecurity controls and partner cross-functionally to improve processes, tooling, and audit traceability.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or an equivalent combination of education and experience.
- 5+ years of experience in cybersecurity, preferably in a manufacturing, industrial, or critical-infrastructure environment.
- Demonstrated experience spearheading or coordinating cybersecurity, ITGC, or compliance audits - including serving as the primary liaison to third-party assessors and external auditors and driving remediation to closure.
- Hands-on experience configuring and deploying security awareness training and phishing simulation programs.
- Solid understanding of network security principles, firewalls, intrusion detection/prevention, and endpoint protection.
- Experience supporting or participating in SOX, ITGC, or other compliance audits.
- Strong analytical skills and the ability to communicate complex issues clearly to both technical and business audiences.
- PREFERRED QUALIFICATIONS
- Knowledge of OT security (DCS, PLC, SCADA) and industrial protocols (Modbus, OPC, Ethernet/IP).
- Experience administering security awareness training platforms such as KnowBe4, Proofpoint Security Awareness, or Adaptive Security.
- Familiarity with ThreatLocker, Proofpoint, and other endpoint or email security tools.
- Experience with SIEM and EDR platforms such as Microsoft Sentinel, the Defender suite, CrowdStrike, or SentinelOne.
- Familiarity with NIST CSF, ISA/IEC 62443, and cybersecurity maturity assessments.
- Experience preparing for and supporting external assessments under SOX, SOC 2, or ISA/IEC 62443.
- CERTIFICATIONS
- Preferred: Security+, CySA+, or CISA (Certified Information Systems Auditor) - or an equivalent security or audit certification.
- A plus: GICSP, GIAC ICS/OT security certifications, or CISSP. Certifications are not required, but are strongly valued.
- KEY COMPETENCIES
- Audit-driven - experienced at leading assessments and translating third-party assessor requirements into actionable, tracked remediation.
- Collaborative communicator - works effectively across IT, Engineering, Audit, and plant operations teams.
- Process-driven - values documentation, repeatability, and audit traceability.
- Analytical and curious - proactive in identifying risks and investigating anomalies.
- Calm under pressure - responds effectively during security incidents and operational disruptions.
- WORK ENVIRONMENT & TRAVEL
- Hybrid office environment based out of LSB Industries’ corporate headquarters in Oklahoma City, with periodic travel to manufacturing facilities.
- Occasional work in plant environments requiring adherence to site safety protocols and personal protective equipment (PPE).
- Availability to support incident response outside of standard business hours as needed for a 24x7 manufacturing operation.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Now is the time for industrialized software development
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?