Cyber Security Associate

Summary

Entry-level cybersecurity role supporting day-to-day security operations at an upstream oil and gas company. Day-to-day work involves monitoring alerts, triaging incidents, tracking vulnerabilities, coordinating SIEM/logging, handling security service requests, and producing operational metrics and reports.

Crescent is a differentiated U.S. energy company committed to delivering value through a disciplined, returns-driven growth through acquisition strategy and consistent return of capital. Our long-life, balanced portfolio combines significant cash flow from stable production with a deep, high-quality development inventory. Crescent is a top three producer in the Eagle Ford basin and a scaled operator in each of the Permian and Uinta basins. Crescent’s leadership is an experienced team of investment, financial and industry professionals that combines proven investment and operating expertise. For more than a decade, Crescent and our predecessors have executed on a consistent strategy focused on cash flow, risk management and returns. Through disciplined and accretive investments, we have successfully tripled the size of our company since going public in December 2021 while maintaining a strong balance sheet.


The Cybersecurity Associate supports the day-to-day operations of the organization’s cybersecurity program through monitoring, triage, reporting, service request fulfillment, and security operations support. This role plays a key part in protecting the company’s digital assets by helping identify potential threats, supporting response activities, and ensuring security processes are consistently executed across enterprise systems and platforms.

This position supports security monitoring, incident triage, vulnerability tracking, logging and SIEM coordination, awareness activities, and operational reporting. The ideal candidate brings foundational cybersecurity knowledge, strong analytical skills, and a proactive mindset, with the ability to work across cybersecurity, infrastructure, applications, and business teams. This individual will contribute to improving cyber resilience, strengthening operational discipline, and supporting the company’s journey toward becoming a secure, technology-enabled, and data-driven enterprise.

Key Responsibilities:

Security Monitoring & Alert Validation

Monitor security alerts and events across approved security tools and platforms.

Review and validate potential threats, suspicious activity, and anomalous behavior for appropriate escalation.

Assist in identifying false positives, documenting findings, and improving alert handling processes.

Support continuous monitoring efforts to improve visibility into enterprise security events and risks.

Incident Triage & Response Support

Support incident triage, investigation, and response efforts in coordination with internal cybersecurity personnel and external partners.

Gather initial evidence, document findings, and help track response actions through closure.

Escalate confirmed or high-risk events in accordance with established procedures.

Assist with post-incident documentation, lessons learned, and follow-up remediation tracking.

Cybersecurity Service Request Management

Manage and respond to cybersecurity-related service requests in a timely and professional manner.

Coordinate with users, IT teams, and security stakeholders to fulfill access, policy, logging, and other security-related requests.

Track request status, document actions taken, and ensure proper closure and communication.

Identify recurring request patterns and suggest process improvements where appropriate.

Logging, SIEM & Security Operations Support

Support proper logging and SIEM integration across systems, platforms, and security tools.

Assist with onboarding log sources, validating data flow, and identifying visibility gaps.

Help maintain monitoring coverage by working with infrastructure, cloud, application, and security teams.

Support security operations processes that strengthen detection, investigation, and response capabilities.

Vulnerability Tracking & Reporting

Track vulnerability remediation efforts across systems and teams to support timely risk reduction.

Assist with compiling remediation status, follow-ups, and exception tracking.

Support reporting on vulnerabilities, open risks, and remediation progress for cybersecurity leadership.

Help coordinate with technical owners to ensure remediation actions are documented and visible.

Security Awareness & Training Support

Deliver security awareness and training support through coordination, communication, and follow-up activities.

Assist in preparing awareness content, phishing campaign support, and user education materials.

Promote cybersecurity best practices and reinforce awareness of common threats and secure behaviors.

Support ongoing efforts to strengthen the organization’s security culture.

Metrics, Reporting & Threat Awareness

Generate security metrics, dashboards, and trend reports to support operational visibility and leadership reporting.

Help analyze trends in alerts, incidents, vulnerabilities, and service requests to identify improvement opportunities.

Stay informed on emerging threats, techniques, and cyber risks, and apply relevant insights to day-to-day operations.

Support documentation and reporting that improves program maturity, consistency, and accountability.

Qualifications & Experience:

Education:

Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field preferred.

Equivalent practical experience will be considered.

Relevant certifications such as Security+, Network+, SC-900, or other entry-level cybersecurity certifications are a plus.

Experience:

1–3 years of experience in cybersecurity, IT support, security operations, or related technical roles preferred.

Exposure to security monitoring, incident response, vulnerability management, or SIEM platforms is preferred.

Experience working with ticketing systems, reporting tools, and operational dashboards is a plus.

Familiarity with cybersecurity concepts such as phishing, malware, identity security, logging, and vulnerability remediation is preferred.

Upstream oil and gas experience is strongly preferred.

Skills & Competencies:

Foundational understanding of cybersecurity operations, threat monitoring, incident triage, and risk reduction practices.

Strong attention to detail and ability to document findings, actions, and trends accurately.

Analytical mindset with the ability to investigate alerts, organize information, and support decision-making.

Ability to manage multiple priorities and follow established processes in a fast-paced environment.

Strong collaboration skills with the ability to work across cybersecurity, infrastructure, applications, and business teams.

Clear communication skills with the ability to explain issues, requests, and findings in a professional and understandable manner.


Crescent Energy is an equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, gender/pregnancy, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status or any other legally protected status. Crescent Energy is also committed to compliance with all fair employment practices regarding citizenship and immigration status. If you require accommodation to complete the application process, please let us know by contacting [email protected].

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available