Apply Now

You will be taken to jobs.valvolineglobal.com to complete your application.

At Valvoline Global Operations, we're proud to be The Original Motor Oil, but we've never rested on being first. Founded in 1866, we introduced the world's first branded motor oil, staking our claim as a pioneer in the automotive and industrial solutions industry. Today, as an affiliate of Aramco, one of the world's largest integrated energy and chemicals companies, we are driven by innovation and committed to creating sustainable solutions for a better future.

The Senior Information Security Engineer is an advanced technical authority responsible for designing, governing, and continuously improving enterprise cybersecurity capabilities. The role owns complex security engineering outcomes across assigned domains and operates with substantial independence in translating business and cyber risk into practical technical decisions.

Job Accountabilities

  • Own the design and technical direction of complex cybersecurity engineering solutions across assigned domains. Define target-state capabilities, reference architectures, engineering standards, and lifecycle plans that align with enterprise security strategy and business risk.
  • Lead cross-functional delivery of major security technology implementations and integrations. Establish technical approach, manage dependencies and risks, direct testing and operational readiness, and ensure solutions are adopted, documented, and transitioned successfully into service.
  • Provide lifecycle and operational ownership for critical cybersecurity platforms and controls. Set configuration and service-quality standards, evaluate performance and coverage, drive continuous improvement, and ensure capabilities remain effective as threats, technologies, and business requirements change.
  • Serve as the final technical escalation point for complex security engineering problems, high-priority incidents, and control deficiencies. Apply expert analysis, coordinate response across teams and vendors, make risk-based recommendations, and communicate status and resolution options to leadership.
  • Lead security reviews and risk assessments for new or materially changed systems, services, and technology solutions. Identify control gaps, recommend proportionate mitigations, and influence architecture and delivery decisions in partnership with GRC, IT, and business owners.
  • Provide technical leadership and mentorship to Information Security Engineering team members. Review designs and deliverables, establish reusable practices, coach engineers through complex work, build the capability required for succession into Lead-level responsibilities, and research emerging threats and technologies to inform the cybersecurity roadmap, investment cases, metrics, and executive communications.
  • Regularly influences Information Security and IT leadership and partners with GRC, enterprise architecture, infrastructure, application teams, business owners, procurement, and third-party providers. The role must explain complex technical and risk topics to both technical and non-technical stakeholders, build alignment across competing priorities, and represent cybersecurity engineering in cross-functional governance and project forums.

Job Qualifications / Education / Skills / Requirements / Capabilities

  • Bachelor's degree in information systems, computer science, engineering, cybersecurity, or a related field, or equivalent combination of education and experience. Advanced degree (nice to have)
  • 8+ years of progressive experience in information technology or information security, including significant experience in security engineering, cloud security, security architecture, security operations, incident response, or related disciplines. Demonstrated experience leading complex, enterprise-impacting initiatives is required.
  • CISSP, CISM, CCSP, GIAC, or equivalent industry certification preferred. Relevant cloud, network, identity, platform, or vendor-specific certifications are also valued.

Competencies Desired

  • Enterprise security engineering: ability to translate cyber risk, business requirements, and threat intelligence into scalable architectures, controls, standards, and roadmaps.
  • Technical authority: advanced knowledge of security platforms, cloud controls, identity and access management, network security, detection and response, vulnerability management, and secure technology integration.
  • Risk-based judgment: ability to assess control effectiveness, prioritize remediation, balance security with operational needs, and make sound decisions under uncertainty.
  • Program and delivery leadership: proven ability to lead complex initiatives across teams, manage dependencies and risks, and deliver measurable outcomes without relying on formal authority.
  • Strategic communication: ability to present clear recommendations, tradeoffs, and risk implications to senior technical leaders, business stakeholders, and governance partners.
  • Operational excellence: ability to establish repeatable engineering practices, metrics, documentation, service expectations, and continuous-improvement mechanisms.
  • Technical mentorship: ability to raise team capability through design reviews, coaching, knowledge sharing, and constructive challenge.
  • Hands-on capability with scripting and automation, security tooling, TCP/IP and network protocols, zero trust principles, and AWS/Azure/GCP security controls.
  • Resilience and accountability: ability to lead through high-pressure incidents, own outcomes, and communicate candidly when risks, constraints, or delivery issues arise.

Working Conditions / Physical Requirements / Travel Requirements

  • Travel up to 10%
  • Remote setting w/travel to the office as needed