WE Soda logo
Moves you to
United States
Support
Relocation support
Posted
Is this job info correct?
Show job description
Posted Wednesday, October 7, 2026 at 6:00 AM

At WE Soda, we believe you are the most important asset. We are taking steps to attract and retain talented and motivated salaried entry-level and experienced individuals. Come utilize your skills and contribute to our continued success. Your new rewarding career begins here!

WE Soda is the world’s largest and most sustainable producer of soda ash, with operations in Turkey and two US-based facilities, located in Green River, Wyoming. At WE Soda, we strive to be the global leader in safe, sustainable, and innovative soda ash solutions, inspiring progress and creating a lasting positive impact for our industry and communities.


Why Join WE Soda?

  • Highly competitive salary commensurate with experience.
  • Medical, Dental, Life & Disability Insurance, Vision, Flexible Spending (Medical and Dependent Care) and Health Savings Accounts (HSA), Pre-paid Legal, beginning first day of employment: company funds a portion of HSA contribution if eligibility is met.
  • 401(k) Savings and Investment Plan for salaried employees, the company makes Safe Harbor matching contributions (fully vested immediately) of 100% up to the first 5% of eligible pay you contribute.
  • Tuition reimbursement programs are available to qualifying employees for approved programs.
  • Paid time off based on years of service with potential credit given for previous work experience.
  • Company-paid transportation available for our Wyoming-based employees to our plants from Green River, Rock Springs, and Bridger Valley.
  • Flexible work schedule (may be available and will vary based on location and/or position).
  • Relocation assistance may be available based on position.

Title: IT Security Analyst Plant Information Resources

Location: Green River, WY (On-site)
Supports operations across the United States and collaborates closely with global teams in the United Kingdom and Turkey.

Reports to: Global Information Security Lead

Direct Reports: None

Role Purpose: The IT Security Analyst is the primary hands-on cybersecurity resource for WE Soda’s United States operations, covering both IT and OT/ICS environments. Reporting to the Global Information Security Lead, the role engineers, operates, and continuously improves the security controls protecting the US business — including firewalls and network security, SIEM, endpoint detection and response (EDR), OT security monitoring, email security, and data loss prevention — and acts as the local lead for security incident response, vulnerability management, and the security awareness program.

The role works closely with the US IT team and with global information security colleagues in the UK and Turkey and supports post-acquisition integration by aligning US network and security services with WE Soda’s global standards, policies, and compliance requirements.

Key Responsibilities:

• Serve as the principal technical cybersecurity specialist for the US region, spanning IT and OT/ICS environments.

• Engineer, configure, and maintain network security infrastructure: firewalls, VPN/remote access, network segmentation, IDS/IPS, and wireless security.

• Administer the SIEM platform: log source onboarding, detection rule and use-case development, alert triage, tuning, dashboards, and reporting.

• Administer the EDR/endpoint protection platform: policy management, threat hunting, containment, and response actions.

• Support OT/ICS security: asset visibility and passive monitoring, IT/OT segmentation, and secure remote access to industrial environments, aligned with IEC 62443 and NIST SP 800-82.

• Lead local detection, triage, containment, and recovery of security incidents, following global incident response playbooks and escalation paths.

• Support the wider security program: email security and phishing triage, data loss prevention (DLP), security awareness activities, vulnerability and patch management, and audit/compliance evidence gathering.

• Implement and enforce WE Soda security policies and standards and contribute to an Information Security Management System aligned with NIST CSF 2.0 and ISO 27001.

• Communicate project status, risks, and achievements clearly to internal and external partners, including managed service providers.

Activities:

Engineering and Provisioning

• Configure, manage, and troubleshoot networking and security equipment (firewalls, switches, wireless, VPN concentrators).

• Maintain secure network architecture and segmentation, including IT/OT boundary controls.

• Conduct regular security assessments, network audits, and configuration reviews.

• Apply security patches and firmware updates to network devices and security systems.

• Perform network traffic analysis and packet inspection to investigate anomalies.

Security Operations and Incident Response

• Monitor and triage SIEM and EDR alerts; investigate suspicious activity and escalate per incident response procedures.

• Execute containment and remediation actions during security incidents and produce incident reports and lessons learned.

• Perform phishing triage and message removal for reported emails; feed confirmed indicators of compromise into blocking controls.

• Coordinate vulnerability scanning, prioritization (including known-exploited vulnerabilities), and remediation tracking with system owners.

• Act as the US point of contact for the managed security service provider (MSSP/MDR) and external penetration testing engagements.

OT/ICS Security

• Support deployment and operation of OT security monitoring tooling and asset inventory for industrial environments.

• Work with plant engineering and operations teams to assess and reduce cyber risk to industrial control systems without disrupting production.

Governance, Awareness and Compliance

• Support the global security awareness program locally: phishing simulations, training assignment and completion follow-up, and awareness campaigns.

• Implement and monitor DLP and data protection controls in line with data classification requirements.

• Maintain evidence and documentation to support internal audits, certifications, and regulatory requirements.

Maintenance and Support:

• Document and maintain operations, configurations, standards, and procedures.

• Monitor system performance and security, identifying and addressing issues proactively; ensure appropriate up time.

• Maintain infrastructure system backups and the security camera system.

• Participate in infrastructure support and the on-call rotation.

• Support post-acquisition integration: assessment, alignment, and transition of network and security services to meet WE Soda’s standards and compliance requirements.

Required Skills, Capabilities, and Educational Requirements:

• University degree in computer science, information technology, cybersecurity, or a related field — or equivalent professional experience — plus 5+ years of network administration and cybersecurity experience in enterprise environments.

• Hands-on firewall administration and network security engineering (e.g. Fortinet FortiGate, Cisco FTD/FMC), including IDS/IPS and secure remote access/VPN.

• Deep knowledge of networking technologies (routing protocols, VLANs, ACLs, NAT, VPN) and proficiency with command-line interfaces (CLI).

• SIEM administration and detection engineering experience (log onboarding, rule creation, alert tuning); LogRhythm experience is a strong advantage.

• EDR/endpoint protection administration and threat hunting experience; Sentinel One experience is a strong advantage.

• Practical security incident response experience: triage, investigation, containment, and reporting.

• Working knowledge of OT/ICS environments and industrial protocols, and of securing IT/OT boundaries (IEC 62443, NIST SP 800-82).

• Familiarity with Microsoft 365 and Entra ID security (Conditional Access, MFA) and email security controls.

• Excellent problem-solving skills and the ability to communicate findings clearly to colleagues and management.

• Strong attention to detail, strong communication and interpersonal skills, and the ability to work autonomously as the primary regional security resource within a global team spanning multiple time zones.

Preferred Skills, Capabilities, and Educational Requirements:

• Master’s degree in cybersecurity or a related discipline.

• Experience with OT security monitoring platforms (e.g. Dragos, Claroty, Nozomi Networks).

• Hands-on experience with Cisco FTD, FMC, WLC, ISE, AnyConnect VPN, Duo, Microsoft SCCM/Intune, and Commvault.

• Experience with email security gateways (e.g. Proofpoint, Microsoft Defender for Office 365), phishing triage platforms, DLP tooling, and security awareness platforms (e.g. KnowBe4).

• Scripting and automation skills (PowerShell, Python).

• Familiarity with security frameworks and regulations: NIST CSF 2.0, NIST SP 800-53, ISO 27001, and US state breach notification requirements.

• Professional certifications such as CompTIA Security+ or CySA+, GIAC (GSEC, GCIA, GCIH, GICSP), Fortinet NSE, Cisco security certifications, or CISSP.

• Experience in manufacturing, chemical, or other critical infrastructure sectors.

WE Soda is an equal opportunity employer. All employment decisions are made without regard to race, color, religion, national origin, sex (including pregnancy, childbirth, and related medical conditions, sexual orientation, or gender identity), age (40 or older), disability, genetic information (including employer requests for, or purchase, use, or disclosure of genetic tests, genetic services, or family medical history), or any other legally protected categories. This includes providing reasonable accommodation for employee's and applicant's disabilities or religious beliefs and practices. Alternative methods of applying for employment are available to individuals unable to apply through this site because of a disability. Contact WE Soda Human Resources to discuss reasonable accommodations by sending an email to humanresources@wesoda.com.

Similar jobs

Apply for this job