About this role
As a Sr. GRC Analyst for Oceaneering, you will support the organization's cybersecurity governance, risk management, compliance, and security assurance programs. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk, and protect critical company information assets.
*Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
- Minimum 5 years of cybersecurity, risk management, compliance, governance, or information security experience.
- Minimum 5 years with: NIST SP 800-53 or NIST SP 800-171
- CMMC
- Risk Management Framework (RMF)
- Minimum 5 years of with security assessments, audits, and control implementation.
- Minimum 3 years of cloud security, identity management, endpoint protection, vulnerability management, and security monitoring.
- Strong technical writing and documentation skills.
- Ability to communicate cybersecurity requirements to both technical and non-technical audiences.
- US Citizen or permanent resident (ITAR compliance)
Preferred Qualifications
- CISSP, CISM, CRISC, Security+, CGRC, or equivalent certification.
- Experience supporting government, defense, energy, or critical infrastructure environments.
- Knowledge of operational technology (OT) and industrial control system (ICS) security.
- Experience with Cyber Essentials / Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms.
- Understanding of data classification, export control, and regulatory compliance requirements.