Senior GRC Analyst – Cybersecurity Governance & Risk
Oceaneering Group Enterprise · Houston
Job description
About the role
As a Senior GRC Analyst for Oceaneering, you will support the organization’s cybersecurity governance, risk management, compliance, and security‑assurance programs. You will partner with business units, IT, OT, legal and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk and protect critical information assets. The role offers a hybrid work environment, combining virtual work with on‑site presence in Houston when required.
Key responsibilities
- Develop, maintain and enhance cybersecurity policies, standards, procedures and governance frameworks.
- Conduct cybersecurity risk assessments and coordinate mitigation activities.
- Support compliance initiatives such as NIST, CMMC, Cyber Essentials, ISO, FedRAMP and UK government requirements.
- Lead responses to customer, supplier and regulatory cybersecurity questionnaires and audits.
- Review system architectures, cloud solutions and OT environments for security and compliance impacts.
- Coordinate vulnerability management, corrective‑action tracking and remediation activities.
- Support incident response, investigations and security event escalation processes.
- Manage cybersecurity documentation, evidence collection and audit‑readiness activities.
Required profile
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field (or equivalent experience).
- Minimum 5 years of experience in cybersecurity, risk management, compliance, governance or information security.
- At least 5 years working with NIST SP 800‑53, NIST SP 800‑171 and the Risk Management Framework.
- Minimum 5 years conducting security assessments, audits and control implementation.
- At least 3 years of experience in cloud security, identity management, endpoint protection, vulnerability management and security monitoring.
- U.S. citizen or permanent resident (ITAR compliance required).
Required skills
- NIST SP 800‑53 and NIST SP 800‑171
- Risk Management Framework (RMF)
- Cloud security and governance platforms
- Identity management and access control (e.g., Entra ID)
- Endpoint protection and vulnerability management
- Security monitoring and incident response
- Security assessments and audit coordination
- Technical writing and documentation
- Microsoft 365 security, Microsoft Purview, Microsoft Defender
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 day ago
Expires 1 month from now
2 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Oceaneering Group Enterprise
Houston
Related job offers
-
Spacecraft Flight Software Development Engineer (P2)
Oceaneering Group Enterprise Houston -
Spacecraft Flight Software Engineer (P2) – Space Systems
Oceaneering Group Enterprise Houston -
Systems Administrator – Linux & Cloud Operations
Oceaneering Group Enterprise Houston -
Operations Technology Specialist (Remote)
BCD Travel -
Manager, Web Platform Owner
KPMG US San Juan