GRC Analyst

Oceaneering International Inc

  • Houston, TX
  • 8 days ago

    Highlights

    Experience with Cyber Essentials / Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk, and protect critical company information assets.

    Numbers & Facts

    LocationHouston, TX

    Description

    As a Sr. GRC Analyst for Oceaneering, you will support the organization''s cybersecurity governance, risk management, compliance, and security assurance programs. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk, and protect critical company information assets.

    • Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required

    Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world''s premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.

    Equal Opportunity Employer:

    All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.

    Required Qualifications

    • Bachelor''s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).

    • Minimum 5 years of cybersecurity, risk management, compliance, governance, or information security experience.

    • Minimum 5 years with:

    • NIST SP 800-53 or NIST SP 800-171

    • CMMC

    • Risk Management Framework (RMF)

    • Minimum 5 years of with security assessments, audits, and control implementation.

    • Minimum 3 years of cloud security, identity management, endpoint protection, vulnerability management, and security monitoring.

    • Strong technical writing and documentation skills.

    • Ability to communicate cybersecurity requirements to both technical and non-technical audiences.

    • US Citizen or permanent resident (ITAR compliance)

    Preferred Qualifications

    • CISSP, CISM, CRISC, Security+, CGRC, or equivalent certification.
    • Experience supporting government, defense, energy, or critical infrastructure environments.
    • Knowledge of operational technology (OT) and industrial control system (ICS) security.
    • Experience with Cyber Essentials / Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms.
    • Understanding of data classification, export control, and regulatory compliance requirements.
    • Develop, maintain, and enhance cybersecurity policies, standards, procedures, and governance frameworks.
    • Conduct cybersecurity risk assessments and coordinate mitigation activities.
    • Support compliance initiatives including NIST, CMMC, Cyber Essentials, ISO standards, FedRAMP, UK government requirements, and customer security assessments.
    • Lead responses to customer, supplier, and regulatory cybersecurity questionnaires and audits.
    • Review system architectures, cloud solutions, and operational technology environments for security requirements and compliance impacts.
    • Coordinate vulnerability management, corrective action tracking, and remediation activities.
    • Support incident response, investigations, and security event escalation processes.
    • Manage cybersecurity documentation, evidence collection, and audit readiness activities.
    • Collaborate with business units, engineering teams, and project stakeholders to incorporate security requirements into projects and operational processes.
    • Evaluate third-party and supply chain cybersecurity risks.
    • Provide cybersecurity guidance, awareness, and training to internal stakeholders.
    • Support data protection initiatives including CUI, ITAR, EAR, and sensitive information handling requirements.
    • As a position necessitating ITAR Regulation Compliance, Permanent Resident or US Citizen Status is required
    • Develop, maintain, and enhance cybersecurity policies, standards, procedures, and governance frameworks.
    • Conduct cybersecurity risk assessments and coordinate mitigation activities.
    • Support compliance initiatives including NIST, CMMC, Cyber Essentials, ISO standards, FedRAMP, UK government requirements, and customer security assessments.
    • Lead responses to customer, supplier, and regulatory cybersecurity questionnaires and audits.
    • Review system architectures, cloud solutions, and operational technology environments for security requirements and compliance impacts.
    • Coordinate vulnerability management, corrective action tracking, and remediation activities.
    • Support incident response, investigations, and security event escalation processes.
    • Manage cybersecurity documentation, evidence collection, and audit readiness activities.
    • Collaborate with business units, engineering teams, and project stakeholders to incorporate security requirements into projects and operational processes.
    • Evaluate third-party and supply chain cybersecurity risks.
    • Provide cybersecurity guidance, awareness, and training to internal stakeholders.
    • Support data protection initiatives including CUI, ITAR, EAR, and sensitive information handling requirements.
    • As a position necessitating ITAR Regulation Compliance, Permanent Resident or US Citizen Status is required

    Similar Jobs