Supports cybersecurity governance, risk management, compliance, and assurance programs. Develops security policies and frameworks, conducts risk assessments, coordinates remediation, and leads audit and questionnaire responses. Reviews cloud, system, and OT architectures; manages documentation, evidence, vulnerability tracking, and third-party risk. Supports incident response, data protection, security awareness, and project security requirements while ensuring compliance with NIST, CMMC, FedRAMP, ITAR, EAR, and other regulations.
As a Sr. GRC Analyst for Oceaneering, you will support the organization's cybersecurity governance, risk management, compliance, and security assurance programs. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk, and protect critical company information assets.
*Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required
Responsibilities- Develop, maintain, and enhance cybersecurity policies, standards, procedures, and governance frameworks.
- Conduct cybersecurity risk assessments and coordinate mitigation activities.
- Support compliance initiatives including NIST, CMMC, Cyber Essentials, ISO standards, FedRAMP, UK government requirements, and customer security assessments.
- Lead responses to customer, supplier, and regulatory cybersecurity questionnaires and audits.
- Review system architectures, cloud solutions, and operational technology environments for security requirements and compliance impacts.
- Coordinate vulnerability management, corrective action tracking, and remediation activities.
- Support incident response, investigations, and security event escalation processes.
- Manage cybersecurity documentation, evidence collection, and audit readiness activities.
- Collaborate with business units, engineering teams, and project stakeholders to incorporate security requirements into projects and operational processes.
- Evaluate third-party and supply chain cybersecurity risks.
- Provide cybersecurity guidance, awareness, and training to internal stakeholders.
- Support data protection initiatives including CUI, ITAR, EAR, and sensitive information handling requirements.
*As a position necessitating ITAR Regulation Compliance, Permanent Resident or US Citizen Status is required
QualificationsRequired Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
- Minimum 5 years of cybersecurity, risk management, compliance, governance, or information security experience.
- Minimum 5 years with:
- NIST SP 800-53 or NIST SP 800-171
- CMMC
- Risk Management Framework (RMF)
- Minimum 5 years of with security assessments, audits, and control implementation.
- Minimum 3 years of cloud security, identity management, endpoint protection, vulnerability management, and security monitoring.
- Strong technical writing and documentation skills.
- Ability to communicate cybersecurity requirements to both technical and non-technical audiences.
- US Citizen or permanent resident (ITAR compliance)
Preferred Qualifications
- CISSP, CISM, CRISC, Security+, CGRC, or equivalent certification.
- Experience supporting government, defense, energy, or critical infrastructure environments.
- Knowledge of operational technology (OT) and industrial control system (ICS) security.
- Experience with Cyber Essentials / Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms.
- Understanding of data classification, export control, and regulatory compliance requirements.
Equal Opportunity Employer:
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.
Similar Jobs
Hardware • Software • Energy
Manage Base’s security governance, risk, and compliance program across software, hardware, manufacturing, field operations, and energy infrastructure. Responsibilities include running SOC 2 and ISO 27001 programs, collecting evidence, testing controls, coordinating audits, maintaining policies and risk registers, assessing vendors, mapping controls to security frameworks, managing customer security assessments, and delivering security awareness training.
Top Skills:
Cis ControlsCloud Audit LogsDrataGrc PlatformsIso 27001MfaNist 800-53Nist CsfSecureframeSIEMSoc 2Vanta
Insurance • Professional Services • Software • Financial Services
Owns enterprise GRC platform administration and migration, including configuration, access, workflows, integrations, reporting, dashboards, and module rollouts. Builds executive risk analytics and key risk indicator reporting, supports control testing, documents processes, trains users, and drives platform automation. Partners with audit, risk, privacy, cybersecurity, IT, and vendors to improve compliance operations and eliminate redundant tooling.
Top Skills:
Ai-Assisted WorkflowsArcherHrisExcelOnspringServicenowSQLWorkiva
Marketing Tech
Owns enterprise GRC platform administration and migration, including configuration, workflows, integrations, control mapping, reporting, analytics, and module rollouts. Develops executive dashboards, key risk indicators, findings analyses, documentation, and training. Partners with audit, risk, privacy, cybersecurity, IT, and business stakeholders to improve compliance processes, automate workflows, support control testing, and consolidate redundant technology. Requires hands-on GRC platform administration, migration experience, strong reporting skills, and knowledge of risk and compliance frameworks.
Top Skills:
ArcherHitrustIso 27001ExcelNistOnspringServicenowSoc 2SQLWorkiva
What you need to know about the Austin Tech Scene
Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.
Key Facts About Austin Tech
- Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
- Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
- Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
- Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center



