As a Sr. GRC Analyst for Oceaneering, you will support the organization's cybersecurity governance, risk management, compliance, and security assurance programs. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement security controls, maintain compliance with industry and government requirements, reduce cyber risk, and protect critical company information assets.
*Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required
Responsibilities- Develop, maintain, and enhance cybersecurity policies, standards, procedures, and governance frameworks.
- Conduct cybersecurity risk assessments and coordinate mitigation activities.
- Support compliance initiatives including NIST, CMMC, Cyber Essentials, ISO standards, FedRAMP, UK government requirements, and customer security assessments.
- Lead responses to customer, supplier, and regulatory cybersecurity questionnaires and audits.
- Review system architectures, cloud solutions, and operational technology environments for security requirements and compliance impacts.
- Coordinate vulnerability management, corrective action tracking, and remediation activities.
- Support incident response, investigations, and security event escalation processes.
- Manage cybersecurity documentation, evidence collection, and audit readiness activities.
- Collaborate with business units, engineering teams, and project stakeholders to incorporate security requirements into projects and operational processes.
- Evaluate third-party and supply chain cybersecurity risks.
- Provide cybersecurity guidance, awareness, and training to internal stakeholders.
- Support data protection initiatives including CUI, ITAR, EAR, and sensitive information handling requirements.
*As a position necessitating ITAR Regulation Compliance, Permanent Resident or US Citizen Status is required
QualificationsRequired Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
- Minimum 5 years of cybersecurity, risk management, compliance, governance, or information security experience.
- Minimum 5 years with:
- NIST SP 800-53 or NIST SP 800-171
- CMMC
- Risk Management Framework (RMF)
- Minimum 5 years of with security assessments, audits, and control implementation.
- Minimum 3 years of cloud security, identity management, endpoint protection, vulnerability management, and security monitoring.
- Strong technical writing and documentation skills.
- Ability to communicate cybersecurity requirements to both technical and non-technical audiences.
- US Citizen or permanent resident (ITAR compliance)
Preferred Qualifications
- CISSP, CISM, CRISC, Security+, CGRC, or equivalent certification.
- Experience supporting government, defense, energy, or critical infrastructure environments.
- Knowledge of operational technology (OT) and industrial control system (ICS) security.
- Experience with Cyber Essentials / Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms.
- Understanding of data classification, export control, and regulatory compliance requirements.
Skills Required
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent experience
- At least 5 years of experience in cybersecurity, risk management, compliance, governance, or information security
- At least 5 years of experience with NIST SP 800-53 or NIST SP 800-171
- At least 5 years of experience with CMMC
- At least 5 years of experience with the Risk Management Framework
- At least 5 years of experience with security assessments, audits, and control implementation
- At least 3 years of experience with cloud security, identity management, endpoint protection, vulnerability management, and security monitoring
- Strong technical writing and documentation skills
- Ability to communicate cybersecurity requirements to technical and non-technical audiences
- US citizen or permanent resident status for ITAR compliance
- CISSP, CISM, CRISC, Security+, CGRC, or equivalent certification
- Experience supporting government, defense, energy, or critical infrastructure environments
- Knowledge of OT and ICS security
- Experience with Cyber Essentials or Cyber Essentials Plus, ISO 27001, CIS Controls, Microsoft 365 security, Microsoft Purview, Microsoft Defender, Entra ID, and cloud governance platforms
- Understanding of data classification, export control, and regulatory compliance requirements
Oceaneering Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Oceaneering and has not been reviewed or approved by Oceaneering.
-
Healthcare Strength — Healthcare offerings are portrayed as comprehensive, including private medical insurance and broad medical, dental, and vision coverage tailored to local markets. In several contexts, coverage is characterized as good to outstanding.
-
Retirement Support — Retirement programs include pension/retirement plans and a U.S. 401(k), which are consistently highlighted as part of a competitive package. These elements are described as contributing meaningful value to overall compensation.
-
Leave & Time Off Breadth — Leave programs include PTO/vacation, paid holidays, and paid sick leave, with annual leave emphasized globally. Time-off provisions are noted as a steady component of total rewards even when salary opinions differ.
Oceaneering Insights
What We Do
Oceaneering pushes the frontiers of deep water, space and motion entertainment environments to execute with new, leading-edge connections to solve tomorrow’s challenges, today. As the trusted subsea connection specialist, our experience combined with the depth and breadth of our portfolio of technologies allows us to engineer solutions for the most complex subsea challenges. From routine to extreme, our integrated products, services, and innovative solutions safely de-risk operational systems, increase reliability, and enable a lower total cost of ownership. We are connecting what’s needed with what’s next as the world’s largest ROV operator and the leading ROV provider to the oil and gas industry with over 300 systems operating worldwide. With our safety-focused and innovative approach, we responsively and decisively react to subsea challenges while providing solutions swiftly and efficiently.









