Sempra Infrastructure

Cybersecurity Analyst - Governance, Risk, and Compliance (GRC)

Cybersecurity Analyst - Governance, Risk, and Compliance (GRC)
Notice info
LocationHouston, TX
Job Typecontract
On-site
Oil and Gas

About This Job

Primary Purpose

This role will lead initiatives to foster a strong cybersecurity culture across the organization, driving awareness programs and educational campaigns to our employees. The Cybersecurity Analyst is part of a broader cybersecurity team that ensures all system design, implementation, and standards protect Sempra's network from cyber-attacks. The Analyst of Governance, Risk, and Compliance (GRC) is focused on preventing security threats and ensuring laws and industry standards are upheld, working with a cross-functional team of across various information security functions to conduct third-party assessments, cybersecurity clause review, exception request handling, SOC reviews, risk control evaluation, and threat intelligence monitoring.

Duties and Responsibilities

Technical Analysis & Delivery

Supports the implementation of the governance & risk frameworks, policy creation & management, IT control management, and security audits & assessments️.

Manages issues and corrective actions plans identified in risk assessments through closure.

Reviews cybersecurity clauses in contracts, applicability criteria, exceptions requests and mitigating controls in accordance with company policies and industry standards.

Conducts SOC II reviews and audits.

Monitors Cyber Threat Intelligence resources (such as Sempra, CISA, FBI, and others).

Proposes and implements innovative ways to establish adequate controls, optimize risk management, and improve continuous monitoring.

Coordinates cybersecurity assessments (such as maturity, risk, and penetration testing).

Develops and monitors cybersecurity KRIs and KPIs.

Increases the level of maturity in risk management and controls.

Communication & Stakeholder Management

Designs, implements, and manages a comprehensive Cybersecurity Awareness Program, including phishing simulations, threat education campaigns, and targeted training for high-risk roles.

Develops engaging content (videos, newsletters, infographics) to promote security best practices and reduce social engineering risks.

Coordinates Cybersecurity Ambassadors Community and champions cultural change initiatives across business units.

Functional Area Leadership

Acts as the primary point of contact for awareness-related metrics and reporting to leadership, ensuring visibility into human risk trends and program effectiveness.

Troubleshooting

Maintains good operational relationships with 3rd party risk assessment managed service providers to perform risk assessments, develop mitigation plans, and ensure appropriate service levels.

Ensures team works closely with System Engineers to implement security controls and patches based on capability and need.

Contacts and coordinates vendor, carrier, and remote support when necessary to resolve high-impact security issues.

Document problems and report to management, engineers and/or peers.

Performs other duties as assigned (no more than 5% of duties).

Qualifications

Education

Bachelor's Degree in Computer Science, Information Technology, or equivalent relevant work experience.

Experience

4+ years' experience in Information Security, Cyber Security, or relevant roles.

2+ years' experience managing Governance, Risk, and Compliance of an organization with a complex Information Technology environment.

Knowledge, Skills, and Abilities

Bilingual in Spanish/English is a plus

Proven experience in cybersecurity awareness program design and delivery, including phishing simulations and behavioral risk reduction strategies

Strong communication and content development skills to engage non-technical audiences effectively

Knowledge of adult learning principles and experience leveraging e-learning platforms or gamified training tool

Strong understanding of security contract management and legal requirements.

Hands-on experience of enterprise GRC tools (e.g., ServiceNow, Archer etc.).

Ability to implement global regulatory requirements surrounding data security & privacy (e.g., GDPR, CCPA, CRPA etc.).

Understanding of relevant cybersecurity regulations and agencies pertinent to utility environments.

General understanding of cyber security operations functions, in areas such as incident response, security monitoring, threat and vulnerability, SOC and SOC service.

General knowledge of OT network infrastructure, SCADA/DCS systems, data/communication systems, and management systems.

General knowledge of security software architecture/programing concepts and security integration into SDLC.

Ability to manage a diverse technical workforce in multiple locations; ability to coach.

Personal drive and energy level to achieve superior results individually and through others.

Proven experience in cybersecurity awareness program design and delivery, including phishing simulations and behavioral risk reduction strategies

Strong communication and content development skills to engage non-technical audiences effectively

Knowledge of adult learning principles and experience leveraging e-learning platforms or gamified training tools

Strong understanding of security contract management and legal requirements.

Hands-on experience of enterprise GRC tools (e.g., ServiceNow, Archer etc.).

Ability to implement global regulatory requirements surrounding data security & privacy (e.g., GDPR, CCPA, CRPA etc.).

Understanding of relevant cybersecurity regulations and agencies pertinent to utility environments.

General understanding of cyber security operations functions, in areas such as incident response, security monitoring, threat and vulnerability, SOC and SOC service.

General knowledge of OT network infrastructure, SCADA/DCS systems, data/communication systems, and management systems.

General knowledge of security software architecture/programing concepts and security integration into SDLC.

Ability to manage a diverse technical workforce in multiple locations; ability to coach.

Personal drive and energy level to achieve superior results individually and through others.

Licenses and Certifications

Standard certifications in Information Security (CISSP, CISM, CISA, or equivalent)

Technical certifications (GRC related e.g. ISACA CRISC)

Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled

Trending Jobs

company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull time
Salary
$55 - $75
Canonsburg, PA
10 months ago
company-logo

Division Order Analyst

Coronado Resources
Job TypeFull time
 
Dallas, TX
7 months ago
company-logo

Professional Landman

Penterra Services, LLC
Job TypeContract
 
Lovington, NM
6 months ago
company-logo

Accounts Payable Clerk

LPR Energy
Job TypeFull time
Salary
$65000 - $65000
Dallas, TX
8 months ago
company-logo

Division Order Landman

R. Lacy Services, Ltd.
Job TypeFull time
 
Longview, TX
7 months ago
company-logo

Title Landman

Sustain Land Services
Job TypeFull time
 
Norman, OK
9 months ago
company-logo

Lead Software Engineer

Energy Hire
Job TypeFull time
Salary
$120000 - $180000
Dallas, Texas
4 months ago
HE

Landman

Herbaly Exploration LLC
Job TypeFull time
 
Littleton, Colorado
about 1 month ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull time
 
Dallas, TX
8 months ago
company-logo

Landman

Stockyards Energy Land Services
Job TypeContract
 
Akiachak, TX
11 months ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull time
 
Lafayette, LA
10 months ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull time
 
Houston, TX
over 1 year ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull time
 
Midland, TX
10 months ago
company-logo

Oil and Gas Title Attorney

Oliva Gibbs PLLC
Job TypeFull time
 
Houston, TX
8 months ago
company-logo

Title Reviewer

Innovation Land Services
Job TypeFull time
 
Pittsburgh, PA
10 months ago
company-logo

Civil/Structural Designer

Dudley Staffing
Job TypeFull time
Salary
$30 - $60
Canonsburg, PA
10 months ago
company-logo

Data Analyst

River City Science Academy
Job TypeFull time
Salary
$20 - $45
Jacksonville, FL
9 months ago
company-logo

Electrical Designer

Dudley Staffing
Job TypeFull time
Salary
$45 - $60
Canonsburg, PA
10 months ago
company-logo

Kentucky Director of Protection

The Nature Conservancy
Job TypeFull time
Salary
$80000 - $90000
Lexington, Kentucky
about 1 month ago
company-logo

Application Developer

Energy Hire
Job TypeFull time
 
Midland, Texas
3 months ago