Information Security Governance Analyst
Houston, TX, US
Job Purpose
Hiring an Information Security Goverance Analyst that will serve as an Information Security Professional as an Information Security Analyst, protecting TechnipFMC information security throughout the system lifecycle.
The Information Security Analyst supports the IT compliance program within the Information Security organization. This support includes but is not limited to Sarbanes Oxley (SOX), SOC 2, ISO 27001, ISO 42001, NIST, and questionnaires from 3rd parties, clients and partners assessing the TechnipFMC’s regulatory compliance status.
Additionally, the role supports the development and implementation of AI governance practices, ensuring responsible and compliant use of AI technologies across the organization.
This position will be a hybrid role working 3 days at our corporate office in Houston, TX.
Job Description
- Audit & Assessment Support
- Conducts and supports internal/external audits and controls testing.
- Gathers, evaluates, and uploads evidence; resolves gaps with SMEs.
- Manages audit schedules and status trackers.
- Assists with customer assessments and questionnaires.
- Reports audit findings and evidence status to GRC management.
- Governing Document Management
- Maintains and updates document status trackers.
- Reviews and reports document status to stakeholders.
- Supports document maintenance and updates as needed.
- AI Governance & Compliance
- Assists in implementing AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
- Supports risk assessments and compliance reviews for AI systems.
- Tracks AI-related controls and regulatory requirements (e.g., EU AI Act).
- Collaborates with AI COE and technical teams to promote responsible AI practices.
- Maintains documentation and metrics related to AI governance.
- Program Improvement & Reporting
- Identifies compliance program gaps and recommends improvements.
- Maintains GRC metrics, KPIs, and the Risk and Controls Matrix (RCM).
- Inputs data into the GRC module and publishes GRC-related content
You are meant for this job if:
Education Requirements:
- Bachelor’s degree in computer science or related discipline considered as a plus
- Certifications: CISA, Security+, Network+, Azure AZ-900, AZ-500, AWS certification, CEH, etc.
- AI-related certifications or coursework (e.g., Responsible AI, ISO/IEC 42001, NIST AI RMF, AIGP) are a plus.
Work Experience:
- 3+ years of experience in supporting or auditing IT and Information Security compliance programs.
- Strong understanding of compliance regulations (e.g., Sarbanes Oxley 404, PCAOB, PCI, GDPR) and security standards (e.g., ISO 27001, NIST CSF).
- Familiar with IT governance and quality frameworks such as ISO, COBIT, and ITIL.
- Skilled in risk assessment methodologies and compliance metrics tracking.
- Experience supporting AI governance and compliance initiatives is a plus.
- Proven ability to work effectively in global, matrixed environments.
- Excellent interpersonal, organizational, and communication skills.
- Strong analytical, problem-solving, and critical thinking capabilities.
- Comfortable collaborating across enterprise-scale organizations and building effective working relationships.
- Advanced oral and written communication skills in English.
Work Environment:
- Office work environment.
- Sponsoring and mentoring environment
- Diversity in work groups
Skills
Nearest Major Market: Houston