Demo

Cybersecurity Analyst - Governance, Risk, and Compliance (GRC)

Sempra Infrastructure
Houston, TX Full Time
POSTED ON 12/19/2025
AVAILABLE BEFORE 1/25/2026
#25-72892

Houston, Texas, USA

Job Category

Information Technology

Full-Time/Part-Time

Full-time

Job Description

Primary Purpose

This role will lead initiatives to foster a strong cybersecurity culture across the organization, driving awareness programs and educational campaigns to our employees. The Cybersecurity Analyst is part of a broader cybersecurity team that ensures all system design, implementation, and standards protect Sempra's network from cyber-attacks. The Analyst of Governance, Risk, and Compliance (GRC) is focused on preventing security threats and ensuring laws and industry standards are upheld, working with a cross-functional team of across various information security functions to conduct third-party assessments, cybersecurity clause review, exception request handling, SOC reviews, risk control evaluation, and threat intelligence monitoring.

Duties And Responsibilities

Technical Analysis & Delivery

  • Supports the implementation of the governance & risk frameworks, policy creation & management, IT control management, and security audits & assessments️.
  • Manages issues and corrective actions plans identified in risk assessments through closure.
  • Reviews cybersecurity clauses in contracts, applicability criteria, exceptions requests and mitigating controls in accordance with company policies and industry standards.
  • Conducts SOC II reviews and audits.
  • Monitors Cyber Threat Intelligence resources (such as Sempra, CISA, FBI, and others).
  • Proposes and implements innovative ways to establish adequate controls, optimize risk management, and improve continuous monitoring.
  • Coordinates cybersecurity assessments (such as maturity, risk, and penetration testing).
  • Develops and monitors cybersecurity KRIs and KPIs.
  • Increases the level of maturity in risk management and controls.

Communication & Stakeholder Management

  • Designs, implements, and manages a comprehensive Cybersecurity Awareness Program, including phishing simulations, threat education campaigns, and targeted training for high-risk roles.
  • Develops engaging content (videos, newsletters, infographics) to promote security best practices and reduce social engineering risks.
  • Coordinates Cybersecurity Ambassadors Community and champions cultural change initiatives across business units.

Functional Area Leadership

  • Acts as the primary point of contact for awareness-related metrics and reporting to leadership, ensuring visibility into human risk trends and program effectiveness.

Troubleshooting

  • Maintains good operational relationships with 3rd party risk assessment managed service providers to perform risk assessments, develop mitigation plans, and ensure appropriate service levels.
  • Ensures team works closely with System Engineers to implement security controls and patches based on capability and need.
  • Contacts and coordinates vendor, carrier, and remote support when necessary to resolve high-impact security issues.
  • Document problems and report to management, engineers and/or peers.

Performs other duties as assigned (no more than 5% of duties).

Requirements

Qualifications

Education

  • Bachelor's Degree in Computer Science, Information Technology, or equivalent relevant work experience.

Experience

  • 4 years' experience in Information Security, Cyber Security, or relevant roles.
  • 2 years' experience managing Governance, Risk, and Compliance of an organization with a complex Information Technology environment.

Knowledge, Skills, And Abilities

  • Bilingual in Spanish/English is a plus
  • Proven experience in cybersecurity awareness program design and delivery, including phishing simulations and behavioral risk reduction strategies
  • Strong communication and content development skills to engage non-technical audiences effectively
  • Knowledge of adult learning principles and experience leveraging e-learning platforms or gamified training tool
  • Strong understanding of security contract management and legal requirements.
  • Hands-on experience of enterprise GRC tools (e.g., ServiceNow, Archer etc.).
  • Ability to implement global regulatory requirements surrounding data security & privacy (e.g., GDPR, CCPA, CRPA etc.).
  • Understanding of relevant cybersecurity regulations and agencies pertinent to utility environments.
  • General understanding of cyber security operations functions, in areas such as incident response, security monitoring, threat and vulnerability, SOC and SOC service.
  • General knowledge of OT network infrastructure, SCADA/DCS systems, data/communication systems, and management systems.
  • General knowledge of security software architecture/programing concepts and security integration into SDLC.
  • Ability to manage a diverse technical workforce in multiple locations; ability to coach.
  • Personal drive and energy level to achieve superior results individually and through others.
  • Proven experience in cybersecurity awareness program design and delivery, including phishing simulations and behavioral risk reduction strategies
  • Strong communication and content development skills to engage non-technical audiences effectively
  • Knowledge of adult learning principles and experience leveraging e-learning platforms or gamified training tools
  • Strong understanding of security contract management and legal requirements.
  • Hands-on experience of enterprise GRC tools (e.g., ServiceNow, Archer etc.).
  • Ability to implement global regulatory requirements surrounding data security & privacy (e.g., GDPR, CCPA, CRPA etc.).
  • Understanding of relevant cybersecurity regulations and agencies pertinent to utility environments.
  • General understanding of cyber security operations functions, in areas such as incident response, security monitoring, threat and vulnerability, SOC and SOC service.
  • General knowledge of OT network infrastructure, SCADA/DCS systems, data/communication systems, and management systems.
  • General knowledge of security software architecture/programing concepts and security integration into SDLC.
  • Ability to manage a diverse technical workforce in multiple locations; ability to coach.
  • Personal drive and energy level to achieve superior results individually and through others.

Licenses and Certifications

  • Standard certifications in Information Security (CISSP, CISM, CISA, or equivalent)
  • Technical certifications (GRC related e.g. ISACA CRISC)

Salary : $99,000 - $148,500

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Analyst - Governance, Risk, and Compliance (GRC)?

Sign up to receive alerts about other jobs on the Cybersecurity Analyst - Governance, Risk, and Compliance (GRC) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$71,440 - $92,105
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$115,647 - $153,495
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Sempra Infrastructure

  • Sempra Infrastructure San Diego, TX
  • #25-73066 Houston, Texas, USA Job Category Information Technology Full-Time/Part-Time Full-time Job Description The Mgr, Group Product - People & Culture a... more
  • 13 Days Ago

  • Sempra Infrastructure Houston, TX
  • #25-72926 Houston, Texas, USA Job Category Business Operations Full-Time/Part-Time Full-time Job Description Primary Purpose Acting as part of a shared ser... more
  • 4 Days Ago

  • Sempra Infrastructure Houston, TX
  • #26-73117 Houston, Texas, USA Job Category Accounting/Finance Full-Time/Part-Time Full-time Job Description Primary Purpose Drives success of large-scale p... more
  • 4 Days Ago

  • Sempra Infrastructure San Diego, TX
  • #25-72963 Houston, Texas, USA Job Category Information Technology Full-Time/Part-Time Full-time Job Description Primary Purpose The Senior Manager, ERP Tec... more
  • 4 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Analyst - Governance, Risk, and Compliance (GRC) jobs in the Houston, TX area that may be a better fit.

  • B12 Consulting Houston, TX
  • Duties and Responsibilities: Provide executive oversight of Governance, Risk & Compliance programs including policy governance, enterprise risk management,... more
  • 4 Days Ago

  • KPMG US Houston, TX
  • KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and looking forward we do not anticipate that slo... more
  • 11 Days Ago

AI Assistant is available now!

Feel free to start your new journey!