> Markdown version of [/jobs/ext/185892-information-security-governance-analyst](https://www.wearedevelopers.com/jobs/ext/185892-information-security-governance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Governance Analyst - **Company:** FMC TECHNOLOGIES, INC. - **Location:** Houston, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Control Objectives for Information and Related Technology (COBIT), Cyber Security, IT Management, Requirements Management, Information Technology - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5e7e1987f643a285 ## About the Role Do you have experience in Technical writing?, Do you have a Bachelor's degree?, * Bachelor's degree in computer science or related discipline considered as a plus * 2+ years of experience in supporting or auditing IT and Information Security compliance programs. * Strong understanding of compliance regulations (e.g., Sarbanes Oxley 404, PCAOB, PCI, GDPR) and security standards (e.g., ISO 27001, NIST CSF). * Familiar with IT governance and quality frameworks such as ISO, COBIT, and ITIL. * Skilled in compliance metrics tracking. * Proven ability to work effectively in global, matrixed environments. * Excellent interpersonal, organizational, and communication skills. * Comfortable collaborating across enterprise-scale organizations and building effective working relationships. * Advanced oral and written communication skills in English. * Strong analytical, problem-solving, and critical thinking capabilities. Nice to have: Information Security related certifications such as CISA, Security+, Network+, Azure AZ-900, AZ-500, AWS certification, CEH. Skills Verbal Communication Coaching Stakeholder Management Technical Writing Systems Thinking Compliance Support Risk Assessment Written Communication Incident Management Process Improvement Budgeting Demand Intake Project/Program Management Business Continuity and Disaster Recovery Planning Develop Governance Principles ## Description We are seeking an Information Security Governance Analyst to support our Information Security Governance, Risk and Compliance (GRC) programme. In this role, you will help demonstrate compliance with key regulatory and industry frameworks by coordinating audits and assessments, gathering and validating evidence, tracking actions through to closure, and supporting continuous improvement of governance documentation and reporting. In this role you will serve as an Information Security Professional as an Information Security Governance Analyst, protecting TechnipFMC information security throughout the system lifecycle. The Information Security Governance Analyst supports the IT compliance program within the Information Security organization. This support includes but is not limited to Sarbanes Oxley (SOX), SOC 2, ISO 27001, ISO 42001, NIST, questionnaires, audits and assessments from 3rd parties, clients and partners assessing the TechnipFMC's regulatory compliance status. Applicants must be authorized to work for any employer in the U.S. without restriction. For this position we are not sponsoring or taking over sponsorship of an employment visa at this time., * Coordinate internal and external audits and controls testing (e.g., SOX, SOC 2, ISO 27001/42001, NIST) by managing timelines, stakeholders, and deliverables to support on-time, high-quality audit outcomes. * Triage, assign, and track requests for information (RFIs) to the correct SMEs, ensuring clear ownership and deadlines and improving response timeliness. * Collect, validate, and submit audit evidence by performing completeness/quality checks to reduce evidence rework and audit follow-ups. * Identify evidence gaps and drive closure by working with control owners/SMEs to remediate missing or insufficient evidence before submission deadlines. * Maintain audit schedules and status trackers to provide accurate, current visibility of audit progress, evidence readiness, and risks to delivery. * Maintain an Audit Findings List and Corrective Action Log to ensure findings are documented, assigned, tracked, and closed within agreed timescales. * Monitor control testing progress and exceptions (including failed tests) and escalate issues with clear context and impact to support timely remediation decisions. * Support third-party, customer, and partner security assessments and questionnaires by coordinating inputs and validating responses to protect accuracy and consistency of submissions. * Maintain and update governance document status trackers to ensure policies/standards/procedures are reviewed, current, and traceable. * Support ongoing maintenance of governing documents by coordinating periodic reviews and updates with stakeholders to keep documentation aligned to requirements and practice. * Identify compliance programme gaps and recommend improvements based on audit outcomes, metrics, and stakeholder feedback to strengthen control effectiveness and readiness. * Maintain GRC metrics, KPIs, and the Risk and Controls Matrix (RCM) to support evidence-based reporting and prioritisation of compliance activities. * Input data into the GRC tooling/module and publish GRC-related content to ensure records are complete, current, and available for reporting and audits. * Prepare materials for management reviews, compliance committees, and governance forums to enable clear decision-making and documented oversight., Requirements Management and Analysis Governance and Security Administration Lean Evidence Handling Regulatory Compliance Interpreting Requirements Project Risk and Issues Management Work Prioritization ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)