Role: Cyber Security Specialist Assurance & Compliance ( TX Local)
Location: Houston, TX (Hybrid/Remote)
Job Summary
We are seeking an experienced cyber security specialist assurance & compliance to support enterprise cybersecurity governance, compliance, audit, and assurance initiatives. The ideal candidate will ensure organizational cybersecurity controls comply with internal security standards, regulatory requirements, and contractual obligations while partnering with IT, OT, Legal, Procurement, Risk, and external auditors.
The successful candidate will drive cybersecurity assurance programs, coordinate audits, manage compliance activities, oversee risk remediation, and support security validation for major IT/OT transformation projects.
Key Responsibilities
Cybersecurity Compliance & Monitoring
Coordinate with regulatory agencies and industry bodies to ensure compliance with applicable regulations.
Partner with cybersecurity architecture teams to ensure security controls align with internal policies and standards.
Work closely with Legal and procurement teams to ensure contractual cybersecurity obligations are fulfilled.
Identify applicable regulations across multiple business geographies.
Develop and maintain cybersecurity compliance and assessment programs aligned with industry frameworks.
Manage periodic assurance testing based on business criticality and regulatory exposure.
Develop evidence collection processes to demonstrate cybersecurity compliance.
Monitor compliance gaps and coordinate remediation efforts until closure.
Assurance Management
Maintain cybersecurity assurance processes and governance.
Track assurance findings and coordinate corrective action plans with stakeholders.
Independently validate remediation activities before formal closure.
Maintain assurance registers and reporting dashboards.
Audit Preparation & Management
Prepare and support internal and external cybersecurity audits.
Coordinate with auditors and regulatory agencies.
Maintain audit evidence and documentation.
Track audit findings through successful remediation.
Support customer and contractual security attestations.
Risk Coordination
Partner with Cybersecurity Risk Management teams.
Identify assurance and compliance gaps.
Ensure identified gaps are recorded within enterprise risk registers.
Monitor risk mitigation activities.
Security Awareness & Training
Develop cybersecurity compliance awareness materials.
Deliver compliance and security awareness training sessions.
Identify knowledge gaps across the organization.
Report awareness program effectiveness.
Control Assurance & Testing (IT / OT Transformation)
Act as the cybersecurity assurance focal point for major IT and OT projects.
Define assurance controls and validation criteria.
Design and execute security control testing programs.
Coordinate penetration testing, Red Team exercises, and external security assessments.
Review assessment findings and ensure remediation is completed.
Required Qualifications
Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, or related field.
7+ years of experience in cybersecurity assurance, IT audit, risk, governance, or compliance.
Strong knowledge of cybersecurity frameworks and security controls.
Hands-on experience with audit planning and execution.
Experience working within regulated industries.
Experience performing control testing and validation.
Experience working with external auditors and regulatory bodies.
Strong understanding of risk assessment methodologies.
Excellent communication and stakeholder management skills.
Preferred Skills
IT Audit
Cybersecurity Assurance
Governance, Risk & Compliance (GRC)
Security Controls Assessment
Risk Management
Internal & External Audit
Regulatory Compliance
Vendor Assurance
Penetration Testing Coordination
Red Team Coordination
Evidence Management
Corrective Action Management
IT/OT Security
Security Governance
Compliance Reporting
Control Testing
Security Awareness Training
Nice to Have
Experience with NIST, ISO 27001, CIS Controls, or similar cybersecurity frameworks.
Experience supporting IT and Operational Technology (OT) environments.
Knowledge of regulatory compliance standards.
Relevant certifications such as:
CISSP
CISA
CRISC
CISM
ISO 27001 Lead Auditor
Security+
Minimum Experience
7+ years in IT Audit, Cybersecurity Assurance, Governance, Risk, or Compliance.
Experience with regulatory compliance.
Experience in audit planning and execution.
Experience conducting control testing.
Experience working with external auditors and regulators.