Bristow

Bristow

IT Security and Compliance Analyst

Houston - Texas

Sponsorship not specified$171k-$800kDetected 30 days ago
CybersecuritySIEMSOC OperationsIncident ResponseComplianceStakeholder ManagementProcurementCommunicationCISSP

About the role

  • The role focuses on improving security operations, vulnerability management, audit readiness, identity governance, third‑party risk management, and overall security maturity across global IT environments.
  • Working closely with Infrastructure & Operations, Applications, and business stakeholders, the Analyst helps reduce enterprise risk, strengthen regulatory compliance, and ensure security controls are effective, repeatable, and defensible.

Responsibilities

  • Maintain and improve incident response playbooks and track response metrics and corrective actions.
  • Support on‑premises and cloud identity platforms and secure authentication controls.
  • Support enforcement of MFA, conditional access, and least‑privilege principles.
  • Maintain audit evidence, control documentation, and test artifacts.
  • Support proactive control monitoring to reduce repeat audit findings.
  • Support supplier security due diligence including questionnaires and review of SOC and ISO artifacts.
  • Support internal and external audits including SOX ITGC, ISO 27001, NIST CSF, NIST 800-171, and contractual requirements.
  • Partner with Procurement and Legal to support security obligations in vendor contracts.
  • Support IT emergency response, disaster recovery, and business continuity planning and exercises.
  • The IT Security & Compliance Analyst supports and operationalizes the organization's global information security and compliance program in support of mission‑critical, safety‑sensitive, and highly regulated aviation operations.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or equivalent professional experience.
  • 3+ years of experience in cybersecurity operations, compliance, vulnerability management, or audit support.
  • Practical experience supporting incident response, vulnerability remediation, and audit evidence production.
  • Experience working with third‑party service providers and regulated environments is desirable.

Nice to have

  • Security or audit‑related certifications preferred (CISSP, CISM, CISA, Security+, SSCP).

Skills

  • Strong understanding of information security controls and operational risk management.
  • Ability to translate security findings into clear remediation actions.
  • Strong documentation, analytical, and stakeholder communication skills.
  • Comfortable operating in regulated, mission‑critical operational environments.

Compensation

  • $171k-$800k

Benefits

  • PERSON SPECIFICATION: (minimum education requirements, key skills and experience)

This listing is sourced directly from Bristow's careers page and normalized into a canonical job model.