IT Governance, Risk & Compliance Advisor
OC2 Occidental Chemical Corporation · Houston, Texas
Posted Oct 5, 2026 · Verified open Oct 9, 2026
Apply on the employer's siteFind more jobs like this on LandMeAbout the job
At OxyChem, our chemistry makes modern life possible, and it is our people who make the difference. We are a safety-first, purpose-driven team committed to innovation, environmental responsibility, and doing things the right way. If you are ready to contribute, elevate your skills, and take ownership of your career, Oxychem offers the opportunity to make a difference every day.
OxyChem, a Berkshire Hathaway company, is a leading producer of essential chemistry with operations in the U.S., Canada and Latin America. OxyChem’s products play an essential role in everyday life, supporting critical applications in water treatment, pharmaceuticals, healthcare, manufacturing, automotive, personal hygiene, and residential and commercial construction. OxyChem actively participates in the Occupational Safety and Health Administration Voluntary Protection Program, underscoring our commitment to safety. Headquartered in Dallas, Texas, OxyChem is a top three U.S. manufacturer of polyvinyl chloride, chlor-alkali and chlorinated organic chemicals, and calcium chloride. Visit oxychem.com for more information.
In a fast-paced industry that demands precision, we create a supportive workplace where the safety and well-being of our employees are paramount. We are committed to rewarding top performers, offering very competitive pay and benefits, and providing tremendous career development opportunities.
OxyChem is seeking an IT Audit & Governance, Risk & Compliance (GRC) Senior Analyst to strengthen the organization's cybersecurity posture through effective governance, risk management, compliance oversight, cybersecurity awareness, and security culture initiatives. This role serves as a key partner to IT, Internal Audit, Legal, Compliance, Human Resources, and business stakeholders to ensure cybersecurity risks are identified, assessed, managed, and communicated across the enterprise.
Key Responsibilities:
Governance, Risk & Compliance (GRC)
- Implement and maintain cybersecurity governance, risk management, and compliance programs aligned with business objectives and industry best practices.
- Conduct IT and business risk assessments and maintain risk registers aligned with frameworks such as NIST Cybersecurity Framework, ISO 27001, and other applicable standards.
- Track, manage, and report remediation activities and corrective action plans through successful closure.
- Support internal and external cybersecurity audits, assessments, and compliance reviews.
- Ensure compliance with applicable regulations, contractual obligations, and cybersecurity requirements, including MTSA, GDPR, and industry-specific standards.
- Review cybersecurity requirements within contracts, vendor agreements, exception requests, and compensating control documentation.
- Develop, monitor, and report cybersecurity Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and compliance metrics to management.
- Support the development, maintenance, and governance of cybersecurity policies, standards, procedures, and guidelines.
- Maintain cybersecurity risk registers and facilitate periodic risk reviews with business and technology stakeholders.
- Provide governance oversight for third-party cybersecurity risk management activities.
IT Audit & Compliance Management
- Serve as a primary cybersecurity liaison for Internal Audit, external auditors, assessors, and regulatory reviews.
- Coordinate evidence collection, documentation reviews, and audit responses.
- Assess control effectiveness and identify opportunities for strengthening cybersecurity governance and compliance processes.
- Support cybersecurity maturity assessments and benchmarking activities.
- Develop executive ready reporting on compliance status, audit findings, remediation progress, and cybersecurity risk exposure.
- Ensure continuous audit readiness through effective documentation, control monitoring, and governance practices.
Security Awareness & Culture
- Design, implement, and continuously improve the enterprise Cybersecurity Awareness Program.
- Manage phishing simulations, awareness campaigns, newsletters, training initiatives, and targeted education for high-risk user groups.
- Develop metrics and reporting to measure awareness program effectiveness and organizational security culture maturity.
- Partner with Human Resources, Communications, and business leaders to promote a strong cybersecurity culture.
- Identify opportunities to improve employee engagement and reduce human-related cybersecurity risks.
- Deliver cybersecurity awareness presentations and briefings to employees, management, and leadership teams.
Technical & Operational Support
- Monitor cyber threat intelligence sources, including government and industry advisories, and communicate relevant risks to stakeholders.
- Coordinate cybersecurity assessments, maturity reviews, vulnerability assessments, and penetration testing activities.
- Manage relationships with cybersecurity service providers, assessment partners, and third-party risk vendors.
- Collaborate with infrastructure, application, cloud, and system engineering teams to support implementation of security controls and remediation activities.
- Support the evaluation of emerging technologies and cybersecurity risks associated with cloud adoption, artificial intelligence (AI), and digital transformation initiatives.
- Assist in cybersecurity incident reviews, lessons learned activities, and risk-based remediation planning.
Required Qualifications:
- Bachelor's degree or relevant years of experience in Cyber Security, Information Systems, Computer Science, Engineering, Finance or a related field.
- CRISC, CISM, CISA, CGRC, or other governance, risk, and compliance certifications.
- 5+ years of experience in cybersecurity, governance, risk, compliance, information security, audit, privacy, or third-party risk management.
- Experience leading compliance programs, audits, risk assessments, or control implementation efforts.
- Experience using and supporting GRC, audit-management, vendor-risk-management, and workflow tools.
- Experience managing policies, control documentation, audit evidence, and remediation activities.
- Strong project-management skills, including the ability to prioritize competing compliance initiatives and drive cross-functional accountability.
- Exceptional written, verbal, and stakeholder-management skills.
- Ability to communicate risk and compliance requirements effectively to both technical and non-technical audiences.
- Ability to travel up to 20%.
Preferred Certifications:
- Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, CDPSE, CIPM, CIPP/US, CIPP/E, or similar.
Fraud Statement:
- It has come to our attention that various individuals and/or organizations are contacting people falsely pretending to recruit on behalf of OxyChem. Please be aware that these recruiting scams and communications do not originate, nor are they associated with our recruitment process. All OxyChem job postings and offers will require a completed application through our company website.
- OxyChem does not charge a fee at any stage of the recruiting process. We will never:
- Ask you to pay for applications, interviews, meetings, processing, training or for any other fees
- Use recruiting or placement agencies that charge candidates an advance fee of any kind or
- Request personal information such as passport and bank account details at an early stage of our recruitment process.
We recommend against responding to unsolicited business propositions or offers from people you don't know. Do not disclose your personal or financial details. If you believe you have been the victim of a recruiting scam, please contact your local police department.