We are seeking an experienced and strategic Cybersecurity Sr. Manager to lead our security operations across both enterprise IT and Operational Technology (OT/ICS) environments. This is a high-impact leadership role responsible for protecting critical systems, enabling resilient operations, and advancing our cybersecurity maturity in alignment with business goals and industry best practices.
You will lead security operations, threat and vulnerability management, and security culture initiatives while driving continuous improvement in detection, response, and risk reduction. This role offers the opportunity to shape the future of cybersecurity in a global organization operating in complex, high-consequence environments.
Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
Essential
You will lead security operations, vulnerability management, Data Privacy, and threat response across IT and OT environments—ensuring our organization is protected, resilient, and aligned with modern cybersecurity standards.
Lead Security Operations
Provide oversight and direction for both internal security teams and third-party SOC/MDR partners
Ensure effective 24x7 monitoring, detection, and response to cyber threats
Continuously enhance SOC capabilities, including SIEM, SOAR, automation, and threat intelligence
Data Privacy
Establish and lead Oceaneering's Data Privacy and Governance function
Responsible for defining data protection policies, governance frameworks, privacy architecture standards, and investigative processes that ensure confidentiality, integrity, availability, and appropriate use of enterprise data
Provide strategic direction and oversight for data sovereignty, developing the governance structure, controls, and standards that business and technology teams follow across the organization
Drive Vulnerability & Patch Management (TVM)
Own the enterprise Threat & Vulnerability Management (TVM) program across IT and OT
Establish governance for patch management and risk-based remediation
Prioritize vulnerabilities based on business risk and ensure timely resolution
Oversee Incident Response & Threat Hunting
Lead enterprise incident response and proactive threat hunting capabilities
Ensure readiness through tested playbooks and crisis response processes
Drive continuous improvement through post-incident reviews and lessons learned
Optimize Security Tools & Investments
Manage the lifecycle, performance, and optimization of security tools and platforms
Align capabilities to the NIST Cybersecurity Framework (CSF)
Evaluate effectiveness, reduce redundancy, and ensure cost-efficient security investments
Strengthen Security Awareness & Culture
Oversee enterprise-wide security awareness and phishing simulation programs
Reduce human risk through targeted training and behavior-driven initiatives
Track effectiveness through measurable outcomes (e.g., phishing resilience, engagement)
Development and execution of table top exercises to verify ownership
Align Security with Business & Risk
Partner with IT, OT, and business leaders to integrate security into operations
Align cybersecurity strategy with business priorities, risk tolerance, and resilience goals
Required
Minimum 15 years of cybersecurity experience, including leadership in security operations
Minimum 10 years’ experience in SOC operations, incident response, and vulnerability management
Minimum 10 years’ experience working with or overseeing third-party security providers (MDR/SOC)
Proven ability to align security strategy, tooling, and operations with business outcomes
Deep knowledge of frameworks such as NIST CSF and/or ISO 27001
Strong leadership, communication, and stakeholder engagement skills
Certifications such as CISSP or CISM
Desired
Experience in energy, oil & gas, or critical infrastructure environments
Familiarity with OT/ICS security (e.g., NIST 800-82, IEC 62443)
Experience managing security tooling strategy, optimization, and cost governance
Exposure to modern security technologies (SIEM, SOAR, EDR, MDR, cloud security)