Bristow Group, Inc

IT Security and Compliance Analyst

Bristow Group, Inc$80K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or equivalent experience.
  • Security or audit-related certifications preferred (CISSP, CISM, CISA, Security+, SSCP).
  • 3+ years of experience in cybersecurity operations, compliance, or vulnerability management.
  • Experience supporting incident response and audit evidence production.
  • Familiarity with third-party service providers and regulated environments is desirable.

Responsibilities

  • Monitor and investigate security events using various security tools.
  • Coordinate incident response activities including recovery and reviews.
  • Maintain incident response playbooks and track corrective actions.
  • Coordinate vulnerability scanning and validate results across environments.
  • Prioritize vulnerabilities and track remediation status with stakeholders.
  • Support identity platforms and manage access control processes.
  • Assist with internal and external audit support and compliance readiness.

Benefits

  • Professional development opportunities.
  • Access to the latest tools and technologies in cybersecurity.
  • Collaborative work environment with cross-departmental teams.
  • Support for continuing education and certifications.
Full Job Description
Job Description:

The IT Security & Compliance Analyst supports and operationalizes the organization's global information security and compliance program in support of mission-critical, safety-sensitive, and highly regulated aviation operations. The role focuses on improving security operations, vulnerability management, audit readiness, identity governance, third-party risk management, and overall security maturity across global IT environments.

Working closely with Infrastructure & Operations, Applications, and business stakeholders, the Analyst helps reduce enterprise risk, strengthen regulatory compliance, and ensure security controls are effective, repeatable, and defensible.

PRINCIPAL RESPONSIBILITIES:

Security Operations & Incident Response
  • Monitor, analyze, and investigate security events using SIEM, EDR, email, cloud, and endpoint security tools.
  • Coordinate incident response activities including containment, eradication, recovery, and post-incident reviews.
  • Maintain and improve incident response playbooks and track response metrics and corrective actions.


Vulnerability Management & Risk Reduction
  • Coordinate vulnerability scanning and validation across infrastructure, endpoint, cloud, and application environments.
  • Prioritize vulnerabilities based on severity, asset criticality, and exploitability.
  • Track remediation SLAs, exceptions, and risk acceptances; report status and trends to stakeholders.


Identity, Access & Security Controls
  • Support on-premises and cloud identity platforms and secure authentication controls.
  • Assist with joiner/mover/leaver processes, access reviews, and privileged access governance.
  • Support enforcement of MFA, conditional access, and least-privilege principles.


Compliance, Audit & Continuous Readiness
  • Support internal and external audits including SOX ITGC, ISO 27001, NIST CSF, NIST 800-171, and contractual requirements.
  • Maintain audit evidence, control documentation, and test artifacts.
  • Support proactive control monitoring to reduce repeat audit findings.
  • Assist with regulatory readiness including aviation-specific security requirements (e.g., EASA Part-IS).


Third-Party & Supplier Security
  • Support supplier security due diligence including questionnaires and review of SOC and ISO artifacts.
  • Track vendor remediation actions and reassessment schedules for higher-risk suppliers.
  • Partner with Procurement and Legal to support security obligations in vendor contracts.


Resilience, Business Continuity & Awareness
  • Support IT emergency response, disaster recovery, and business continuity planning and exercises.
  • Assist with security awareness initiatives and targeted training programs.


PERSON SPECIFICATION: (minimum education requirements, key skills and experience)

Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, or equivalent professional experience.
  • Security or audit-related certifications preferred (CISSP, CISM, CISA, Security+, SSCP).


Experience:
  • 3+ years of experience in cybersecurity operations, compliance, vulnerability management, or audit support.
  • Practical experience supporting incident response, vulnerability remediation, and audit evidence production.
  • Experience working with third-party service providers and regulated environments is desirable.


Skills:
  • Strong understanding of information security controls and operational risk management.
  • Ability to translate security findings into clear remediation actions.
  • Strong documentation, analytical, and stakeholder communication skills.
  • Comfortable operating in regulated, mission-critical operational environments.


About Bristow Group, Inc

Bristow Group Inc. is an American industrial aviation service provider based in Houston, Texas. The company provides helicopter services to the offshore energy industry and search-and-rescue (SAR) services, and also performs helicopter maintenance and repair services. Bristow has customers in the Americas, Europe, Africa, the Middle East, and Asia Pacific. The company was founded in 1955 and has grown through a series of mergers and acquisitions. Bristow has a fleet of over 300 aircraft and operates in over 10 countries.
Learn more about Bristow Group, Inc
Size
2,916 employees
Market Cap
$698.5 million
Industry
Net Income
-$20.7 million
Founded
1955
5 Year Trend
+36.8%
Revenue
$941.7 million
NASDAQ

Similar Jobs

More Jobs at Bristow Group, Inc

More Information Technology Jobs

Find similar IT Security and Compliance Analyst jobs: