Jobs · Information Technology · Texas

Cybersecurity Governance & Risk Analyst

Texas Health and Human Services · Austin, TX · 1 mo ago
Information Technology$7k–$10k/moFull-time

Location: Austin, TX

About the role

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. This position performs senior-level security work with emphasis on cloud security, web application protection, and governance, risk, and compliance (GRC). The role supports on-premises and cloud environments by evaluating, implementing, and monitoring security controls to protect agency systems and data.

The Governance & Risk Analyst leads the enterprise cybersecurity governance framework and enterprise risk-management activities to ensure full alignment with legislative mandates, NIST 800-53, HIPAA, and State of Texas DIR mandates. This position provides senior-level expertise in secure architecture standards, vendor risk management, and data governance. The Analyst advises on regulatory changes, develops the enterprise system risk posture, stays current with industry best practices and emerging technologies, participates in compliance and regulatory audits, and supports the implementation of enterprise security improvements.

This position serves as a critical architect of the agency’s security policy framework, ensuring that every vendor, system architecture, and data flow aligns with legislative requirements and adheres to agency governance standards. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment.

Responsibilities

  • Cyber Governance – 30%
    • Performs reviews and risk management for vendors, system architectures, and data flows to advise and help teams comply with governance and regulatory standards.
    • Reviews regulatory and legislative changes and develops roadmaps for required updates to policy and governance structures.
    • Ensures alignment with NIST 800-53, State of Texas DIR mandates, HIPAA, TAC 202, and agency legislative requirements.
    • Using established risk management methodologies, identifies enterprise policy or control needs, and evaluates the effectiveness of security solutions across assigned governance areas.
  • Enterprise Risk Management – 25%
    • Develops and maintains the enterprise system risk posture, including risk identification, assessment, metrics, and documentation.
    • Oversees vendor risk management activities, including third-party assessments, contract security requirements, and ongoing monitoring.
    • Ensures risk-management practices are aligned with agency objectives and federal/state requirements.
    • Develops vendor, procurement, or supply chain training. Promotes secure system and data safeguards.
  • Security Architecture, Advisory, & Collaboration – 25%
    • Provides senior-level guidance on secure architecture, cloud security, and application protection; evaluates and monitors security controls to protect agency systems and data.
    • Advises programs and technical teams on security technical compliance, governance requirements; supports enterprise security improvement initiatives.
    • Uses established standards and processes to adequately protect Health and Human Services (HHS) personnel, facilities, cloud infrastructure, information, and business operations.
    • Provides leadership and mentorship to other security analysts, offering guidance in performing assessments, implementing controls, and carrying out security functions.
  • Program Oversight & Strategy – 10%
    • Incorporates audit findings and identified security gaps into remediation planning; assists with special projects, documentation updates, and process improvements as assigned.
    • Reviews project charters, provides input on strategic initiatives, and assists with planning activities that strengthen the agency’s cybersecurity posture.
  • Other duties – 10%
    • Performs additional cybersecurity, governance, and risk-related tasks as assigned, including supporting special projects, contributing to process improvements, and assisting with agency initiatives that enhance overall security posture.

Requirements

  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another.
  • At least 5+ years of experience in information technology, security risk, management, assessment, auditing, project management, or consulting.
  • Experience in researching, authoring, or supporting the development of information security policies and standards.
  • Experience developing security and risk performance metrics and reporting dashboards for executive, business, and technical audiences.

Knowledge, Skills, and Abilities

  • Information security risk assessment and security assessment methodologies, processes, and audit practices.
  • Security program policies, standards, controls, and procedural requirements.
  • Networking, operating systems, applications, databases, and related technologies, including wireless and mobile environments.
  • Incident response concepts, practices, and procedures.
  • Secure Software/System Development Lifecycle (S-SDLC) methodologies.
  • Regulatory and compliance requirements, including HIPAA/HITECH, PCI, SOX, TAC 202, IRS Publication 1075, Texas Business and Commerce Code, and Texas Health and Safety Code.
  • Security and risk management frameworks such as NIST, SANS, HITRUST, ISO, and COBIT.

Skill In:

  • Written and verbal communication.
  • Analyzing and solving complex problems and quickly understanding technical concepts.
  • Developing, implementing, and maintaining information security policies, standards, and controls.
  • Performing risk assessments, security assessments, and audits.
  • Evaluating risks and identifying mitigation strategies, including defining compensating controls.

Ability To:

  • Interpret and apply regulatory, policy, and security framework requirements.
  • Communicate technical information to both technical and non-technical audiences.
  • Work collaboratively with diverse teams and guide others in information security practices.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Manager (CISM)
  • Global Information Assurance Certification (GIAC)
  • Project Management Professional (PMP)

Benefits

Our comprehensive benefits package includes:

  • 100% paid employee health insurance for full-time eligible employees.
  • A defined benefit pension plan.
  • Generous time off benefits.
  • Numerous opportunities for career advancement.

Explore more details on the Benefits of Working at HHS webpage.

Pay

Salary Range: $7,015.16 - $10,472.33 per month

Schedule

  • Full-time
  • Day shift
  • Not eligible for telework
  • Regular, predictable attendance is required following agency leave policy.

This position is open to permanent residents or US citizens only. Candidates will be subject to a pre-employment security review to determine employment eligibility. This is an onsite position in Austin, TX. Any employment offer is contingent upon available budgeted funds and background check.

Similar jobs