Get more replies from employers
Send a job-specific resume in minutes.
Texas Education Agency seeks a seasoned GRC Manager to lead cybersecurity governance, risk, and compliance efforts across the agency. You will collaborate with risk management, security operations, and agency leaders to advance a comprehensive control framework and enterprise risk program.
The role focuses on policy creation, third-party risk, regulatory alignment with TAC 202 and NIST, and executive reporting.
The Texas Education Agency (TEA) oversees primary and secondary public education in Texas and is committed to improving outcomes for all public school students by providing leadership, guidance, and support to school systems across the state.
The Office of Information Technology works closely with all agency divisions to implement innovative technology solutions in a cost-efficient manner that supports the goals and priorities of the Texas Education Agency. The Office of IT provides efficient technology solutions and stellar customer services to internal staff, 20 Educational Service Centers, and 1,200-plus public-school districts and charter schools. The following services are provided by IT: leadership on IT initiatives; guidance on security/policy issues; new application development/enhancements; software acquisition; technical support; assistance with technical sections of purchasing documents such as Request for Information (RFI), Request for Offers (RFO), Request for Proposals (RFP); and oversight on the data collection process which helps to support and improve outcomes for all of Texas' 5 million-plus students.
The Cybersecurity Governance Risk and Compliance (GRC) Manager performs advanced (senior-level) information security and cybersecurity analysis work. The GRC Manager reports to the Executive Director of IT Administration and Compliance in the Office of Information Technology and will work closely with the Chief Information Security Officer and the Cybersecurity Operations Manager. The GRC Manager serves as the lead subject matter expert for GRC initiatives, collaborating closely with risk management, security operations and leaders across the agency. The GRC Manager is responsible for overseeing enterprise risks, conducting risk analyses, implementing and advancing policies and a comprehensive control framework to execute the GRC strategy.
This role will oversee the administration of standards and controls, risk management, third-party risk, baseline security controls and technology compliance initiatives. The GRC Manager will be solution oriented, and have a strong background in cybersecurity principles, risk management frameworks, and regulatory compliance. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. The GRC Manager will also work with internal and external team members to support the K12 Cybersecurity initiative by working to enhance cybersecurity in our Texas school systems. Employees at this level may independently perform the most complex information security and cybersecurity work and advise management and users regarding security configurations and procedures.
Job duties are not limited to the essential functions mentioned below. You may perform other functions as assigned.
1. Cybersecurity Governance Framework: responsible for creating, approving, and enforcing security policies, standards, and procedures that align with strategic business goals and the overall risk appetite of the organization, ensuring alignment with TAC 202 requirements and best practices in accordance with NIST. The Cybersecurity GRC Manager will implement process improvements using GRC tools and methodologies to drive productive gains.
2. Oversee Third Party and Vendor Risk Assessments: responsible for establishing a comprehensive risk management program that regularly conducts formal risk assessments. Additionally, this role is responsible for evaluating the effectiveness of current controls and recommending mitigation strategies based on risk severity.
3. Ensure Continuous Regulatory and Policy Compliance: responsible for ensuring adherence to internal polices, as well as external regulations and legal mandates such as TAC 202 and NIST. The GRC Manager will establish and maintain a continuous monitoring program for tracking and resolving non-compliance issues.
4. Executive Level Reporting and Communication: coordinate with stakeholders to communicate emerging risks across the organization and implement effective risk mitigation strategies.
5. Team Management and Supervision: guide the team to align with security, audit, and risk management efforts in ongoing security program assessments. This role will also provide guidance to team members to ensure compliance with relevant laws and regulations.
Education: Graduation from an accredited four-year college or university
Degree field(s): Cybersecurity, Risk Management, Computer Science, Audit, Information Technology Security, Computer Engineering, Computer Information Systems
Required Licenses: One or more of the following: CISSP, CISM, CGRC, CRISC, CISA
Experience: At least six (6) years of experience in Cybersecurity, Risk Management, or Audit, including experience leading teams in handling both legacy and emerging technologies to manage business risk and enforce security controls
Substitutions: An advanced degree may substitute for two years of required experience
New hires, rehires, and internal hires will typically receive a starting salary between the posted minimum and the average pay of employees within the same classification. Offers are based on the candidate's experience and qualifications and consider internal pay equity across employees performing similar work.
The top half of the posted salary range is generally reserved for candidates whose qualifications exceed the role's requirements. The maximum of the range is typically reserved for candidates who significantly exceed the required and preferred qualifications.
TEA employees receive a comprehensive benefits package through the State of Texas and the Employee Retirement System of Texas (ERS), supporting health, financial security, and work-life balance.
To learn more about benefits available to State of Texas employees, please review the State of Texas Employee Benefits brochure and visit the TEA Compensation and Benefits page.
Applicants eligible for Military Employment Preference will be considered in accordance with applicable state and federal laws and regulations.
To explore how military experience may align with this role, applicants may review Military Occupational Specialty (MOS) codes within the State's Position Classification Plan. Please refer to the Military Crosswalk and select the occupational category that most closely corresponds with the classification listed in this job posting.
TEA is an equal opportunity employer and complies with all applicable federal and state nondiscrimination laws. Employment decisions are made without regard to race, religion, color, national origin, sex, disability, age, or veteran status.
TEA does not sponsor or assume sponsorship of employment visas.
This position requires the applicant to meet Agency standards and criteria which may include passing a pre-employment criminal background check, prior to being offered employment by the Agency.
To learn more about working at TEA, including hiring timelines, process details, and candidate resources, please visit the Careers at TEA page.
Due to the high volume of applications, we are unable to accept phone calls or respond to all email inquiries. Only candidates selected for an interview will be contacted.
To help ensure you receive updates regarding your application, please add capps.recruiting@cpa.texas.gov and @tea.texas.gov to your safe sender's list.