Information Security GRC Systems Analyst

Harris County

Houston (TX)

Hybrid

USD 85,000 - 125,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Harris County Universal Services is seeking an Information Security Analyst – Governance, Risk & Compliance (GRC) to protect information systems across cloud, hybrid, and on‑premise environments. You will conduct security risk assessments, develop policies, and coordinate with vendors and internal teams to ensure regulatory compliance with CJIS, HIPAA, PCI‑DSS, and Privacy Act.

Strong communication and mentoring skills are required, with the ability to present risk findings to leadership and

Qualifications

  • Bachelor’s degree in IT, cybersecurity, or a related field.
  • Experience with governance, risk, and compliance (GRC) tools.
  • Knowledge of CJIS, HIPAA, PCI-DSS, and Privacy Act.
  • Ability to conduct security risk assessments for cloud/hybrid/on‑premise systems.
  • Strong communication and training capabilities.

Responsibilities

  • Serve as SME on cloud security with emphasis on Azure.
  • Conduct security risk assessments for cloud, hybrid, and on‑premise IT solutions.
  • Develop, manage, and coordinate security risk assessments for third-party vendors and internally developed/managed applications.
  • Assess and prioritize information security risk; facilitate regulatory compliance.
  • Plan, research, and evaluate cybersecurity architecture for infrastructure projects.
  • Identify security design gaps and propose improvements.
  • Lead evaluation, design, and implementation of new security solutions.
  • Develop and maintain IT security policies, standards, and guidelines.

Skills

Azure Cloud Security
Security Risk Assessments
GRC Tools
CJIS Compliance
HIPAA Compliance
PCI-DSS Compliance
Vendor Management
Security Policy Development
Security Training / Mentoring

Education

Bachelor’s degree in Information Technology, Cybersecurity, or related field

Tools

GRC Tools
Microsoft 365
Power BI
SharePoint

Job description

About Harris County and Universal Services:

Harris County Universal Services is transforming the way the County does business and seeking a Information Security GRC Systems Analyst to join our team.

Universal Services is the enterprise IT solutions center for the departments and offices of Harris County, providing Information Technology, Public Safety and Justice Technologies, 311 Constituent Engagement Services, Fleet Services, and Records and Information Governance Services.

Harris County is the third largest and most diverse county in the nation, with a population of more than 4.7 million. Harris County Commissioners Court, the County’s governing body, directs a budget of more than $4 billion providing essential services including flood control, infrastructure, healthcare, housing, and justice administration.

This is a great time to join Universal Services as we enhance critical services to Harris County residents and internal customers.

Position Overview:

The Information Security Analyst – Governance, Risk & Compliance (GRC) performs all procedures necessary to ensure the security of information and information systems, protecting systems from intentional or inadvertent access, alteration, or destruction.

Duties and Responsibilities:
  • Serve as a subject matter expert and/or provide direction on processes, projects, and issues related to Cloud Security, with emphasis on Microsoft Azure.
  • Conduct security risk assessments for cloud, hybrid, and on-premise IT solutions and infrastructure.
  • Utilize cloud security controls to enhance security posture and research emerging threats affecting cloud and hybrid cloud environments.
  • Develop, manage, and coordinate security risk assessments for:
    • Third-party vendors
    • Internally developed/managed applications and systems
    • Ensuring alignment with the Confidentiality, Integrity, and Availability (CIA) triad
  • Assess and prioritize information security risk; facilitate compliance with regulatory requirements and internal security policies.
  • Plan, research, and evaluate cybersecurity architecture for infrastructure projects (cloud and on-premise).
  • Identify security design gaps in proposed architectures and recommend improvements.
  • Lead the evaluation, design, and implementation of new security solutions and technologies.
  • Develop and maintain IT security policies, standards, procedures, and guidelines, including exception management processes.
  • Create policy drafts, procedures, educational content, strategy/technology roadmaps, metrics packages, RFPs/RFOs, project plans, communications, and executive-level presentations.
  • Design and implement tools/processes to monitor and govern security control effectiveness.
  • Maintain dashboards and reports to communicate security risks and compliance status.
  • Present cybersecurity risks and remediation plans to stakeholders; track and ensure timely closure of open issues.
  • Participate in ongoing updates and management of the Harris County Cybersecurity Framework and cybersecurity policies.
  • Balance business needs with security priorities and communicate risk effectively to leadership.
  • Evaluate and assist with the adoption of emerging security tools and solutions.
  • Lead or serve as a subject matter expert on complex, multi-disciplinary security projects.
  • Coach and mentor junior managerial and technical staff.
  • Conduct cybersecurity training and awareness sessions as needed.
  • Perform other duties as assigned.
Harris County is an Equal Opportunity Employer

https://hrrm.harriscountytx.gov/Pages/EqualEmploymentOpportunityPlan.aspx

If you need special services or accommodations, please call (713) 274-5445 or email ADACoordinator@bmd.hctx.net.

This position is subject to a criminal history check. Only relevant convictions will be considered and, even when considered, may not automatically disqualify the candidate.

Education:
  • Minimum: High School diploma or G.E.D. from an accredited educational institution.
Knowledge, Skills, and Abilities:
  • Strong interpersonal and communication skills; able to build collaborative relationships across departments.
  • Ability to analyze complex problems, assess risk, and recommend effective, business-aligned solutions.
  • A self-starter with passion for cybersecurity, adaptability, and a team-oriented approach.
  • Working knowledge of security regulations such as CJIS, HIPAA, PCI-DSS, and Privacy Act.
  • Experience mentoring others and conducting security training sessions.

Applicants for this position will be subject to a criminal background check that includes being fingerprinted. This applies to any position with network access to Criminal Justice Information Services (CJIS) or access to an area where CJIS is received, maintained or stored either manually or electronically (i.e. custodian, maintenance).

Automatic Disqualification:
  • Convictions, probation, or deferred adjudication for any Felony, and any Class A Misdemeanor
  • Convictions, probation, or deferred adjudication for a Class B Misdemeanor, if within the previous 10 years
  • Open arrest for any criminal offense (Felony or Misdemeanor)
  • Family Violence conviction
NOTE:

Qualifying education, experience, knowledge and skills must be documented on your job application. You may attach a resume to the application as supporting documentation but ONLY information stated on the application will be used for consideration. "See Resume" will not be accepted for qualifications.

  • Bachelor’s degree in Information Technology, Cybersecurity, or related field.
  • Experience consulting with stakeholders on security best practices, network controls, and regulatory requirements.
  • Proficiency with Governance, Risk & Compliance (GRC) tools.
  • Familiarity with productivity platforms such as Microsoft 365 (Word, Excel, PowerPoint, Outlook), Teams, SharePoint, QuickBase, and Power BI.
Location:
  • 406 Caroline St., Houston, TX 77002
Work Arrangement:
  • Hybrid
Employment may be contingent on passing a drug screen and meeting other standards.

Due to a high volume of applications positions may close prior to the advertised closing date or at the discretion of the Hiring Department.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Risk Advisor, Governance, Risk, & Compliance (GRC)
IT Security Risk Advisor, Governance, Risk, & Compliance (GRC)

Harris County • Houston (TX)

On-site
USD 90,000 - 120,000
Manager, Threat & Vulnerability
Manager, Threat & Vulnerability

Harris County • Houston (TX)

Hybrid
USD 140,000 - 190,000
Information Security Specialist (Remote)
Information Security Specialist (Remote)

Harris Computer • North Dakota

On-site
USD 80,000 - 110,000
Competitive compensation package
Health Insurance (medical, dental, vision)
Paid Vacation
+1
Sr. Manager, Service Desk
Sr. Manager, Service Desk

Harris County • Houston (TX)

On-site
USD 120,000 - 160,000
Cybersecurity Analyst II
Cybersecurity Analyst II

Texas Health and Human Services • Austin (TX)

On-site
USD 65,000 - 84,000
100% paid employee health insurance
Defined benefit pension plan
Generous time off benefits
+1
GRC Systems Analyst: Cloud Security & Risk (Hybrid)
GRC Systems Analyst: Cloud Security & Risk (Hybrid)

Harris County • Houston (TX)

Hybrid
USD 85,000 - 125,000
Strategic IT Security Risk Advisor
Strategic IT Security Risk Advisor

Harris County • Houston (TX)

On-site
USD 90,000 - 120,000
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

Texas Health and Human Services • Austin (TX)

Hybrid
USD 78,000 - 116,000
Health insurance
Pension plan
Technical Security Risk & Governance Analyst
Technical Security Risk & Governance Analyst

Mbi Llc • Harrisburg

Hybrid
USD 80,000 - 100,000
Hybrid/telework eligibility
Participation in after-hours change windows or incident support