Systems Analyst, IT Security Risk Advisor
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
The Systems Analyst, IT Security Risk Advisor provides technical security risk, governance, and compliance expertise across Harris County information technology systems, networks, business applications, cloud solutions, and vendor-managed services. The position leads security reviews, identifies technology and regulatory risks, recommends mitigating controls, and develops risk-management processes and tools that support secure and compliant technology operations., * Lead cybersecurity risk reviews for technology projects, system and application upgrades, acquisitions, and other ad hoc initiatives; evaluate security exposures and determine whether appropriate controls are designed to mitigate identified risks.
- Provide technical security consulting to architects, business analysts, project managers, business owners, and other stakeholders regarding system architecture, cloud solutions, network design, applications, and security controls.
- Assess vendor-managed information technology services and cloud solutions to determine whether vendors meet minimum security requirements and to identify risks, required safeguards, and mitigating controls.
- Review technical and security information submitted through procurement and request-for-proposal processes; interpret vendor responses, evaluate architectural and security considerations, and provide risk-based recommendations to evaluation teams.
- Design and enhance security risk-management and control-development processes, including standard operating procedures, assessment methodologies, screening tools, and supporting documentation.
- Align risk-management practices and security controls with recognized frameworks, including NIST 800-53 and NIST 800-30, while considering organizational risk tolerance, operating capabilities, and budget constraints.
- Develop risk assessment workflows and provide training, technical guidance, and work direction to Governance, Risk, and Compliance staff and contractors.
- Develop control-testing approaches and lead security reviews of systems, applications, processes, data-center environments, and third-party relationships; identify exposures and recommend controls that are appropriate for the level of risk.
- Coordinate cybersecurity audit and regulatory (CJIS, PCI, HIPAA) assessment activities, including evidence collection, control validation, management responses, and corrective-action tracking.
- Evaluate security findings, assist with risk classification, and track remediation activities to support timely resolution of identified vulnerabilities and compliance concerns.
- Participate in cybersecurity incident response activities, including development of timelines, follow-up actions, lessons learned, and recommendations for process improvement.
- Provide information, analysis, and recommendations to management that support technology risk, security, compliance, vendor, and implementation decisions.
- Monitor changes in cybersecurity requirements, emerging threats, and technology practices and recommend updates to policies, standards, controls, and assessment methodologies.
- Serve as an escalation point for complex or high-risk technology reviews and advise leadership regarding risk acceptance, remediation, or implementation decisions.
- Lead security and risk reviews for artificial intelligence (AI), machine-learning, and generative AI solutions; evaluate data protection, privacy, access, model security, vendor, regulatory, transparency, and human-oversight risks, and recommend controls aligned with County policy and the NIST AI Risk Management Framework.
- Leadership and Decision-Making initiatives
- Provides direction to employees and contractors, including assigning work, providing technical guidance, establishing procedures, and delivering training and instruction.
- Exercises independent judgment in evaluating technology risks and recommending new or revised security approaches, methods, practices, and controls.
- May recommend postponing or stopping a technology implementation when significant control concerns or security risks require remediation before proceeding.
- May recommend eliminating a vendor or solution from consideration when risk analysis indicates that minimum security requirements are not met., Please provide the dates of employment during which you obtained experience working in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Provide the month and year that began and ended the experience ( Example: âJanuary 2020 - December 2025â ) If this experience is not clearly documented in the Work Experience section, your application will be disqualified. If you do not have this experience, type âN/Aâ in the space provided. 06
Do you have industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications?
- Yes
- No
Requirements
- Bachelors degree in Computer Science, Cybersecurity, or closely related field, * High School Diploma with industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications
Experience:
- Minimum five years of progressively responsible professional experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Experience must include evaluating technical environments and security controls, communicating risk-based recommendations, and leading projects, assessments, employees, or contractors.
Knowledge, Skills, and Abilities:
- Intermediate to advanced knowledge of end-to-end information technology environments, including networks, operating systems, applications, cloud computing, data management, and security architecture.
- Knowledge of information security risk management, controls governance, regulatory compliance, and methods for evaluating technology-related compliance requirements.
- Knowledge of common operating systems and technologies, including Windows, Linux/Unix, TCP/IP, identity management, encryption protocols, cloud security, and vendor management.
- Knowledge of security and compliance frameworks and standards such as CJIS, NIST 800-53, NIST 800-30, COBIT, ISO 27001, PCI DSS, and other applicable regulatory requirements
- Ability to analyze complex technical information, identify security and compliance risks, assess mitigating controls, and communicate risk-based recommendations.
- Strong written and verbal communication skills with the ability to explain technical concepts, findings, instructions, and recommendations to technical and nontechnical audiences.
- Ability to develop processes, procedures, risk-assessment tools, control tests, and technical documentation.
- Proficiency with Microsoft Office products, including advanced Microsoft Excel functions; familiarity with Microsoft Access and Microsoft 365 tools.
- Knowledge of AI governance and risk-management principles, including acceptable use, data privacy, model security, human oversight, transparency, and third-party AI risk., * Relevant information security or audit certifications are preferred, including CISSP, GIAC, CISA, CompTIA security certifications, or comparable industry credentials., * High School or GED diploma
- Associate Degree
- Bachelorâs Degree
- Masterâs Degree or higher
- None of the above
02
If you selected a college degree in response to the previous question, which of the following best describes your major?
- Computer Science
- Cybersecurity
- Other Related Field
- Unrelated Field
- N/A; No Degree
03
Please describe your educational background including level of education completed, area of study and completed major and minor programs. 04
Which of the following best describes your verifiable experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area?(To be considered, qualifying experience must be documented in your applicationâs employment history)
- Less than five (5) years
- Five (5) years but less than six (6) years
- Six (6) years but less than seven (7) years
- Seven (7) years or more
- I do not have this experience
Benefits & conditions
Harris County offers a highly competitive benefits program, featuring a comprehensive group health plan and defined benefit retirement plan. The following benefits are offered only to Harris County employees in regular (full-time) positions: Health & Wellness Benefits
- Medical Coverage
- Dental Coverage
- Vision Coverage
- Wellness Plan
- Life Insurance
- Long-Term Disability (LTD) Insurance
- Employee Assistance Program (EAP)
- Healthcare Flexible Spending Account
- Dependent Care Flexible Spending Account
Paid Time Off (PTO)
- Ten (10) days of vacation leave per year (accrual rate increases after 5 years of service)
- Eleven (11) County-observed holidays
- One (1) floating holiday per year
- Paid Parental Leave*
- Sick Leave
Retirement Savings Benefit
- 457 Deferred Compensation Plan
The following benefits are available to Harris County employees in full-time and select part-time positions:
- Professional learning & development opportunities
- Retirement pension (TCDRS defined benefit plan)
- Flexible work schedule*
-
METRO RideSponsor Program*
- Participation may vary by County department. The employee benefits plans of Harris County are extended to all eligible participants across various departments with the exception of the Harris County Community Supervision and Corrections Department, for which the cited Health & Wellness Benefits are administered through the State of Texas. In accordance with the Harris County Personnel Regulations, group health and related benefits are subject to amendment or discontinuance at any time. Harris County Commissioners Court reserves the right to make benefit modifications on the Countyâs behalf as needed. For plan details, visit the Harris County Benefits & Wellness website: 01
About the company
Harris County Universal Services (Universal Services) is transforming the way the County does business and seeking an Information Security Analyst, GRC to join our team. Universal Services is the enterprise IT solutions center for the departments and offices of Harris County, providing Information Technology, Public Safety and Justice Technologies, 311 Constituent Engagement Services, Fleet Services, and Records and Information Governance Services. Harris County is the third largest and most diverse county in the nation, with a population of more than 5.1million. Harris County Commissioners Court, the Countyâs governing body, directs a budget of more than $4 billion providing essential services including flood control, infrastructure, healthcare, housing, and justice administration. This is a great time to join Universal Services as we enhance critical services to Harris County residents and internal customers.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
How to Answer the Interview Question: âWhy Do You Want to Be a Software Engineer?â
Should senior developers refuse interview coding challenges?
How to Write a CV and Interview if You Don't Fully Qualify For The Job