> Markdown version of [/jobs/ext/3347876-systems-analyst-it-security-risk-advisor](https://www.wearedevelopers.com/jobs/ext/3347876-systems-analyst-it-security-risk-advisor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Analyst, IT Security Risk Advisor - **Company:** Harris County Services Inc - **Location:** Houston, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Excel, Microsoft Windows, Artificial Intelligence, Business Software, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), CompTIA Security+, Cyber Security, Data Centers, Linux, Cryptographic Protocols, Identity and Access Management, Machine Learning, Microsoft Office, Network Planning and Design, PCI Data Security Standards, Cloud Services, Systems Architecture, TCP/IP, Office365, Information Technology, Data Management - **Published:** September 17, 2026 - **Apply:** https://www.dice.com/job-detail/125e8c22-4704-4955-b724-f8503fa376c2 ## About the Role * Bachelors degree in Computer Science, Cybersecurity, or closely related field, * High School Diploma with industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications Experience: * Minimum five years of progressively responsible professional experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Experience must include evaluating technical environments and security controls, communicating risk-based recommendations, and leading projects, assessments, employees, or contractors. Knowledge, Skills, and Abilities: * Intermediate to advanced knowledge of end-to-end information technology environments, including networks, operating systems, applications, cloud computing, data management, and security architecture. * Knowledge of information security risk management, controls governance, regulatory compliance, and methods for evaluating technology-related compliance requirements. * Knowledge of common operating systems and technologies, including Windows, Linux/Unix, TCP/IP, identity management, encryption protocols, cloud security, and vendor management. * Knowledge of security and compliance frameworks and standards such as CJIS, NIST 800-53, NIST 800-30, COBIT, ISO 27001, PCI DSS, and other applicable regulatory requirements * Ability to analyze complex technical information, identify security and compliance risks, assess mitigating controls, and communicate risk-based recommendations. * Strong written and verbal communication skills with the ability to explain technical concepts, findings, instructions, and recommendations to technical and nontechnical audiences. * Ability to develop processes, procedures, risk-assessment tools, control tests, and technical documentation. * Proficiency with Microsoft Office products, including advanced Microsoft Excel functions; familiarity with Microsoft Access and Microsoft 365 tools. * Knowledge of AI governance and risk-management principles, including acceptable use, data privacy, model security, human oversight, transparency, and third-party AI risk., * Relevant information security or audit certifications are preferred, including CISSP, GIAC, CISA, CompTIA security certifications, or comparable industry credentials., * High School or GED diploma * Associate Degree * Bachelor's Degree * Master's Degree or higher * None of the above 02 If you selected a college degree in response to the previous question, which of the following best describes your major? * Computer Science * Cybersecurity * Other Related Field * Unrelated Field * N/A; No Degree 03 Please describe your educational background including level of education completed, area of study and completed major and minor programs. 04 Which of the following best describes your verifiable experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area?(To be considered, qualifying experience must be documented in your application's employment history) * Less than five (5) years * Five (5) years but less than six (6) years * Six (6) years but less than seven (7) years * Seven (7) years or more * I do not have this experience ## Description The Systems Analyst, IT Security Risk Advisor provides technical security risk, governance, and compliance expertise across Harris County information technology systems, networks, business applications, cloud solutions, and vendor-managed services. The position leads security reviews, identifies technology and regulatory risks, recommends mitigating controls, and develops risk-management processes and tools that support secure and compliant technology operations., * Lead cybersecurity risk reviews for technology projects, system and application upgrades, acquisitions, and other ad hoc initiatives; evaluate security exposures and determine whether appropriate controls are designed to mitigate identified risks. * Provide technical security consulting to architects, business analysts, project managers, business owners, and other stakeholders regarding system architecture, cloud solutions, network design, applications, and security controls. * Assess vendor-managed information technology services and cloud solutions to determine whether vendors meet minimum security requirements and to identify risks, required safeguards, and mitigating controls. * Review technical and security information submitted through procurement and request-for-proposal processes; interpret vendor responses, evaluate architectural and security considerations, and provide risk-based recommendations to evaluation teams. * Design and enhance security risk-management and control-development processes, including standard operating procedures, assessment methodologies, screening tools, and supporting documentation. * Align risk-management practices and security controls with recognized frameworks, including NIST 800-53 and NIST 800-30, while considering organizational risk tolerance, operating capabilities, and budget constraints. * Develop risk assessment workflows and provide training, technical guidance, and work direction to Governance, Risk, and Compliance staff and contractors. * Develop control-testing approaches and lead security reviews of systems, applications, processes, data-center environments, and third-party relationships; identify exposures and recommend controls that are appropriate for the level of risk. * Coordinate cybersecurity audit and regulatory (CJIS, PCI, HIPAA) assessment activities, including evidence collection, control validation, management responses, and corrective-action tracking. * Evaluate security findings, assist with risk classification, and track remediation activities to support timely resolution of identified vulnerabilities and compliance concerns. * Participate in cybersecurity incident response activities, including development of timelines, follow-up actions, lessons learned, and recommendations for process improvement. * Provide information, analysis, and recommendations to management that support technology risk, security, compliance, vendor, and implementation decisions. * Monitor changes in cybersecurity requirements, emerging threats, and technology practices and recommend updates to policies, standards, controls, and assessment methodologies. * Serve as an escalation point for complex or high-risk technology reviews and advise leadership regarding risk acceptance, remediation, or implementation decisions. * Lead security and risk reviews for artificial intelligence (AI), machine-learning, and generative AI solutions; evaluate data protection, privacy, access, model security, vendor, regulatory, transparency, and human-oversight risks, and recommend controls aligned with County policy and the NIST AI Risk Management Framework. * Leadership and Decision-Making initiatives * Provides direction to employees and contractors, including assigning work, providing technical guidance, establishing procedures, and delivering training and instruction. * Exercises independent judgment in evaluating technology risks and recommending new or revised security approaches, methods, practices, and controls. * May recommend postponing or stopping a technology implementation when significant control concerns or security risks require remediation before proceeding. * May recommend eliminating a vendor or solution from consideration when risk analysis indicates that minimum security requirements are not met., Please provide the dates of employment during which you obtained experience working in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Provide the month and year that began and ended the experience ( Example: "January 2020 - December 2025" ) If this experience is not clearly documented in the Work Experience section, your application will be disqualified. If you do not have this experience, type "N/A" in the space provided. 06 Do you have industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications? * Yes * No ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Quick guide: How to write a Software Developer CV](https://www.wearedevelopers.com/magazine/37-quick-guide-how-to-write-a-software-developer-cv) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Answer the Interview Question: “Why Do You Want to Be a Software Engineer?”](https://www.wearedevelopers.com/magazine/392-how-to-answer-the-interview-question-why-do-you-want-to-be-a-software-engineer) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)