Harris County logo

IT Security Risk Advisor, Governance, Risk, & Compliance (GRC)

Harris County

Houston, TXFull-timePosted 4 days agoStill listed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Houston, TX
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Systems Analyst, IT Security Risk Advisor provides technical security risk, governance, and compliance expertise across Harris County IT systems, networks, applications, cloud solutions, and vendor‑managed services, leading reviews, identifying risks, and developing risk‑management processes and tools.

Skills & qualifications

RequiredNice to have

Skills

WindowsLinux/UnixTCP/IPIdentity ManagementEncryption ProtocolsCloud SecurityVendor ManagementMicrosoft OfficeMicrosoft ExcelMicrosoft AccessMicrosoft 365AI GovernanceRisk‑Management Principles

Qualifications

Bachelors Degree in Computer Science, Cybersecurity, or Related FieldHigh School Diploma With Industry-Recognized CertificationsMinimum Five Years of Progressive IT Security and Risk Management ExperienceRelevant Information Security or Audit Certifications

Full job description

About Harris County and Universal Services: Harris County Universal Services (Universal Services) is transforming the way the County does business and seeking an Information Security Analyst, GRC to join our team.

Universal Services is the enterprise IT solutions center for the departments and offices of Harris County, providing Information Technology, Public Safety and Justice Technologies, 311 Constituent Engagement Services, Fleet Services, and Records and Information Governance Services.

Harris County is the third largest and most diverse county in the nation, with a population of more than 5.1million. Harris County Commissioners Court, the County’s governing body, directs a budget of more than $4 billion providing essential services including flood control, infrastructure, healthcare, housing, and justice administration.

This is a great time to join Universal Services as we enhance critical services to Harris County residents and internal customers.

Position Overview The Systems Analyst, IT Security Risk Advisor provides technical security risk, governance, and compliance expertise across Harris County information technology systems, networks, business applications, cloud solutions, and vendor-managed services. The position leads security reviews, identifies technology and regulatory risks, recommends mitigating controls, and develops risk-management processes and tools that support secure and compliant technology operations.

Duties and Responsibilities:

  • Lead cybersecurity risk reviews for technology projects, system and application upgrades, acquisitions, and other ad hoc initiatives; evaluate security exposures and determine whether appropriate controls are designed to mitigate identified risks.

  • Provide technical security consulting to architects, business analysts, project managers, business owners, and other stakeholders regarding system architecture, cloud solutions, network design, applications, and security controls.

  • Assess vendor-managed information technology services and cloud solutions to determine whether vendors meet minimum security requirements and to identify risks, required safeguards, and mitigating controls.

  • Review technical and security information submitted through procurement and request-for-proposal processes; interpret vendor responses, evaluate architectural and security considerations, and provide risk-based recommendations to evaluation teams.

  • Design and enhance security risk-management and control-development processes, including standard operating procedures, assessment methodologies, screening tools, and supporting documentation.

  • Align risk-management practices and security controls with recognized frameworks, including NIST 800-53 and NIST 800-30, while considering organizational risk tolerance, operating capabilities, and budget constraints.

  • Develop risk assessment workflows and provide training, technical guidance, and work direction to Governance, Risk, and Compliance staff and contractors.

  • Develop control-testing approaches and lead security reviews of systems, applications, processes, data-center environments, and third-party relationships; identify exposures and recommend controls that are appropriate for the level of risk.

  • Coordinate cybersecurity audit and regulatory (CJIS, PCI, HIPAA) assessment activities, including evidence collection, control validation, management responses, and corrective-action tracking.

  • Evaluate security findings, assist with risk classification, and track remediation activities to support timely resolution of identified vulnerabilities and compliance concerns.

  • Participate in cybersecurity incident response activities, including development of timelines, follow-up actions, lessons learned, and recommendations for process improvement.

  • Provide information, analysis, and recommendations to management that support technology risk, security, compliance, vendor, and implementation decisions.

  • Monitor changes in cybersecurity requirements, emerging threats, and technology practices and recommend updates to policies, standards, controls, and assessment methodologies.

  • Serve as an escalation point for complex or high-risk technology reviews and advise leadership regarding risk acceptance, remediation, or implementation decisions.

  • Lead security and risk reviews for artificial intelligence (AI), machine-learning, and generative AI solutions; evaluate data protection, privacy, access, model security, vendor, regulatory, transparency, and human-oversight risks, and recommend controls aligned with County policy and the NIST AI Risk Management Framework.

  • Leadership and Decision-Making initiatives

  • Provides direction to employees and contractors, including assigning work, providing technical guidance, establishing procedures, and delivering training and instruction.

  • Exercises independent judgment in evaluating technology risks and recommending new or revised security approaches, methods, practices, and controls.

  • May recommend postponing or stopping a technology implementation when significant control concerns or security risks require remediation before proceeding.

  • May recommend eliminating a vendor or solution from consideration when risk analysis indicates that minimum security requirements are not met.

Harris County is an Equal Opportunity Employer https://hrrm.harriscountytx.gov/Pages/EqualEmploymentOpportunityPlan.aspx If you need special services or accommodations, please call (713) 274-5445 or email [email protected]. This position is subject to a criminal history check. Only relevant convictions will be considered and, even when considered, may not automatically disqualify the candidate. Education:

  • Bachelors degree in Computer Science, Cybersecurity, or closely related field

OR

  • High School Diploma with industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications

Experience:

  • Minimum five years of progressively responsible professional experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Experience must include evaluating technical environments and security controls, communicating risk-based recommendations, and leading projects, assessments, employees, or contractors.

Knowledge, Skills, and Abilities:

  • Intermediate to advanced knowledge of end-to-end information technology environments, including networks, operating systems, applications, cloud computing, data management, and security architecture.

  • Knowledge of information security risk management, controls governance, regulatory compliance, and methods for evaluating technology-related compliance requirements.

  • Knowledge of common operating systems and technologies, including Windows, Linux/Unix, TCP/IP, identity management, encryption protocols, cloud security, and vendor management.

  • Knowledge of security and compliance frameworks and standards such as CJIS, NIST 800-53, NIST 800-30, COBIT, ISO 27001, PCI DSS, and other applicable regulatory requirements

  • Ability to analyze complex technical information, identify security and compliance risks, assess mitigating controls, and communicate risk-based recommendations.

  • Strong written and verbal communication skills with the ability to explain technical concepts, findings, instructions, and recommendations to technical and nontechnical audiences.

  • Ability to develop processes, procedures, risk-assessment tools, control tests, and technical documentation.

  • Proficiency with Microsoft Office products, including advanced Microsoft Excel functions; familiarity with Microsoft Access and Microsoft 365 tools.

  • Knowledge of AI governance and risk-management principles, including acceptable use, data privacy, model security, human oversight, transparency, and third-party AI risk.

Applicants for this position will be subject to a criminal background check that includes being fingerprinted. This applies to any position with network access to Criminal Justice Information Services (CJIS) or access to an area where CJIS is received, maintained or stored either manually or electronically (i.e. custodian, maintenance).

Automatic Disqualification:

  • Convictions, probation, or deferred adjudication for any Felony, and any Class A Misdemeanor
  • Convictions, probation, or deferred adjudication for a Class B Misdemeanor, if within the previous 10 years
  • Open arrest for any criminal offense (Felony or Misdemeanor)
  • Family Violence conviction

NOTE: Qualifying education, experience, knowledge and skills must be documented on your job application. You may attach a resume to the application as supporting documentation but ONLY information stated on the application will be used for consideration. "See Resume" will not be accepted for qualifications. Preferred Certifications

  • Relevant information security or audit certifications are preferred, including CISSP, GIAC, CISA, CompTIA security certifications, or comparable industry credentials.

Location:

  • 406 Caroline, Houston, TX 77002

Employment may be contingent on passing a drug screen and meeting other standards.

Due to a high volume of applications positions may close prior to the advertised closing date or at the discretion of the Hiring Department.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.