Cybersecurity Governance, Risk, Compliance Manager (Cybersecurity Analyst IV )

Job Description

Agency Information

The Texas Education Agency (TEA) oversees primary and secondary public education in Texas and is committed to improving outcomes for all public school students by providing leadership, guidance, and support to school systems across the state.

Core Values

  • We are Determined: We are committed and intentional in pursuing our primary purpose of improving outcomes for students.
  • We are People-Centered: We strive to attract, develop, and retain committed talent that reflects the diversity of Texas, with each individual contributing to our shared vision for students.
  • We are Learners: We seek evidence, reflect on outcomes, and continuously improve in pursuit of excellence for students.
  • We are Servant Leaders: We are public servants committed to improving opportunities for students and supporting those who serve them.


Job Description

About Office of IT

The Office of Information Technology works closely with all agency divisions to implement innovative technology solutions in a cost-efficient manner that supports the goals and priorities of the Texas Education Agency. The Office of IT provides efficient technology solutions and stellar customer services to internal staff, 20 Educational Service Centers, and 1,200-plus public-school districts and charter schools. The following services are provided by IT: leadership on IT initiatives; guidance on security/policy issues; new application development/enhancements; software acquisition; technical support; assistance with technical sections of purchasing documents such as Request for Information (RFI), Request for Offers (RFO), Request for Proposals (RFP); and oversight on the data collection process which helps to support and improve outcomes for all of Texas' 5 million-plus students.

Position Overview

The Cybersecurity Governance Risk and Compliance (GRC) Manager performs advanced (senior-level) information security and cybersecurity analysis work. The GRC Manager reports to the Executive Director of IT Administration and Compliance in the Office of Information Technology and will work closely with the Chief Information Security Officer and the Cybersecurity Operations Manager. The GRC Manager serves as the lead subject matter expert for GRC initiatives, collaborating closely with risk management, security operations and leaders across the agency. The GRC Manager is responsible for overseeing enterprise risks, conducting risk analyses, implementing and advancing policies and a comprehensive control framework to execute the GRC strategy.

This role will oversee the administration of standards and controls, risk management, third-party risk, baseline security controls and technology compliance initiatives. The GRC Manager will be solution oriented, and have a strong background in cybersecurity principles, risk management frameworks, and regulatory compliance. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. The GRC Manager will also work with internal and external team members to support the K12 Cybersecurity initiative by working to enhance cybersecurity in our Texas school systems. Employees at this level may independently perform the most complex information security and cybersecurity work and advise management and users regarding security configurations and procedures.

Flexible work location in Texas may be considered for qualified candidates.

Please note that a resume is a required attachments for applying to this position. Incomplete applications will not be considered. Applicants who are strongly being considered for employment must submit to a national criminal history background check.

Essential Functions

Job duties are not limited to the essential functions mentioned below. You may perform other functions as assigned.

1. Cybersecurity Governance Framework: responsible for creating, approving, and enforcing security policies, standards, and procedures that align with strategic business goals and the overall risk appetite of the organization, ensuring alignment with TAC 202 requirements and best practices in accordance with NIST. The Cybersecurity GRC Manager will implement process improvements using GRC tools and methodologies to drive productive gains.

2. Oversee Third Party and Vendor Risk Assessments: responsible for establishing a comprehensive risk management program that regularly conducts formal risk assessments. Additionally, this role is responsible for evaluating the effectiveness of current controls and recommending mitigation strategies based on risk severity.

3. Ensure Continuous Regulatory and Policy Compliance: responsible for ensuring adherence to internal polices, as well as external regulations and legal mandates such as TAC 202 and NIST. The GRC Manager will establish and maintain a continuous monitoring program for tracking and resolving non-compliance issues.

4. Executive Level Reporting and Communication: coordinate with stakeholders to communicate emerging risks across the organization and implement effective risk mitigation strategies.

5. Team Management and Supervision: guide the team to align with security, audit, and risk management efforts in ongoing security program assessments. This role will also provide guidance to team members to ensure compliance with relevant laws and regulations.

Qualifications

Minimum Qualifications

Education: Graduation from an accredited four-year college or university

Degree field(s): Cybersecurity, Risk Management, Computer Science, Audit, Information Technology Security, Computer Engineering, Computer Information Systems

Required Licenses: One or more of the following: CISSP, CISM, CGRC, CRISC, CISA

Experience: At least six (6) years of experience in Cybersecurity, Risk Management, or Audit, including experience leading teams in handling both legacy and emerging technologies to manage business risk and enforce security controls

Substitutions: An advanced degree may substitute for two years of required experience

Other Qualifications

  • Share the belief that all Texas students can achieve at high levels and are able to succeed in college, career, or the military
  • Understanding of frameworks, regulations and laws such as ISO, NIST, FERPA
  • Proficient in GRC tools for tracking and managing compliance, conducting risk assessments and reporting
  • Project management skills for working with stakeholders and completing projects on time and in scope
  • Excellent written and verbal communication skills for both business and cybersecurity contexts
  • Commitment to sharing up to date industry knowledge with team to elevate overall GRC program expertise
  • Knowledge of Information Technology infrastructure, including routers, switches, firewalls, databases, operating systems, encryption, load balancing, intrusion prevention systems, and network protocols and concepts
  • Research, evaluate, and recommend information-security-related hardware and software, including developing business cases for security investments


New hires, rehires, and internal hires will typically receive a starting salary between the posted minimum and the average pay of employees within the same classification. Offers are based on the candidate's experience and qualifications and consider internal pay equity across employees performing similar work.

The top half of the posted salary range is generally reserved for candidates whose qualifications exceed the role's requirements. The maximum of the range is typically reserved for candidates who significantly exceed the required and preferred qualifications.

Benefits

TEA employees receive a comprehensive benefits package through the State of Texas and the Employee Retirement System of Texas (ERS), supporting health, financial security, and work-life balance.

Benefits include:

  • Retirement through ERS and employer-paid health insurance for eligible employees
  • Optional dental, vision, and dependent coverage
  • Paid state holidays, vacation leave, sick leave, and longevity pay
  • Wellness programs, employee assistance programs, and professional development opportunities
  • Eligibility for the federal Public Service Loan Forgiveness (PSLF) program


To learn more about benefits available to State of Texas employees, please review the State of Texas Employee Benefits brochure and visit the TEA Compensation and Benefits page .

Military/Veteran Information

Applicants eligible for Military Employment Preference will be considered in accordance with applicable state and federal laws and regulations.

To explore how military experience may align with this role, applicants may review Military Occupational Specialty (MOS) codes within the State's Position Classification Plan. Please refer to the Military Crosswalk and select the occupational category that most closely corresponds with the classification listed in this job posting.

Additional Information

TEA is an equal opportunity employer and complies with all applicable federal and state nondiscrimination laws. Employment decisions are made without regard to race, religion, color, national origin, sex, disability, age, or veteran status.

TEA does not sponsor or assume sponsorship of employment visas.

This position requires the applicant to meet Agency standards and criteria which may include passing a pre-employment criminal background check, prior to being offered employment by the Agency.

To learn more about working at TEA, including hiring timelines, process details, and candidate resources, please visit the Careers at TEA page .

Due to the high volume of applications, we are unable to accept phone calls or respond to all email inquiries. Only candidates selected for an interview will be contacted.

To help ensure you receive updates regarding your application, please add [email protected] and @tea.texas.gov to your safe sender's list.

How to Apply

To apply for a position in the Candidate Gateway:

  • Select the job posting and click "Apply"
  • Review and accept the Privacy Agreement by selecting "Accept"
  • If you are a first-time user, select "New User" and create an account using a personal email address.
  • Once your account is created, complete and submit the online application.