Lead Information Security Analyst Governance, Risk, & Compliance (GRC)
Houston, TX - USA
Job Summary
- Position Description
About Harris County and Universal Services:
Harris County is the third largest and most diverse county in the nation with a population of more than 4.7 million. Harris County Commissioners Court the Countys governing body directs a budget of more than $4 billion providing essential services including flood control infrastructure healthcare housing and justice administration.
Harris County Universal Services (HCUS) is the enterprise IT solutions center for the departments and offices of Harris County providing Information Technology Public Safety and Justice Technologies 311 Constituent Engagement Services Fleet Services and Records and Information Governance Services.
HCUS is transforming the way the County does business and seeking a Lead Information Security Analyst - GRC - to join our team. Now is a great time to join Universal Services as we enhance critical services to Harris County residents and internal customers!
Job Summary:
The Information Security Lead will ensure cybersecurity risks and threats are proactively identified and addressed to maintain the protection of Harris Countys information systems critical assets and network security infrastructure.
Duties and Responsibilities:
Conduct information security risk assessments and facilitate reviews of cloud hybrid cloud and on-premises IT solutions and infrastructure.
Perform third-party vendor security risk assessments to support governance efforts.
Serve as a subject matter expert (SME) on Cloud Security with an emphasis on Microsoft Azure.
Stay updated on cybersecurity threats and vulnerabilities and provide recommendations for mitigation particularly within Microsoft Azure cloud security.
Utilize security controls to enhance security posture and research emerging threats relevant to cloud and hybrid cloud operations.
Assess and prioritize information security risks ensuring compliance with regulatory requirements and information security policies.
Oversee assigned project activities to ensure timely completion.
Develop remediation plans and proactively track progress presenting cybersecurity risks and gaps to stakeholders.
Provide design input implementation and maintenance of enterprise-wide security solutions to address cybersecurity needs.
Work on high-complexity projects requiring in-depth knowledge across multiple technical areas and business segments.
Communicate security vulnerabilities and risks to key stakeholders and consult on remediation efforts.
Develop documentation to support cybersecurity operations including:
Communications
Job aids
Educational/training materials
Architecture diagrams
Technical reference guides
Procedures
Strategy/technology roadmaps
Request for Proposal/Offers (RFP/RFOs)
Statement of Work (SOW)
Metrics and reports
Project plans
Executive presentations
Coach and mentor junior-level technical staff.
Participate in Cybersecurity Incident Response Team (CIRT) investigations and response activities.
Perform other duties as assigned.
Harris County is an Equal Opportunity Employer
you need special services or accommodations please call or email .
This position is subject to a criminal history check. Only relevant convictions will be considered and even when considered may not automatically disqualify the candidate.- Requirements
Education:
High school diploma or GED equivalency from an accredited educational institution.
Experience:
Five (5) years of experience in Information Security IT Computer Science or IT Risk Management
Knowledge Skills & Abilities:
Designing implementing and executing IT Risk Management projects.
Building and maintaining strong interdepartmental relationships.
Effectively communicating security risks and controls to stakeholders and leadership.
Passion for cybersecurity a self-starter mentality and ability to work in a team environment.
NOTE: Qualifying education experience knowledge and skills must be documented in your job application. You may attach a resume to the application as supporting documentation butONLY information stated on the application will be used for consideration. See Resumewill not be accepted for qualifications.
- Preferences
Education:
Bachelors degree in Cybersecurity Computer Science Information Technology or a related field (or equivalent work experience).
Certifications:
Industry certifications such as CompTIA Security Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) or GIAC Certified Incident Handler (GCIH) credentials.
Experience:
Strong understanding of IT infrastructure and network security principles.
Experience with cloud security (AWS Azure or GCP).
Knowledge of scripting languages (Python PowerShell etc.) for automation.
- General Information
Location:
406 Caroline St. Houston Tx 77002
Work Schedule:
8 hours/day
Work Arrangement:
Hybrid (3 days onsite 2 days WFH)
Working Conditions:
May require occasional evening or weekend work during major incidents or upgrades.
Employment may be contingent on passing a drug screen and meeting other standards.
Due to a high volume of applications positions may close prior to the advertised closing date or at the discretion of the Hiring Department.
Required Experience:
IC