Job DescriptionPosition OverviewThe Cybersecurity Governance Risk and Compliance (GRC) Manager performs advanced (seniorlevel) information security and cybersecurity analysis work. The GRC Manager reports to the Executive Director of IT Administration and Compliance in the Office of Information Technology and will work closely with the Chief Information Security Officer and the Cybersecurity Operations Manager. The GRC Manager serves as the lead subject matter expert for GRC initiatives, collaborating closely with risk management, security operations and leaders across the agency. The GRC Manager is responsible for overseeing enterprise risks, conducting risk analyses, implementing and advancing policies and a comprehensive control framework to execute the GRC strategy.
This role will oversee the administration of standards and controls, risk management, thirdparty risk, baseline security controls and technology compliance initiatives. The GRC Manager will be solution oriented, and have a strong background in cybersecurity principles, risk management frameworks, and regulatory compliance. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. The GRC Manager will also work with internal and external team members to support the K12 Cybersecurity initiative by working to enhance cybersecurity in our Texas school systems. Employees at this level may independently perform the most complex information security and cybersecurity work and advise management and users regarding security configurations and procedures.
Flexible work location in Texas may be considered for qualified candidates.Please note that a resume is a required attachments for applying to this position. Incomplete applications will not be considered. Applicants who are strongly being considered for employment must submit to a national criminal history background check. Essential Functions Job duties are not limited to the essential functions mentioned below. You may perform other functions as assigned.
1. Cybersecurity Governance Framework: responsible for creating, approving, and enforcing security policies, standards, and procedures that align with strategic business goals and the overall risk appetite of the organization, ensuring alignment with TAC 202 requirements and best practices in accordance with NIST. The Cybersecurity GRC Manager will implement process improvements using GRC tools and methodologies to drive productive gains.
2. Oversee Third Party and Vendor Risk Assessments: responsible for establishing a comprehensive risk management program that regularly conducts formal risk assessments. Additionally, this role is responsible for evaluating the effectiveness of current controls and recommending mitigation strategies based on risk severity.
3. Ensure Continuous Regulatory and Policy Compliance: responsible for ensuring adherence to internal polices, as well as external regulations and legal mandates such as TAC 202 and NIST. The GRC Manager will establish and maintain a continuous monitoring program for tracking and resolving noncompliance issues.
4. Executive Level Reporting and Communication: coordinate with stakeholders to communicate emerging risks across the organization and implement effective risk mitigation strategies.
5. Team Management and Supervision: guide the team to align with security, audit, and risk management efforts in ongoing security program assessments. This role will also provide guidance to team members to ensure compliance with relevant laws and regulations.
QualificationsMinimum QualificationsEducation: Graduation from an accredited fouryear college or university
Degree field(s): Cybersecurity, Risk Management, Computer Science, Audit, Information Technology Security, Computer Engineering, Computer Information Systems
Required Licenses: One or more of the following: CISSP, CISM, CGRC, CRISC, CISA
Experience: At least six (6) years of experience in Cybersecurity, Risk Management, or Audit, including experience leading teams in handling both legacy and emerging technologies to manage business risk and enforce security controls
Substitutions: An advanced degree may substitute for two years of required experience
Other Qualifications- Share the belief that all Texas students can achieve at high levels and are able to succeed in college, career, or the military
- Understanding of frameworks, regulations and laws such as ISO, NIST, FERPA
- Proficient in GRC tools for tracking and managing compliance, conducting risk assessments and reporting
- Project management skills for working with stakeholders and completing projects on time and in scope
- Excellent written and verbal communication skills for both business and cybersecurity contexts
- Commitment to sharing up to date industry knowledge with team to elevate overall GRC program expertise
- Knowledge of Information Technology infrastructure, including routers, switches, firewalls, databases, operating systems, encryption, load balancing, intrusion prevention systems, and network protocols and concepts
- Research, evaluate, and recommend informationsecurityrelated hardware and software, including developing business cases for security investments
New hires, rehires, and internal hires will typically receive a starting salary between the posted minimum and the average pay of employees within the same classification. Offers are based on the candidate's experience and qualifications and consider internal pay equity across employees performing similar work.
The top half of the posted salary range is generally reserved for candidates whose qualifications exceed the role's requirements. The maximum of the range is typically reserved for candidates who significantly exceed the required and preferred qualifications.
BenefitsTEA employees receive a comprehensive benefits package through the State of Texas and the Employee Retirement System of Texas (ERS), supporting health, financial security, and worklife balance.
Benefits include:- Retirement through ERS and employerpaid health insurance for eligible employees
- Optional dental, vision, and dependent coverage
- Paid state holidays, vacation leave, sick leave, and longevity pay
- Wellness programs, employee assistance programs, and professional development opportunities
- Eligibility for the federal Public Service Loan Forgiveness (PSLF) program
To learn more about benefits available to State of Texas employees, please review the State of Texas Employee Benefits brochure and visit the TEA Compensation and Benefits page .
Military/Veteran InformationApplicants eligible for Military Employment Preference will be considered in accordance with applicable state and federal laws and regulations.
To explore how military experience may align with this role, applicants may review Military Occupational Specialty (MOS) codes within the State's Position Classification Plan. Please refer to the Military Crosswalk and select the occupational category that most closely corresponds with the classification listed in this job posting.
Additional InformationTo learn more about working at TEA, including hiring timelines, process details, and candidate resources, please visit the Careers at TEA page .
Due to the high volume of applications, we are unable to accept phone calls or respond to all email inquiries. Only candidates selected for an interview will be contacted.
To help ensure you receive updates regarding your application, please add
[email protected] and @tea.texas.gov to your safe sender's list.
How to ApplyTo apply for a position in the Candidate Gateway:
- Select the job posting and click "Apply"
- Review and accept the Privacy Agreement by selecting "Accept"
- If you are a firsttime user, select "New User" and create an account using a personal email address.
- Once your account is created, complete and submit the online application.