IT Security Risk Advisor, Governance, Risk, & Compliance (GRC)

Harris County, TX

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent credentials with certifications.
  • Minimum five years of professional experience in IT, cybersecurity, or related areas with a focus on risk management and compliance.
  • Knowledge of security frameworks such as NIST, CJIS, and PCI DSS.
  • Ability to analyze technical information and assess security risks.
  • Strong written and verbal communication skills for technical concepts.

Responsibilities

  • Lead cybersecurity risk reviews for projects and technology initiatives.
  • Provide technical security consulting to stakeholders on various technology aspects.
  • Assess vendor cloud solutions for security compliance and risks.
  • Review procurement documents and provide risk-based recommendations.
  • Design security risk-management processes and controls.
  • Develop training and workflows for risk assessment staff.
  • Coordinate cybersecurity audit activities and manage compliance tracking.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Paid Time Off of ten days vacation, eleven holidays, and parental leave.
  • Long-term disability and life insurance options.
  • Retirement savings plans, including a defined benefit pension.
  • Flexible work schedule and professional development opportunities.
Full Job Description
Salary: Depends on Qualifications
Location : Houston, TX
Job Type: Regular Full-time
Job Number: 17211
Department: Universal Services
Opening Date: 09/11/2026
Closing Date: 10/11/2026 11:59 PM Central
Max Number of Applicants: 100

Position Description
Position Overview

The Systems Analyst, IT Security Risk Advisor provides technical security risk, governance, and compliance expertise across Harris County information technology systems, networks, business applications, cloud solutions, and vendor-managed services. The position leads security reviews, identifies technology and regulatory risks, recommends mitigating controls, and develops risk-management processes and tools that support secure and compliant technology operations.
Duties and Responsibilities:
  • Lead cybersecurity risk reviews for technology projects, system and application upgrades, acquisitions, and other ad hoc initiatives; evaluate security exposures and determine whether appropriate controls are designed to mitigate identified risks.
  • Provide technical security consulting to architects, business analysts, project managers, business owners, and other stakeholders regarding system architecture, cloud solutions, network design, applications, and security controls.
  • Assess vendor-managed information technology services and cloud solutions to determine whether vendors meet minimum security requirements and to identify risks, required safeguards, and mitigating controls.
  • Review technical and security information submitted through procurement and request-for-proposal processes; interpret vendor responses, evaluate architectural and security considerations, and provide risk-based recommendations to evaluation teams.
  • Design and enhance security risk-management and control-development processes, including standard operating procedures, assessment methodologies, screening tools, and supporting documentation.
  • Align risk-management practices and security controls with recognized frameworks, including NIST 800-53 and NIST 800-30, while considering organizational risk tolerance, operating capabilities, and budget constraints.
  • Develop risk assessment workflows and provide training, technical guidance, and work direction to Governance, Risk, and Compliance staff and contractors.
  • Develop control-testing approaches and lead security reviews of systems, applications, processes, data-center environments, and third-party relationships; identify exposures and recommend controls that are appropriate for the level of risk.
  • Coordinate cybersecurity audit and regulatory (CJIS, PCI, HIPAA) assessment activities, including evidence collection, control validation, management responses, and corrective-action tracking.
  • Evaluate security findings, assist with risk classification, and track remediation activities to support timely resolution of identified vulnerabilities and compliance concerns.
  • Participate in cybersecurity incident response activities, including development of timelines, follow-up actions, lessons learned, and recommendations for process improvement.
  • Provide information, analysis, and recommendations to management that support technology risk, security, compliance, vendor, and implementation decisions.
  • Monitor changes in cybersecurity requirements, emerging threats, and technology practices and recommend updates to policies, standards, controls, and assessment methodologies.
  • Serve as an escalation point for complex or high-risk technology reviews and advise leadership regarding risk acceptance, remediation, or implementation decisions.
  • Lead security and risk reviews for artificial intelligence (AI), machine-learning, and generative AI solutions; evaluate data protection, privacy, access, model security, vendor, regulatory, transparency, and human-oversight risks, and recommend controls aligned with County policy and the NIST AI Risk Management Framework.
  • Leadership and Decision-Making initiatives
  • Provides direction to employees and contractors, including assigning work, providing technical guidance, establishing procedures, and delivering training and instruction.
  • Exercises independent judgment in evaluating technology risks and recommending new or revised security approaches, methods, practices, and controls.
  • May recommend postponing or stopping a technology implementation when significant control concerns or security risks require remediation before proceeding.
  • May recommend eliminating a vendor or solution from consideration when risk analysis indicates that minimum security requirements are not met.

Requirements
Education:
  • Bachelors degree in Computer Science, Cybersecurity, or closely related field

OR
  • High School Diploma with industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications

Experience:
  • Minimum five years of progressively responsible professional experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Experience must include evaluating technical environments and security controls, communicating risk-based recommendations, and leading projects, assessments, employees, or contractors.

Knowledge, Skills, and Abilities:
  • Intermediate to advanced knowledge of end-to-end information technology environments, including networks, operating systems, applications, cloud computing, data management, and security architecture.
  • Knowledge of information security risk management, controls governance, regulatory compliance, and methods for evaluating technology-related compliance requirements.
  • Knowledge of common operating systems and technologies, including Windows, Linux/Unix, TCP/IP, identity management, encryption protocols, cloud security, and vendor management.
  • Knowledge of security and compliance frameworks and standards such as CJIS, NIST 800-53, NIST 800-30, COBIT, ISO 27001, PCI DSS, and other applicable regulatory requirements
  • Ability to analyze complex technical information, identify security and compliance risks, assess mitigating controls, and communicate risk-based recommendations.
  • Strong written and verbal communication skills with the ability to explain technical concepts, findings, instructions, and recommendations to technical and nontechnical audiences.
  • Ability to develop processes, procedures, risk-assessment tools, control tests, and technical documentation.
  • Proficiency with Microsoft Office products, including advanced Microsoft Excel functions; familiarity with Microsoft Access and Microsoft 365 tools.
  • Knowledge of AI governance and risk-management principles, including acceptable use, data privacy, model security, human oversight, transparency, and third-party AI risk.

Applicants for this position will be subject to a criminal background check that includes being fingerprinted. This applies to any position with network access to Criminal Justice Information Services (CJIS) or access to an area where CJIS is received, maintained or stored either manually or electronically (i.e. custodian, maintenance).

Automatic Disqualification:
  • Convictions, probation, or deferred adjudication for any Felony, and any Class A Misdemeanor
  • Convictions, probation, or deferred adjudication for a Class B Misdemeanor, if within the previous 10 years
  • Open arrest for any criminal offense (Felony or Misdemeanor)
  • Family Violence conviction


NOTE: Qualifying education, experience, knowledge and skills must be documented on your job application. You may attach a resume to the application as supporting documentation but ONLY information stated on the application will be used for consideration. "See Resume" will not be accepted for qualifications.

Preferences
Preferred Certifications
  • Relevant information security or audit certifications are preferred, including CISSP, GIAC, CISA, CompTIA security certifications, or comparable industry credentials.

General Information
Location:
  • 406 Caroline, Houston, TX 77002

Employment may be contingent on passing a drug screen and meeting other standards.

Due to a high volume of applications positions may close prior to the advertised closing date or at the discretion of the Hiring Department.

HARRIS COUNTY EMPLOYEE BENEFITS

Harris County offers a highly competitive benefits program, featuring a comprehensive group health plan and defined benefit retirement plan.
The following benefits are offered only to Harris County employees in regular (full-time) positions:
Health & Wellness Benefits
  • Medical Coverage
  • Dental Coverage
  • Vision Coverage
  • Wellness Plan
  • Life Insurance
  • Long-Term Disability (LTD) Insurance
  • Employee Assistance Program (EAP)
  • Healthcare Flexible Spending Account
  • Dependent Care Flexible Spending Account

Paid Time Off (PTO)
  • Ten (10) days of vacation leave per year (accrual rate increases after 5 years of service)
  • Eleven (11) County-observed holidays
  • One (1) floating holiday per year
  • Paid Parental Leave*
  • Sick Leave

Retirement Savings Benefit
  • 457 Deferred Compensation Plan

The following benefits are available to Harris County employees in full-time and select part-time positions:
  • Professional learning & development opportunities
  • Retirement pension (TCDRS defined benefit plan)
  • Flexible work schedule*
  • METRO RideSponsor Program*


* Participation may vary by County department. The employee benefits plans of Harris County are extended to all eligible participants across various departments with the exception of the Harris County Community Supervision and Corrections Department, for which the cited Health & Wellness Benefits are administered through the State of Texas.
In accordance with the Harris County Personnel Regulations, group health and related benefits are subject to amendment or discontinuance at any time. Harris County Commissioners Court reserves the right to make benefit modifications on the County's behalf as needed.
For plan details, visit the Harris County Benefits & Wellness website:
01

Which of the following best describes your highest level of education completed as it relates to this position?Qualifying information must be documented in the Education section of your application.
  • High School or GED diploma
  • Associate Degree
  • Bachelor's Degree
  • Master's Degree or higher
  • None of the above

02

If you selected a college degree in response to the previous question, which of the following best describes your major?
  • Computer Science
  • Cybersecurity
  • Other Related Field
  • Unrelated Field
  • N/A; No Degree

03

Please describe your educational background including level of education completed, area of study and completed major and minor programs.
04

Which of the following best describes your verifiable experience in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area?(To be considered, qualifying experience must be documented in your application's employment history)
  • Less than five (5) years
  • Five (5) years but less than six (6) years
  • Six (6) years but less than seven (7) years
  • Seven (7) years or more
  • I do not have this experience

05

Please provide the dates of employment during which you obtained experience working in information technology, cybersecurity, technical risk management, compliance, vendor security assessment, or a related area. Provide the month and year that began and ended the experience ( Example: "January 2020 - December 2025" ) If this experience is not clearly documented in the Work Experience section, your application will be disqualified. If you do not have this experience, type "N/A" in the space provided.
06

Do you have industry-recognized certifications related to the field, including CompTIA, ISC2, ISACA and GIAC certifications?
  • Yes
  • No

07

Do you have Relevant information security or audit certifications, including CISSP, GIAC, CISA, CompTIA security certifications, or comparable industry credentials?
  • Yes
  • No

Required Question

Similar Jobs

More Jobs at Harris County, TX

More Information Technology Jobs

Find similar IT Security Risk Advisor, Governance, Risk, & Compliance (GRC) jobs: