Senior IT Governance, Risk, and Compliance (GRC) Analyst

Augusta University Medical Center

$95K — $115K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience required.
  • Minimum of 5 years in governance, risk, compliance, or cybersecurity.
  • Relevant certifications (CISSP, CISA, etc.) preferred.
  • Advanced degree in a related field is a plus.
  • Experience in higher education or regulated environments preferred.

Responsibilities

  • Lead comprehensive IT and cybersecurity risk assessments using recognized frameworks.
  • Enhance enterprise IT risk register with accurate documentation and tracking.
  • Conduct third-party vendor risk assessments for organizational risk evaluation.
  • Coordinate audit readiness activities and stakeholder engagement for cybersecurity audits.
  • Assess controls against compliance requirements like GLBA and HIPAA.
  • Support the University's data privacy program with necessary consultations and training.
  • Develop and review cybersecurity policies and governance documentation.

Benefits

  • Work within a collaborative and supportive university environment.
  • Opportunity to drive significant cybersecurity initiatives.
  • Access to professional development and training opportunities.
  • Engage in strategic decision-making at a senior level.
  • Encourage participation in research and compliance-related activities.
Full Job Description
Location

(Primary Location for Job Responsibilities) Our Kennesaw campus is located at 1000 Chastain Road NW, Kennesaw, GA 30144.

Our Marietta campus is located at 1100 South Marietta Parkway, Marietta, GA 30060.

Job Summary

The position leads enterprise cybersecurity governance, risk management, compliance, and third-party risk activities while supporting alignment with institutional, state, and federal requirements. This position serves as a senior subject matter expert, providing strategic guidance, leading complex assessments, and promoting risk-informed decision-making across the university.

Responsibilities

KEY RESPONSIBILITIES:
1. Leads enterprise IT and cybersecurity risk assessments using NIST, CIS, and institutional frameworks, evaluating compensating controls and contextual risk to support informed decision-making.
2. Maintains and enhances the enterprise IT risk register, ensuring accurate risk documentation, ownership assignment, remediation tracking, and risk acceptance processes.
3. Leads third-party vendor risk assessments, analyzing SOC reports, HECVATs, security questionnaires, and supporting documentation to evaluate organizational risk.
4. Coordinates audit readiness activities, evidence collection, stakeholder engagement, response tracking, and remediation efforts related to cybersecurity and regulatory audits.
5. Assesses and validates technical, administrative, and operational controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST, and related compliance requirements.
6. Supports the University's data privacy program, including Records of Processing Activities (RoPA), data privacy consultations and assessments, data privacy requests, privacy risk identification and mitigation, and the development and implementation of data privacy awareness and training initiatives.
7. Develops, reviews, and maintains cybersecurity policies, standards, procedures, and governance documentation to support compliance and operational maturity.
8. Collaborates with internal stakeholders to evaluate, validate, and reassess IT controls, identify control gaps and risks, and support the development and implementation of appropriate remediation strategies.
9. Collaborates with the Office of Research, faculty, and other key stakeholders to support the governance, compliance, risk management, and security and privacy requirements associated with sponsored research, controlled information, and regulated research environments.
10. Partners with business, academic, and technology stakeholders to identify risks, recommend mitigation strategies, and support implementation of corrective actions.
11. Develops metrics, dashboards, and executive reports that communicate cybersecurity risk, compliance status, trends, and program effectiveness to leadership.

Required Qualifications

Educational Requirements
Bachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/or experience.

Required Experience
Five (5) years of professional experience supporting governance, risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.

Preferred Qualifications

Additional Preferred Qualifications
Relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation

Preferred Educational Qualifications
An advanced degree from an accredited institution of higher education in a related field such as Information Technology, Cybersecurity, Information Systems, Business Administration, or Risk Management

Preferred Experience
Experience in higher education or regulated environments (FERPA, GLBA, HIPAA, PCI-DSS, NIST 800-171, CMMC)
Experience with GRC platforms such as ServiceNow GRC, RSA Archer, OneTrust, Apptega, or similar systems

Knowledge, Skills, & Abilities

ABILITIES
Ability to interpret regulatory, contractual, and institutional compliance requirements
Ability to develop governance documentation, policies, standards, and procedures
Ability to communicate technical and risk-related concepts to technical and non-technical audiences
Ability to prepare executive-level reports, metrics, and recommendations
Strong analytical and problem-solving skills with the ability to evaluate complex risk scenarios
Able to handle multiple tasks or projects at one time, meeting assigned deadlines

KNOWLEDGE
Advanced knowledge of cybersecurity governance, risk management, compliance, and privacy principles and frameworks
Knowledge of cybersecurity frameworks including NIST, RMF, CIS, ISO 27001, and related standards
Knowledge of research security principles and applicable requirements governing federally sponsored research, controlled information, and regulated research environments.
Experience leading IT risk assessments and evaluating compensating controls and contextual risk
Experience with GRC tools, dashboards, and compliance tracking systems
Strong understanding of vendor risk management and third-party security assessment practices

SKILLS
Excellent interpersonal, initiative, teamwork, problem-solving, independent judgment, organization, communication (verbal and written), time management, project management, and presentation skills
Proficient with computer applications and programs associated with the position (i.e., Microsoft Office suite)
Strong attention to detail and follow-up skills
Strong customer service skills and phone and e-mail etiquette

Other Information

This is not a supervisory position.
This position does not have any financial responsibilities.
This position will not be required to drive.
This role is considered a position of trust.
This position does not require a purchasing card (P-Card).
This position may travel 1% - 24% of the time
This position does not require security clearance.

Background Check

  • Standard Enhanced
  • Education

Per the University System of Georgia background check policy, all final candidates will be required to consent to a criminal background investigation. Final candidates may be asked to disclose criminal record history during the initial screening process and prior to a conditional offer of employment. Applicants for positions of trust with screening results which confirm a disqualifying criminal history will be immediately disqualified from employment eligibility

All applicants are required to include professional references as part of their application process. Some positions may require additional job-based screenings such as motor vehicle report, credit check, pre-employment drug screening and/or verification of academic credentials.

https://www.usg.edu/hr/assets/hr/hrap_manual/HRAP_Background_Investigation_Employment.pdf

Similar Jobs

More Jobs at Augusta University Medical Center

More Education, Government & Non-Profit Jobs

Find similar Senior IT Governance, Risk, and Compliance (GRC) Analyst jobs: