Location(Primary Location for Job Responsibilities) Our Kennesaw campus is located at 1000 Chastain Road NW, Kennesaw, GA 30144.
Our Marietta campus is located at 1100 South Marietta Parkway, Marietta, GA 30060.
Job SummaryThe position leads enterprise cybersecurity governance, risk management, compliance, and third-party risk activities while supporting alignment with institutional, state, and federal requirements. This position serves as a senior subject matter expert, providing strategic guidance, leading complex assessments, and promoting risk-informed decision-making across the university.
Responsibilities KEY RESPONSIBILITIES: 1. Leads enterprise IT and cybersecurity risk assessments using NIST, CIS, and institutional frameworks, evaluating compensating controls and contextual risk to support informed decision-making.
2. Maintains and enhances the enterprise IT risk register, ensuring accurate risk documentation, ownership assignment, remediation tracking, and risk acceptance processes.
3. Leads third-party vendor risk assessments, analyzing SOC reports, HECVATs, security questionnaires, and supporting documentation to evaluate organizational risk.
4. Coordinates audit readiness activities, evidence collection, stakeholder engagement, response tracking, and remediation efforts related to cybersecurity and regulatory audits.
5. Assesses and validates technical, administrative, and operational controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST, and related compliance requirements.
6. Supports the University's data privacy program, including Records of Processing Activities (RoPA), data privacy consultations and assessments, data privacy requests, privacy risk identification and mitigation, and the development and implementation of data privacy awareness and training initiatives.
7. Develops, reviews, and maintains cybersecurity policies, standards, procedures, and governance documentation to support compliance and operational maturity.
8. Collaborates with internal stakeholders to evaluate, validate, and reassess IT controls, identify control gaps and risks, and support the development and implementation of appropriate remediation strategies.
9. Collaborates with the Office of Research, faculty, and other key stakeholders to support the governance, compliance, risk management, and security and privacy requirements associated with sponsored research, controlled information, and regulated research environments.
10. Partners with business, academic, and technology stakeholders to identify risks, recommend mitigation strategies, and support implementation of corrective actions.
11. Develops metrics, dashboards, and executive reports that communicate cybersecurity risk, compliance status, trends, and program effectiveness to leadership.
Required QualificationsEducational RequirementsBachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/or experience.
Required Experience Five (5) years of professional experience supporting governance, risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.
Preferred QualificationsAdditional Preferred Qualifications Relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation
Preferred Educational Qualifications An advanced degree from an accredited institution of higher education in a related field such as Information Technology, Cybersecurity, Information Systems, Business Administration, or Risk Management
Preferred Experience Experience in higher education or regulated environments (FERPA, GLBA, HIPAA, PCI-DSS, NIST 800-171, CMMC)
Experience with GRC platforms such as ServiceNow GRC, RSA Archer, OneTrust, Apptega, or similar systems
Knowledge, Skills, & AbilitiesABILITIES Ability to interpret regulatory, contractual, and institutional compliance requirements
Ability to develop governance documentation, policies, standards, and procedures
Ability to communicate technical and risk-related concepts to technical and non-technical audiences
Ability to prepare executive-level reports, metrics, and recommendations
Strong analytical and problem-solving skills with the ability to evaluate complex risk scenarios
Able to handle multiple tasks or projects at one time, meeting assigned deadlines
KNOWLEDGE Advanced knowledge of cybersecurity governance, risk management, compliance, and privacy principles and frameworks
Knowledge of cybersecurity frameworks including NIST, RMF, CIS, ISO 27001, and related standards
Knowledge of research security principles and applicable requirements governing federally sponsored research, controlled information, and regulated research environments.
Experience leading IT risk assessments and evaluating compensating controls and contextual risk
Experience with GRC tools, dashboards, and compliance tracking systems
Strong understanding of vendor risk management and third-party security assessment practices
SKILLS Excellent interpersonal, initiative, teamwork, problem-solving, independent judgment, organization, communication (verbal and written), time management, project management, and presentation skills
Proficient with computer applications and programs associated with the position (i.e., Microsoft Office suite)
Strong attention to detail and follow-up skills
Strong customer service skills and phone and e-mail etiquette
Other InformationThis is not a supervisory position.
This position does not have any financial responsibilities.
This position will not be required to drive.
This role is considered a position of trust.
This position does not require a purchasing card (P-Card).
This position may travel 1% - 24% of the time
This position does not require security clearance.
Background Check - Standard Enhanced
- Education
Per the University System of Georgia background check policy, all final candidates will be required to consent to a criminal background investigation. Final candidates may be asked to disclose criminal record history during the initial screening process and prior to a conditional offer of employment. Applicants for positions of trust with screening results which confirm a disqualifying criminal history will be immediately disqualified from employment eligibility
All applicants are required to include professional references as part of their application process. Some positions may require additional job-based screenings such as motor vehicle report, credit check, pre-employment drug screening and/or verification of academic credentials.
https://www.usg.edu/hr/assets/hr/hrap_manual/HRAP_Background_Investigation_Employment.pdf