Enterprise Information Security Risk Analyst, Information Technology, Dell Medical School
The University of Texas at AustinAbout the role
Job Posting Title:
Enterprise Information Security Risk Analyst, Information Technology, Dell Medical School----
Hiring Department:
Dell Medical School----
Position Open To:
All Applicants----
Weekly Scheduled Hours:
40----
FLSA Status:
Exempt----
Earliest Start Date:
Immediately----
Position Duration:
Expected to Continue----
Location:
AUSTIN, TX----
Job Details:
General Notes
The position will have a hybrid work arrangement, which is based in Austin, Texas. Pre-approval on state eligibility during the offer process will be required for remote work. Remote work will require reliable internet access and a suitable workspace free from distractions.
Purpose
Under the direction of the Manager of Enterprise IT Security and Operations within the Office of the CIO, the Enterprise Information Security Risk Analyst will work closely with the Enterprise Cybersecurity Architect to perform IT security analysis and assessments in accordance with established procedures and protocols. The position will ensure the demonstrable Confidentiality, Integrity, and Availability (CIA) of the University of Austin Dell Medical School’s information assets for authorized internal and external users by reviewing, validating, classifying, and responding to security events and cyber-attacks.
Responsibilities
Contribute to maintaining and improving the Dell Medical School Cyber Security Governance, Risk, and Compliance program and further mature the Dell Medical School’s Risk and Governance capabilities. Work closely with various cybersecurity teams to track the effectiveness of security controls, map threats to controls, and properly prioritize the implementation of controls to reduce risk within the Dell Medical School environment. Conduct cybersecurity audits, assessments and support ongoing audit requirements for all systems. Refine security metrics and dashboards; and manage the cyber security risk register processes and risk profile.
Work with technology and business partners to ensure compliance with security standards and regulations, such as HIPAA, FERPA, PCI DSS, ISO 27001, NIST, etc. Work closely with development and technical staff, as well as with other stakeholders to coordinate, track, and support the remediation of security issues and risks. Oversee and manage the compliance of key controls, reporting on remediation activities, and coordinate continuous risk remediation efforts. Ensure timely reporting and escalation to security and executive leadership. Analyze data to identify potential risks, aggregates data from multiple sources to provide a comprehensive assessment, creates reports, summaries, presentations, and process documents, collaborates with other team members to effectively analyze and present data.
Conduct review of existing security policies, procedures, standards, and exceptions. Assist in the development of policies for conducting cyber security risk assessments and compliance audits. Assist in mapping Dell Medical School’s cyber security program to multiple industry security frameworks, regulations, and best practices (HIPAA, NIST, FERPA, Texas Cyber Security Framework). Contribute to the continuous improvement of the cyber security program and provide feedback and recommendations on security best practices and enhancements.
Conduct review of third-party vendor assessment of services/contracts (applications, hosting, systems, etc.) that involve the collection, processing, transmission, or storage of all data types defined by the University’s Data Classification standards; develop and implement an ongoing supporting documentation.
Other related duties as assigned.
Required Qualifications
Bachelor's degree plus 4 years of progressive experience working in information technology, security, or risk management. Comparable success and work experience may be considered in lieu of degree requirement. Knowledge of risk management frameworks (RMF). Must have functional understanding of federal, state and University regulations, standards, and compliance mandates, including but not limited to HIPAA, HITECH, PCI, FERPA, NIST 800-171, NIST 800-53, and other regulatory audits. CompTIA Security + or other industry related certifications. Must possess a high degree of integrity relative to computer security and the confidentiality of information. Demonstrated ability to analyze IT security threats, understand risk, articulate operational impact and work as part of a team dedicated to achieving and maintaining compliance to all applicable regulations. Working knowledge of following technologies: Various operating systems such as Windows, Linux, macOS, various security tools such as, SIEMs, Data Loss and Prevention (DLP), Vulnerability Assessment tools such as MS Defender ATP an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s