Sr. Information Security Analyst, Governance, Risk, and Compliance
University of ChicagoAbout the role
Department
About the Department
This at-will position is wholly or partially funded by contractual grant funding which is renewed under provisions set by the grantor of the contract. Employment will be contingent upon the continued receipt of these grant funds and satisfactory job performance.
Job Summary
The Center for Translational Data Science (CTDS) is looking for an experienced professional who is a self-starter, organized, and passionate about GRC (Governance, Compliance, Risk), security and attention to detail. You are an innovative, self-motivated team player, and a leader who will be able to educate, provide guidance, and drive a cultural and programmatic risk appreciation for information security, risk management, vulnerability management and detection, and governance, risk, and compliance throughout the Center. You will join a team who is passionate about staying up to date on emerging security vulnerabilities and threats, keeps a cool head in crisis, and advocates every single day for improving the security of CTDS’s products and services. Successful candidates will need to have a good technical background, experience with FedRAMP Moderate compliance, superb interpersonal skills, and strong writing and communication skills.
Responsibilities
Develops diverse and impactful risk metrics.
Monitors and manages compliance for FISMA & FedRAMP Moderate information systems.
Leads and participates in multiple FISMA & FedRAMP Moderate audits/assessments annually, including coordination on technical updates to information system documentation.
Leads and conducts risk analysis, assessments, and security audits using internal solutions and third-party vendor partners.
Identifies, implements, monitors, and leads enforcement of information security compliance, regulatory, and control frameworks.
Provides Information Security consulting and security awareness education.
Coordinates and leads weekly internal and monthly external Continuous Monitoring (ConMon) meetings with technical staff and executive-level sponsors, including communications on RA-5 vulnerabilities.
Improves, monitosr, and coordinates Third Party Vendor Risk Management activities.
Conducts research on information security best practices, solutions, strategies.
Develops, maintains, and leads enforcement of strong security governance of all Information Security strategy and operational process.
Plans and reviews annually the risks influencing the effectiveness of information security, privacy, and information security risk management.
Represents Information Security and foster positive collaboration amongst CTDS peers, University departments, agency sponsors, and organizational partners.
Uses a deep understanding of IT expertise to develop and implement security and compliance policies, guidelines, and safe practices for university-wide computing and networking systems.
Leads teams to conduct in-depth information technology risk assessments; makes recommendations and designs improvements to IT security procedures.
Guides communications with users to understand their security needs and supports the implementation of procedures to accommodate them. Ensures that user community understands and adheres to necessary procedures to maintain security.
Performs other related work as needed.
Minimum Qualifications
Education:
Minimum requirements include a college or university degree in related field.---
Work
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s