- Salary
- $86k – $120k/yr
- Location
- Austin, TX, TX, US
- Workplace
- Remote
- Department
- Security
- Education
- Bachelor
- Source
- GovernmentJobs
Description
Travis County Technology and Operations is seeking an Information Security Analyst Sr to join the Enterprise Risk Management Division.
Performs advanced information security, compliance, risk management, and audit activities in support of the County's Information Assurance and cybersecurity programs. Serves as a senior-level subject matter resource for assessing compliance with information security requirements, with significant responsibility for supporting the County's Criminal Justice Information Services (CJIS) compliance program and evaluating compliance with the FBI CJIS Security Policy.
Plans and conducts technical and administrative security assessments and audits; evaluates security controls; identifies compliance gaps and risks; develops findings and recommendations; and monitors corrective action and remediation activities. Assists County departments with interpreting and implementing applicable security requirements, including CJIS, NIST, HIPAA, County policies, and other regulatory or contractual requirements.
Conducts information technology risk assessments and evaluates administrative, technical, and physical safeguards protecting County systems and information. Reviews system configurations, policies, procedures, documentation, audit records, access controls, security architecture, and supporting evidence to determine whether security controls are appropriately designed, implemented, and operating as intended.
Develops assessment methodologies, audit procedures, control checklists, compliance documentation, risk reports, and executive-level summaries. Collaborates with County departments, Information Technology personnel, information security staff, departmental security representatives, management, vendors, auditors, and external agencies to strengthen security governance and maintain regulatory compliance
This position is eligible for teleworking, in office as needed.Distinguishing Characteristics:
This is a senior-level information security classification within the Information Technology job family. Incumbents perform complex information security, compliance, audit, and risk management activities requiring advanced knowledge of cybersecurity principles, regulatory requirements, security frameworks, and information technology controls.
The Information Security Analyst Senior exercises considerable independent judgment in planning and conducting security assessments and audits, interpreting security and compliance requirements, evaluating technical and administrative controls, identifying deficiencies and risks, and developing recommendations for corrective action.
The position will serve as a subject matter resource for the County's Criminal Justice Information Services (CJIS) compliance program and will coordinate compliance and audit activities across multiple County departments that access, process, store, transmit, or support Criminal Justice Information (CJI). Responsibilities may include assessing compliance with the FBI CJIS Security Policy, preparing departments for internal and external audits, documenting findings, monitoring remediation activities, and assisting departments with implementation of required security controls.
This classification may lead projects, mentor or provide technical guidance to other staff, and represent the department in meetings with County departments, auditors, regulatory entities, vendors, and other governmental agencies. This classification may require a flexible work schedule to meet operational or audit requirements.
Plans, conducts, documents, and reports information security compliance assessments, technical and administrative audits, and risk assessments of County departments, systems, applications, processes, and third-party services.
Supports administration of the County's Criminal Justice Information Services (CJIS) compliance program and evaluates compliance with applicable FBI CJIS Security Policy requirements.
Conducts CJIS compliance assessments and internal audits of multiple County departments and systems that access, process, store, transmit, or support Criminal Justice Information (CJI).
Develops and maintains audit methodologies, assessment procedures, evidence requirements, control checklists, questionnaires, workpapers, compliance documentation, and other tools necessary to evaluate and demonstrate compliance.
Coordinates audit preparation and evidence collection activities with County departments, Information Technology personnel, departmental security representatives, management, vendors, and other stakeholders.
Reviews policies, procedures, system configurations, access controls, security documentation, audit logs, network and system architecture, data flows, training records, personnel security documentation, incident response processes, physical safeguards, and other evidence to determine compliance with applicable requirements.
Documents audit and assessment findings, identifies control deficiencies and associated risks, develops recommendations for corrective action, and communicates results to technical personnel, departmental management, and executive leadership.
Develops, tracks, and monitors corrective action plans, plans of action and milestones (POA&Ms), risk treatment activities, exceptions, and other remediation efforts resulting from security assessments and audits.
Performs follow-up assessments to validate that corrective actions have been implemented and identified security deficiencies have been appropriately addressed.
Assists County departments with interpreting CJIS Security Policy requirements and translating security requirements into practical administrative, technical, and operational controls.
Supports County preparation for external CJIS audits and assessments, including coordinating evidence collection, reviewing documentation, facilitating interviews, responding to audit requests, documenting findings, and monitoring corrective actions.
Conducts information technology and cybersecurity risk assessments using qualitative and quantitative methodologies and evaluates risks associated with systems, applications, technology services, vendors, business processes, and security control deficiencies.
Evaluates administrative, technical, and physical security controls against applicable laws, regulations, contractual requirements, County policies, and recognized cybersecurity frameworks and standards.
Reviews proposed and existing technologies to identify security, privacy, regulatory, and compliance risks and recommends appropriate safeguards and risk treatment measures.
Develops and maintains information security policies, standards, procedures, guidelines, assessment methodologies, and supporting documentation based on changes in technology, threats, regulatory requirements, and industry standards.
Analyzes changes to the FBI CJIS Security Policy and other applicable cybersecurity requirements and evaluates their impact on County systems, departments, policies, procedures, and security controls.
Prepares technical reports, risk assessments, audit reports, compliance reports, dashboards, presentations, executive summaries, and other documentation communicating security risks, findings, remediation status, and compliance posture.
Collaborates with information security, Information Technology, privacy, legal, risk management, departmental personnel, and external organizations regarding cybersecurity risk and compliance matters.
Provides consultation, guidance, training, and awareness to County departments regarding information security requirements, CJIS compliance responsibilities, security controls, and audit readiness.
Participates in security governance, risk management, compliance, incident response, business continuity, and other Information Assurance initiatives as assigned.
May lead projects, mentor staff, review work performed by other analysts, and provide technical or compliance guidance to junior staff.
Performs other job-related duties as assigned.
Bachelor's degree in Computer Science, Information Systems, Business Administration or a directly related field AND five (5) years of relevant work experience, including at least three (3) years experience in information security;
OR,
Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge, skills, and abilities sufficient to successfully perform the duties and responsibilities of this job.
Licenses, Registrations, Certifications, or Special Requirements:
Valid Texas Driver's License.
Preferred:
Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC)
Knowledge, Skills, and Abilities:
Knowledge of:
- Information security governance, risk management, compliance, and audit principles and practices.
- FBI Criminal Justice Information Services (CJIS) Security Policy requirements and security controls applicable to systems that access, process, store, or transmit Criminal Justice Information.
- National Institute of Standards and Technology (NIST) cybersecurity standards and frameworks, including NIST SP 800-53, NIST AI RMF, NIST CSF 2.0, and related security control assessment and risk management concepts.
- Federal, State, Local and County applicable laws, regulations, policies, standards, and contractual requirements applicable to information security and privacy, including the Health Insurance Portability and Accountability Act (HIPAA).
- Information security audit methodologies, evidence collection techniques, control testing, sampling, documentation, workpapers, findings development, and corrective action monitoring.
- Information technology risk assessment and risk management methodologies, including qualitative and quantitative approaches.
- Security control design, implementation, assessment, monitoring, and remediation.
- Data protection concepts including encryption, cryptographic controls, data classification, data loss prevention, removable media protection, transmission security, and secure disposal.
- Third-party and vendor cybersecurity risk management.
- Cloud computing and Software-as-a-Service security concepts and shared responsibility models.
- Principles and practices for developing security policies, standards, procedures, guidelines, and technical documentation.
- Methods for communicating technical, security, risk, and compliance information to technical and non-technical audiences.
- Computer equipment to include word processing, spreadsheets, databases and a variety of software packages.
- Conducting information security audits, compliance assessments, security control assessments, and information technology risk assessments.
- Interpreting and applying cybersecurity frameworks, regulatory requirements, policies, standards, and technical requirements.
- Evaluating administrative, technical, and physical security controls and determining whether sufficient evidence demonstrates compliance.
- Identifying control deficiencies, analyzing associated risk, determining root causes, and developing practical recommendations for corrective action.
- Developing audit workpapers, assessment documentation, findings, risk statements, corrective action plans, and executive-level reports.
- Collecting, reviewing, analyzing, and documenting technical and administrative evidence.
- Researching cybersecurity requirements and applying them to complex information technology environments.
- Managing multiple assessments, audits, findings, and remediation activities simultaneously.
- Communicating complex technical and regulatory requirements in clear, understandable language to technical and non-technical audiences.
- Providing consultation, guidance, training, and technical assistance to County departments and stakeholders.
- Building collaborative working relationships across organizational and departmental boundaries.
- Problem-solving, critical thinking, analysis, and independent decision-making.
- Preparing and delivering professional written reports, presentations, briefings, and recommendations.
- Interpret complex cybersecurity policies, standards, laws, regulations, and contractual requirements and translate them into measurable security controls and operational requirements.
- Independently plan, organize, conduct, document, and report information security audits, assessments, and risk analyses.
- Evaluate evidence objectively and determine whether security controls are appropriately designed, implemented, and operating effectively.
- Identify and clearly articulate security control deficiencies, compliance gaps, risks, and recommended corrective actions.
- Apply CJIS Security Policy requirements to diverse technical environments, business processes, County departments, and information systems.
- Communicate audit findings and security risks professionally and effectively.
- Work collaboratively with technical personnel, departmental leadership, auditors, vendors, legal counsel, risk management personnel, and other governmental entities.
- Maintain independence, objectivity, confidentiality, and professional judgment when conducting audits and assessments.
- Manage multiple complex assignments, prioritize competing requirements, meet deadlines, and maintain accurate assessment and compliance documentation.
- Research, compile, analyze, interpret, and present complex technical and regulatory information.
- Develop practical recommendations that balance security and compliance requirements with operational and business needs.
- Provide guidance, mentoring, and technical assistance to other staff.
- Establish and maintain effective working relationships with County departments, elected and appointed officials, external agencies, vendors, auditors, and other stakeholders.
- Work independently with limited supervision while contributing effectively as a member of multidisciplinary teams.
Physical requirements include extended periods of sitting, using a computer and other standard office equipment. Subject to visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks, especially during incident response or time-sensitive audits.
Travis County employees play an important role in business continuity. As such, employees can be assigned to business continuity efforts outside of normal job functions.
Work Hours: 8 am - 5 pm, Monday-Friday. May work some holidays, some nights, some weekends
Location: 700 Lavaca St, Austin, TX 78701
This position is eligible for teleworking, in office as needed.
Department: Information Security
Criminal, Driving, Education, and Employment Background Checks Required.
For updates or questions on this position, contact: [email protected]
This job description is intended to be generic in nature. It is not necessarily an exhaustive list of all duties and responsibilities. The essential duties, functions and responsibilities and overtime eligibility may vary based on the specific tasks assigned to the position.