Cybersecurity Governance & Risk Analyst
Texas Health and Human Services
Date: Jul 23, 2026 Location: AUSTIN, TX Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage. Functional Title: Cybersecurity Governance & Risk Analyst Job Title: Cybersecurity Analyst III Agency: Health & Human Services Comm Department: IT Security Posture EI Posting Number: 18992 Closing Date: 08/22/2026 Posting Audience: Internal and External Occupational Category: Computer and Mathematical Salary Range: $7,015.16 - $10,472.33 Pay Frequency: Monthly Salary Group: TEXAS-B-27 Shift: Day Telework: Not Eligible for Telework Travel: Regular/Temporary: Regular Full Time/Part Time: Full time FLSA Exempt/Non-Exempt: Exempt Job Location City: AUSTIN Job Location Address: 701 W 51ST ST Other Locations: Austin MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A 170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D 26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS This position is open to permanent residents or US citizens only. The Cybersecurity Analyst III performs senior‑level security work with emphasis on cloud security, web application protection, and governance, risk, and compliance (GRC). The role supports on‑premises and cloud environments by evaluating, implementing, and monitoring security controls to protect agency systems and data. Governance & Risk role is responsible for leading the enterprise cybersecurity governance framework and enterprise risk‑management activities to ensure full alignment with legislative mandates, NIST 800-53, HIPAA, and State of Texas DIR mandates. This position provides senior‑level expertise in secure architecture standards, vendor risk management, and data governance. Ensuring that cybersecurity policies, controls, and risk‑management practices are upheld and aligned with State of Tx DIR, NIST 800-53, agency objectives, and regulatory requirements. The Governance & Risk Analyst advises on regulatory changes, develops the enterprise system risk posture, stays current with industry’s best practices and emerging technologies, participates in compliance and regulatory audits, and supports the implementation of enterprise security improvements. This position serves as a critical architect of the agency’s security policy framework, ensuring that every vendor, system architecture, and data flow aligns with legislative requirements and adheres to agency governance standards. This position performs highly complex information security and cybersecurity analysis work. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. May research and implement new security risk and mitigation strategies, tools, techniques, and solutions for the prevention, detection, containment, and correction of data security breaches. Reviews penetration testing results, supports vulnerability remediation efforts, and uses security tools to evaluate and track risk. The Analyst also provides expert guidance on HHS Security Policy, TAC 202, HIPAA, and other applicable regulations; partners with program, security, project managers, and technical teams; and supports staff on security, risk, and compliance matters. Essential Job Functions (EJFs) Attends work on a regular and predictable schedule following agency leave policy and performs other duties as assigned. Cyber Governance – 30% Performs reviews and risk management for vendors, system architectures, and data flows to advise and help teams comply with governance and regulatory standards. Reviews regulatory and legislative changes and develops roadmaps for required updates to policy and governance structures. Ensures alignment with NIST 800-53, State of Texas DIR mandates, HIPAA, TAC 202, and agency legislative requirements. Using established risk management methodologies, identifies enterprise policy or control needs, and evaluates the effectiveness of security solutions across assigned governance areas. Enterprise Risk Management – 25% Develops and maintains the enterprise system risk posture, including risk identification, assessment, metrics, and documentation. Oversees vendor risk management activities, including third‑party assessments, contract security requirements, and ongoing monitoring. Ensures risk‑management practices are aligned with agency objectives and federal/state requirements. Develop vendor, procurement or supply chain training. Promotes secure system and data safeguards. Security Architecture, Advisory, & Collaboration – 25% Provides senior‑level guidance on secure architecture, cloud security, and application protection; evaluates and monitors security controls to protect agency systems and data. Advises programs and technical teams on security technical compliance, governance requirements; supports enterprise security improvement initiatives. Uses established standards and processes to adequately protect Health and Human Services (HHS) personnel, facilities, cloud infrastructure, information, and business operations. Provide leadership and mentorship to other security analysts, offering guidance in performing assessments, implementing controls, and carrying out security functions. Program Oversight & Strategy – 10% Incorporates audit findings and identified security gaps into remediation planning; assists with special projects, documentation updates, and process improvements as assigned. Reviews project charters, provides input on strategic initiatives, and assists with planning activities that strengthen the agency’s cybersecurity posture. Other duties – 10% Performs additional cybersecurity, governance, and risk‑related tasks as assigned, including supporting special projects, contributing to process improvements, and assisting with agency initiatives that enhance overall security posture. Knowledge Of Knowledge Skills Abilities (KSAs) Information security risk assessment and security assessment methodologies, processes, and audit practices. Security program policies, standards, controls, and procedural requirements. Networking, operating systems, applications, databases, and related technologies, including wireless and mobile environments. Incident response concepts, practices, and procedures. Secure Software/System Development Lifecycle (C-SDLC) methodologies. Regulatory and compliance requirements, including HIPAA/HITECH, PCI, SOX, TAC 202, IRS Publication 1075, Texas Business and Commerce Code, and Texas Health and Safety Code. Security and risk management frameworks such as NIST, SANS, HITRUST, ISO, and COBIT. Skill In Written and verbal communication. Analyzing and solving complex problems and quickly understanding technical concepts. Developing, implementing, and maintaining information security policies, standards, and controls. Performing risk assessments, security assessments, and audits. Evaluating risks and identifying mitigation strategies, including defining compensating controls. Ability To Interpret and apply regulatory, policy, and security framework requirements. Communicate technical information to both technical and non‑technical audiences. Work collaboratively with diverse teams and guide others in information security practices. Registrations, Licensure Requirements, Or Certifications Prefer one or more of the following certifications: Certified Information Systems Security Professional (CISSP) Certified Information Systems Auditor (CISA) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Manager (CISM) Global Information Assurance Certification (GIAC) Project Management Professional (PMP) Initial Screening Criteria Graduation from an accredited four‑year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another. At least 5+ years of experience in information technology, security risk, management, assessment, auditing, project management, or consulting. Experience in researching, authoring, or supporting the development of information security policies and standard. Experience developing security and risk performance metrics and reporting dashboards for executive, business, and technical audiences. Additional Information Candidates for this position will be subject to a pre‑employment security review to determine employment eligibility. This is an onsite position in Austin Tx. Any employment offer is contingent upon available budgeted funds and background check. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual. Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC. Active Duty, Military, Reservists, Guardsmen, And Veterans Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active‑duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor’s Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions. ADA Accommodations In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on‑line application, contact the HHS Employee Service Center at View phone number on click.appcast.io. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview. Pre-Employment Checks And Work Eligibility Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks. HHSC uses E‑Verify. You must bring your I‑9 documentation with you on your first day of work. Download the I‑9 Form Telework Disclaimer This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs. Nearest Major Market: Austin #J-18808-Ljbffr
- ...the Information Security Office at The University of Texas at Austin. This role is crucial for supporting governance, risk, and compliance programs in cybersecurity. You'll work with an intelligent and dedicated team focused on making a tangible impact through effective...SuggestedWork at officeRemote work
- ...maximizing value creation for our shareholders. How you will make an impact The Senior Risk Analyst advances the company’s risk management function through disciplined data governance, insurance renewal readiness, exposure tracking, and risk reporting. This role...SuggestedImmediate startRemote work
$81.07k - $129.71k
...maintenance, and ongoing improvement of the IT risk management, IT controls framework,... ..., with a strong focus on technology, cybersecurity, data privacy, and regulatory risks Provides... ...in IT audit, risk management, governance, or compliance, including CISA, CRISC, and...SuggestedFull timeWork at officeLocal areaRemote workFlexible hours2 days per week- ...today! UCT is looking for a talented Analyst III, IT Infosec to join us in Austin... ..., execution, and maturity of UCT’s IT governance, risk, and compliance program. This role is... ...requirements, SOX obligations, cybersecurity frameworks, internal policies, and UCT...SuggestedContract workLocal area
- Akerman LLP, a premier law firm based in Austin, Texas, is seeking a motivated New Business Intake Analyst for their Conflicts Department. This dynamic role involves processing client intake requests efficiently and accurately within a fast-paced environment. The ideal...SuggestedWork at office
- A leading security solutions provider in Austin, TX is seeking an Intel Analyst responsible for supporting proactive risk management through intelligence analysis. Key tasks include monitoring threats, developing reports, and collaborating across teams to ensure effective...Remote work
$185k - $237.5k
...Support the day-to-day management and operation of Circle’s Product Risk Management function. The goal of this function is to partner... ...What You'll Bring To Circle Principal Product Operations and Risk Analyst 10+ years working in risk management for B2B and B2C products...Flexible hours$60k
...operating, and improving essential government systems and services, with proven... ...citizenship. This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and... ...management, operations, and cybersecurity teams to support service reviews,...Contract workRemote work$68.47k - $75.15k
...nonprofit member organization for cybersecurity professionals, our core... ...most vulnerable about cyber risks and empowering access to... ...Summary The Sales Operations Analyst will act as a liaison... ...and the SMB, B2B, OTP, IAP, Government and Sponsorship channels, including...Work experience placementWork at officeRemote work- 2,000+ Contract System Analyst Jobs in United States Linux Information Systems Analyst, Sr / Secret / King of Prussia, PA Business Data... ...-Epic Senior Remote Senior Information Systems Analyst | Cybersecurity & Cloud Systems Admin Business Data Analyst, Construction (Entry...Contract workWork at officeLocal areaRemote work
$152.7k - $294k
...and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security... ...efforts and program performance to senior leaders and governance forums. Stay informed on emerging threats, technologies, methodologies...Work experience placementSummer holidayLocal areaFlexible hours$131k - $268k
...collaborates with colleagues within the Conflicts, Client Engagement, and Risk Management departments of the firm to identify and resolve... ...Open and Intapp Terms. Serves as a resource for conflicts analysts regarding the identification and resolution of conflicts of interest...Remote jobFull timeTemporary workWork at officeFlexible hours$54.4k - $111.5k
...Fifth Third Bank, N.A. is looking for a Credit Analyst II in Austin, Texas. In this role, you'll partner with Portfolio Managers to perform... ...and underwriting tasks, conduct financial analyses, and manage risk assessments. The ideal candidate has a Bachelor's degree in...$155k - $195k
...the continuous improvement of our product development lifecycle Cultivate proactive relationships with underwriting, legal, finance, risk and reinsurance, and agency to translate analytics into visible and actionable work Must Haves Minimum of 5 years of actuarial...Temporary workRelocationRelocation packageFlexible hours- FuturePlan is the nation's largest third-party administrator (TPA) of retirement plans, partnering with advisors in all 50 states. FuturePlan delivers the best of both worlds: high-touch personalized service from local TPAs backed by the strength and security of a large...Second jobWork at officeLocal areaRemote work
- ..., program oversight, and strategic decision-making. What You’ll Do As an Actuarial Analyst, you will support core actuarial functions aligned with Incline’s pricing, reserving, and risk management objectives. You will apply actuarial judgment, analytical rigor, and industry...
- ...Senior Actuarial Analyst Location: Austin, TX (Hybrid) Open Lending is seeking a Senior Actuarial... ...and emerging trends to identify areas of risk or opportunity Support pricing changes by... ...methodologies, review cycles, and governance processes Build relationships with key partners...
$129.3k - $177.8k
Become a part of our caring community The Actuary, Analytics/Forecasting analyzes and forecasts financial, economic, and other data to provide accurate and timely information for strategic and operational decisions. Establishes metrics, provides data analyses, and works...Full timeTemporary workFor contractorsApprenticeshipWork at officeRemote workWork from homeHome officeMonday to Friday- ...Senior Actuarial Analyst I Applicants must be authorized to work for any employer in the U.S. Remote positions are open to applicants based anywhere in the continental U.S. Hybrid positions are open to applicants based in the Austin, Texas area. This position will primarily...Weekly payTemporary workRemote workFlexible hours
$124k - $211k
...high-impact, cross-functional workstreams that require strong judgment, prioritization, and accountability Mentor and support Analysts and junior Actuaries through technical guidance and ongoing feedback Monitor health policy, regulatory, and market developments...Work experience placementLocal areaRemote workVisa sponsorshipWork visa$106.9k - $147k
...experience in coding and data manipulation. Prior experience in pricing or actuarial modeling preferred. Exposure to Value‑Based, Risk Sharing, or other alternative payment models. Demonstrated proficiency in data visualization tools (e.g., Power BI), with...Full timeContract workTemporary workApprenticeshipRemote workWork from home$110k - $140k
...changes to actuarial models, ensuring compliance with all model risk management standards, especially documentation and testing requirements... ...Level Associate Employment Type Full‑time Job Function Analyst, Research, and Strategy/Planning Industries: Insurance Referrals...Weekly payFull timeTemporary workWork at officeFlexible hours- ...Benefits of Working at HHS webpage. Functional Title: Data Analyst IV Job Title: Data Analyst IV Agency: Health & Human Services Comm... ...analyses. Establishes and maintains standard work procedures governing the appropriate use of data and reporting artifacts (templates,...Full timeTemporary workPart timeWork at officeRemote workShift workDay shift2 days per week
- Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages...Local area
- ...Tax Exempt And Government Entities (TEGE) WHAT IS TAX EXEMPT AND GOVERNMENT ENTITIES (TEGE)? A description of the business units can be found at Position(s) are to be filled in the following area(s): ~ TEGE - Employee Plans, Rulings & Agreement, Groups...
- ...opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage. Functional Title: Data Analyst V Job Title: Data Analyst V Agency: Health & Human Services Comm Department: DAP Foster Care Litigation Posting Number: 19310...Full timeTemporary workPart timeWork at officeRemote workShift workDay shift
$78.9k - $123.3k
...Overview We are seeking a detail-oriented cybersecurity compliance professional to support... ...Plan of Action and Milestones (POA&Ms) Risk Assessments Continuous Monitoring documentation... ...Substitutions are subject to government customer review and approval. Mid to senior...Permanent employmentFull timePart timeWork at officeLocal areaRemote work$91k - $321.5k
...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable Time Type: Full time Travel Requirements... ...engagement planning by applying risk management frameworks and governance considerations that strengthen delivery and contract compliance...Full timeContract workH1b- ...Business Analyst – Data Governance Austin, Texas (Hybrid – 4 Days Onsite | 1 Day Remote) Experience: Minimum 12+ Years Preferred Experience ✔ State of Texas Agency Business Analyst experience (2–3+ Years) OR ✔ Other State Government Agency experience (3...Contract workRemote work
$80k - $105k
...curious minds, together we can solve the world’s most complex challenges and deliver more impact together. Role description: A data analyst collects, cleans, and interprets complex datasets to help organizations make better business decisions. Core responsibilities...Full timePart time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Governance & Risk Analyst. Be the first to apply!


