Principal Cybersecurity Analyst - Risk Mgmt & AI Security
Full-time
MD Anderson
The University of Texas MD Anderson Cancer Center is seeking a highly skilled Principal Cybersecurity Analyst to serve as a technical authority within its Cybersecurity department. The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices.
The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function.
The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST. Preferred candidates will also have hands-on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP.
Minimum $123,000 - Midpoint $154,000 - Maximum $185,000
Work Location: Remote 100% Why Us?
At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment. This position offers the opportunity to shape enterprise risk strategy, influence executive decision-making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work-life balance.
• Employer-paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.
• Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options.
• Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups.
• Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer-paid life and reduced salary protection programs.
Responsibilities
Governance, Risk & Compliance (GRC) Architecture & Risk Management Program Leadership
• Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs
• Define and maintain risk assessment methodologies, control frameworks, and risk scoring models
• Establish workflows across development, staging, and production environments
• Develop SOPs, roles, segregation of duties, and change management processes
• Lead design and execution of enterprise risk management strategies
Security & Risk Platform Integration and Automation
• Architect and maintain integrations across Archer, Tenable, ServiceNow, Microsoft Configuration Manager (SCCM/MECM), and Medigate
• Design automated workflows consolidating asset, vulnerability, and risk data
• Enable enterprise-wide risk visibility and reporting through data-driven systems
• Ensure data quality, reconciliation, and interoperability across platforms and CMDB
Regulatory & Compliance Framework Management
• Apply frameworks including NIST CSF, NIST 800-53, HIPAA, and HITRUST
• Conduct control mapping, gap assessments, and compliance reporting
• Advise stakeholders on remediation strategies and regulatory requirements
• Align institutional policies with regulatory and accreditation standards
AI Security & Governance
• Establish and mature AI security and governance programs
• Develop AI risk assessment criteria and governance standards
• Align controls to NIST AI Risk Management Framework and institutional policies
• Evaluate AI/ML tools and vendors for data protection and compliance risks
• Partner with data governance, privacy, and legal teams on AI initiatives
Strategic Risk Visioning, Assessment & Executive Advisory
• Develop multi-year roadmaps, milestones, and resource plans
• Lead enterprise and project-level risk assessments
• Translate technical findings into executive-level reporting and dashboards
• Advise leadership on risk posture and investment prioritization
• Provide technical leadership and mentorship across teams EDUCATION
The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function.
The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST. Preferred candidates will also have hands-on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP.
Minimum $123,000 - Midpoint $154,000 - Maximum $185,000
Work Location: Remote 100% Why Us?
At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment. This position offers the opportunity to shape enterprise risk strategy, influence executive decision-making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work-life balance.
• Employer-paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.
• Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options.
• Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups.
• Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer-paid life and reduced salary protection programs.
Responsibilities
Governance, Risk & Compliance (GRC) Architecture & Risk Management Program Leadership
• Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs
• Define and maintain risk assessment methodologies, control frameworks, and risk scoring models
• Establish workflows across development, staging, and production environments
• Develop SOPs, roles, segregation of duties, and change management processes
• Lead design and execution of enterprise risk management strategies
Security & Risk Platform Integration and Automation
• Architect and maintain integrations across Archer, Tenable, ServiceNow, Microsoft Configuration Manager (SCCM/MECM), and Medigate
• Design automated workflows consolidating asset, vulnerability, and risk data
• Enable enterprise-wide risk visibility and reporting through data-driven systems
• Ensure data quality, reconciliation, and interoperability across platforms and CMDB
Regulatory & Compliance Framework Management
• Apply frameworks including NIST CSF, NIST 800-53, HIPAA, and HITRUST
• Conduct control mapping, gap assessments, and compliance reporting
• Advise stakeholders on remediation strategies and regulatory requirements
• Align institutional policies with regulatory and accreditation standards
AI Security & Governance
• Establish and mature AI security and governance programs
• Develop AI risk assessment criteria and governance standards
• Align controls to NIST AI Risk Management Framework and institutional policies
• Evaluate AI/ML tools and vendors for data protection and compliance risks
• Partner with data governance, privacy, and legal teams on AI initiatives
Strategic Risk Visioning, Assessment & Executive Advisory
• Develop multi-year roadmaps, milestones, and resource plans
• Lead enterprise and project-level risk assessments
• Translate technical findings into executive-level reporting and dashboards
• Advise leadership on risk posture and investment prioritization
• Provide technical leadership and mentorship across teams EDUCATION
- Required: Bachelor's Degree Computer Information Systems, Business Information Systems, Computer Science or related field.
- Preferred: Master's Degree Information Security, Computer Science or related field
- Required: 7 years In information security and/or cybersecurity experience including multiple security domains, to include two years lead/supervisory experience.
- May substitute required education degree with additional years of equivalent experience on a one to one basis.
- Preferred: At least 7-8 years of progressive cybersecurity experience, hands-on risk management (risk assessment, risk register ownership, control evaluation, or risk quantification), led or owned a security risk management program or framework implementation (e.g., NIST RMF/CSF, ISO 27005, FAIR, or equivalent), direct hands-on experience assessing the security or risk posture of AI/ML systems or GenAI deployments, ability to translate technical risk into business-level language for executive and governance audiences (e.g., briefing a CISO, risk committee, or board), experience using Archer, excellent communication skills, risk management, and cybersecurity framework is a must.
- Preferred: CISSP - Cert IS Security Professional Issued by the International Information Systems Security Certification Consortium ((ISC).
- Preferred: CISM - Cert Info Security Manager Issued by Information Systems Audit and Control Association (ISACA).
- Preferred: PMP - Project Mgt Professional Issued by the Project Management Institute (PMI).
- Preferred: Other applicable security industry certifications.
- Requisition ID: 181706
- Employment Status: Full-Time
- Employee Status: Regular
- Work Week: Days
- Minimum Salary: US Dollar (USD) 123,000
- Midpoint Salary: US Dollar (USD) 154,000
- Maximum Salary : US Dollar (USD) 185,000
- FLSA: exempt and not eligible for overtime pay
- Fund Type: Hard
- Work Location: Remote (within Texas only)
- Pivotal Position: Yes
- Referral Bonus Available?: Yes
- Relocation Assistance Available?: Yes
Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Principal Cybersecurity Analyst - Risk Mgmt & AI Security in Houston, TX vacancy
- ...anywhere in the continental U.S.The Principal AI Advisor, Center of Excellence... ...advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor designs security solutions... ...operations, security needs, and risk appetiteIdentify AI related security...PrincipalFull timeLocal areaRemote workWork from home
$168.75k - $200k
...work. Today, ServiceNow is the AI control tower for business reinvention... ...an organization’s cyber risk exposure in real time. Combined with ServiceNow’s Security and Risk capabilities, as well... ...The ideal candidate has strong cybersecurity knowledge, practical enterprise...SuggestedWork at officeImmediate startRemote workFlexible hours$200k - $225k
...shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded,... ...security posture credibly to the broader Cybersecurity organization. KEY RESPONSIBILITIES... ...each Falcon release—balancing genuine risk against the team's delivery timeline....SuggestedFull timeLocal areaImmediate startRemote work$112k - $209k
...firm of K&L Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior... ..., and technical leadership. It utilizes AI-driven tools to improve security measures... ...Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information...SuggestedFull timeTemporary workWork experience placementLocal areaRemote work- DescriptionWe are seeking a Cybersecurity Analyst (Product Security Engineer) to join our team and assist with cybersecurity, penetration testing, and product... ...a comprehensive understanding of global cybersecurity risks and market requirements, including regulations and...Suggested
$43 - $46 per hour
...sponsorship will be considered. Job Title: Cybersecurity Governance Analyst Job Type: Contract (this role is a... ...and maturity of an enterprise AI governance and cybersecurity program. This role will assist with AI security standards, risk assessments, vendor reviews,...Contract workRelocation package- ...client needs and provide solutions based on NTT Data’s Agentic AI offerings/framework and AI tools. Drive annual account planning... ...enterprise-wide thinking in the team; Remain informed on industry security trends and issues, including emerging technologies, and navigate...Work at officeRemote workFlexible hours
$216.7k - $303.4k
...For more information, visit . The GenAI Security team within Reddit’s Security, Privacy, Assurance... ...mission is to secure and protect Reddit’s AI traffic and GenAI adoption by default.... ...models that detect and prevent security risks such as prompt injection, jailbreak...For contractorsWork experience placementRemote workFlexible hours- ...Technology Team as an Identity and Security Engineer located in various... ...credentials and high-risk identitiesBuilds integrations... ...Fundamental understanding of AI model infrastructure and AI agent... ...preferredRelevant professional cybersecurity certifications, such as CISSP...Full timeRemote workFlexible hours
- ...Summary The Sr Strategy & Portfolio Management Analyst will be responsible for supporting a... ...in the Department of Homeland Security U.S. Citizenship and Immigration Services... ...Law SupplementRequisition ID5240- Posted07/30/2026-United States-Texas-Houston-PROJ_MGMT-Work at officeLocal areaRemote work2 days per week
- ...our Technology Team as a Cloud Security Engineer located in various... ...prioritize remediation and validate risk mitigation strategiesOffers... ..., Information Technology, Cybersecurity, or equivalent... ...securityCertifications such as AI-900, AZ 500, SC 200, SC 300,...Full time
- The IT Cloud & Artificial Intelligence (AI) Security Architect is responsible for... ...technologies. This role serves as the cybersecurity subject matter expert for AI adoption,... ...secure-by-design principles, governance, risk management, and architectural standards...Work at office
- As Principal IT Analyst, S4 HANA PMO Lead, you will be responsible for leading the Project Management... ...challenges around energy, safety, security, air travel, productivity, and global urbanization... ...lessons learned as well as latest AI practices for a modern, deliverable...PrincipalTemporary workWork experience placementWork at officeFlexible hours
$111k - $216k
...lead to the same place.We are seeking a Cloud/DevOps (Development, Security, and Operations) Engineer to join the firm. The Cloud/DevOps... ...enable scalable, resilient, and secure cloud solutions, including AI and data workloads.ESSENTIAL DUTIES• Provide technical...Full timeTemporary workLocal areaRemote work- ..., ideally near Dallas or Houston.The Cybersecurity Advisor (or Security Advisor / SA as we call it) plays a critical... ...following Domains: Data Protection & AI; Cloud Security/DevSecOps; Endpoint... ...operations, security needs, and risk appetite. Identify their security concerns...Full timeWork experience placementLocal areaRemote workWork from home
- ...is accepting online applications for the position Global Security Systems Support Analyst through August 18th, 2026 at 11:59 p.m. (Central Time). Global... ...processes and recommend appropriate technical and AI-enabled solutions Manage change requests and determine the...Local areaWorldwideRelocationVisa sponsorshipWork visa
$105.4k - $207.8k
...opportunities businesses face in cybersecurity. Join our team to deliver... ...confidence, and proactively manage to secure success. Recruiting for this... ...on the Cloud Cyber Risk team, you will be responsible... ...-200, SC-300, SC-400, SC-500, AI-300, AI-103, or AI-200Cybersecurity...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Zscaler Network Security Engineer / Senior Consultant, Strategy,... ...challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful... ...1+ years of experience with Zscaler AI-powered capabilities, including AI-driven...Work experience placementLocal area- ...software delivery lifecycle.As a Principal Software Engineer at... ...leading technology products in a secure, stable, and scalable way. Leverage... ...and governs agentic AI-enabled engineering workflows... ...implications, data sensitivity, and risk-based governance; ability to influence...Principal
- ...technologies, including generative AI and agentic AI.Members... ...Role of Architecture Principal, your Area Of... ...demands. Drive scalable and secure architectural designs ensuring... ...solutions basis system risk landscape and define... ...interacting with CXO, Middle mgmt. and developers • Should...Full timeTemporary workImmediate startRelocation
- ...organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach... ...Sec+, Net+, M365/Google Workspace or equivalent cybersecurity certification (preferred) Bachelor’s degree in Computer...Full timeRemote workWorldwide
- ...solutions powered by advanced AI technologies. We blend our... ...Experience• This role is suited for a cybersecurity professional who can... ...analysis and investigation of security alerts using CrowdStrike (NGSIEM... ...threats to determine risk and drive appropriate response...Full timeTemporary workRelocation
$65k - $90k
...delivery-focused Artificial Intelligence (AI) Consultant to join our AI Practice Team.... ...and providing timely updates on progress, risks, and key decisions. Support the project manager... ...more than 160 years ago to promote the security of life and property at sea and preserve...Remote workFlexible hours- ...applications for the position Global Security Systems Support Analyst through August 18th, 2026 at 11:59 p.m... ...develop and deploy solutions, processes, AI‑enabled capabilities, and tools that... ...Line to provide security service and risk mitigation excellence to business units...Full timeLocal areaRelocationVisa sponsorshipWork visa
$154.38k - $193.13k
...DescriptionAbout the RoleWe are seeking a high-caliber Principal / Senior Consultant with deep expertise... ...and modeling to advanced analytics and AI-driven process intelligence, enabling... ...certifications (Data Engineer / Analyst / EMS)Experience in energy, utilities, or...PrincipalFull timeTemporary work- Principal or Senior Principal, Anthropic AI Solutions (Central Region)AI Systems & Platforms | Anthropic Business Unit****Please note: This role is not... ...usage, and integration strategies to ensure scalable, secure, and production-ready implementations. * Build and operationalize...PrincipalTemporary workWork at officeLocal area
$77k - $202k
...AssociateJob Description & SummaryThe OpportunityAs an AWS Security Engineer - Senior Associate, you will play a crucial role in... ...processes- Applying analytical thinking to evaluate and mitigate cybersecurity risks- Developing and maintaining security infrastructure to...Full timeH1b- ...Texas is looking to add a Senior Cyber Risk Analyst to their team. This person will be joining... ...this team sees - 1 is 3rd party security risk assessments and the other is security... ...assessments for consulting companies Insight to AI within the job function #J-18808-Ljbffr...Work at office
- ...services. As Senior Principal Solutions Architect,... ...delivery of innovative, secure, and scalable data... ...that power automation, AI, and advanced analytics... ...with Legal, Privacy, Cybersecurity, and Risk teams to embed... ...programs for data stewards, analysts, and AI practitioners...PrincipalFull timeWork experience placementWork at officeFlexible hours
- ...DescriptionYour RoleThe Advanced Engineering team is Invesco’s AI center of excellence, driving innovation through IVYGPT, agentic... ...hackathons, and cross-functional collaboration.We are seeking a Principal Data Scientist in Atlanta to design, build, and validate agentic...PrincipalFull timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Cybersecurity Analyst - Risk Mgmt & AI Security. Be the first to apply!
Related searches
- cyber security consultant Houston, TX
- cyber security specialist Houston, TX
- cybersecurity analyst remote Houston, TX
- it risk analyst Houston, TX
- transaction risk analyst Houston, TX
- senior quantitative risk analyst Houston, TX
- operational risk specialist Houston, TX
- operational risk consultant Houston, TX
- risk analyst Houston, TX
- risk officer Houston, TX

