The University of Texas at Austin

Cybersecurity GRC Team Lead

The University of Texas at Austin  •  $155k/yr  •  Austin, TX (Onsite)  •  6 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Posting Title:

Cybersecurity GRC Team Lead

----

Hiring Department:

Information Security Office

----

Position Open To:

All Applicants

----

Weekly Scheduled Hours:

40

----

FLSA Status:

Exempt from FLSA

----

Earliest Start Date:

Immediately

----

Position Duration:

Expected to Continue

----

Location:

AUSTIN, TX

----

General Notes

This is a remote-eligible opportunity offering flexible work arrangements, competitive benefits, and the chance to lead a highly impactful team within the Information Security Office (ISO) at UT Austin. The Cybersecurity Governance, Risk, and Compliance (GRC) Team Lead will oversee a team of analysts responsible for supporting security compliance efforts across a variety of university operations—with a notable focus on controlled research environments and compliance with CUI-related frameworks (e.g., NIST 800-171, DFARS, ITAR, and CMMC).

In addition to supporting controlled research, this role will also guide the team’s work in other key compliance areas such as HIPAA, PCI-DSS, NIST 800-53, and internal policy requirements.

This position is central to building a mature, risk-informed, and agile GRC program that aligns with the university’s research mission and enterprise IT operations.

You will get to work with a very intelligent and dedicated team to address enterprise cybersecurity challenges through novel approaches in an office that highly values work-life balance, the freedom to explore out of the box ideas, and serving others.

Most importantly, you will help our researchers to securely advance their pursuits. What starts here changes the world!

Your skills will make a difference

You'll be working for a university that is internationally recognized for research and the work you do will make a difference in the lives of our students, faculty and staff. You’ll also be working for a team that is nationally respected by their peer community. If you're the type of person that wants to know your work has meaning and impact, you'll like working for our team.

The Information Security Office at The University of Texas at Austin provides an outstanding benefits package to our staff. Those benefits include:

  • Competitive health benefits (employee premiums covered at 100%, family premiums at 50%)

  • Voluntary Vision, Dental, Life, and Disability insurance options

  • Generous paid vacation, sick time, and holidays

  • Teachers Retirement System of Texas, a defined benefit retirement plan, with employer matching funds

  • Additional Voluntary Retirement Programs: Tax Sheltered Annuity 403(b) and a Deferred Compensation program 457(b)

  • Flexible spending account options for medical and childcare expenses

  • Robust free training access through LinkedIn Learning plus professional conference opportunities

  • An exclusive incentive pay program

  • A great physical office space should you prefer to work from campus

  • Tuition assistance

  • Expansive employee discount program including athletic tickets

  • Free access to UT Austin's libraries and museums with staff ID card

  • Free rides on all UT Shuttle and Austin CapMetro buses with staff ID card

For more details, please see: https://hr.utexas.edu/prospective/benefits and https://hr.utexas.edu/current/services/my-total-rewards

This position requires you to maintain Internet service and a mobile phone with voice and data plans to be used when required for work. You must also be authorized to work in the United States on a full-time basis for any employer without sponsorship (e.g., US citizen, US resident, US asylee).

Purpose

The Cybersecurity GRC Team Lead provides strategic and operational leadership for the GRC team in the ISO. This team performs risk assessments, policy development, control evaluations, and compliance support across a range of regulatory and internal frameworks. The Team Lead is expected to be a subject matter expert in multiple areas of compliance, with a strong emphasis on controlled research programs and CUI handling requirements, while also ensuring broad support for the university’s evolving GRC needs.

Responsibilities

  • Lead and manage a team of cybersecurity GRC analysts responsible for:
    • Supporting the Controlled Research Program and ensuring alignment with CUI-related frameworks (e.g., NIST 800-171, CMMC, DFARS, ITAR)
    • Conducting risk assessments, gap analyses, control reviews, and compliance documentation for enterprise-wide regulatory frameworks, such as HIPAA, PCI-DSS, NIST 800-53, GLBA, and others.
    • Advising on appropriate security controls, documenting implementation strategies, and helping units align with both external requirements and internal policy.
  • Oversee development and maintenance of security compliance documentation including System Security Plans (SSPs), POA&Ms, risk registers, and internal/external audit response materials.
  • Work with stakeholders across the institution—including IT leadership, research administration, legal, and compliance offices—to interpret regulatory requirements and provide practical guidance.
  • Serve as a liaison between the ISO and external auditors, assessors, and institutional compliance teams.
  • Maintain awareness of emerging regulatory requirements (e.g., new CMMC versions, updated HIPAA guidance, changes in PCI-DSS) and proactively update practices and communications.
  • Guide and mentor team members, supporting both professional development and technical growth.
  • Participate in strategic planning and contribute to the long-term vision of a cohesive, risk-informed GRC program that supports research and administrative operations.
  • Ensure continuous improvement of GRC processes, templates, and tools; support GRC platform management (e.g., IsoraGRC).
  • Perform other duties as assigned to support the Information Security Office’s mission.

Required Qualifications

  • U.S. Citizen, resident, or officially recognized asylee - Applicant selected will be subject to government security investigation and must meet eligibility requirements for access to classified information at the level appropriate to the project requirements of the position.
  • Minimum of 5 years of experience in cybersecurity, risk management, compliance, or audit, with at least 2 years of leadership or supervisory experience.
  • Demonstrated experience with multiple compliance frameworks, including NIST 800-171, NIST 800-53, HIPAA, PCI-DSS, or similar.
  • Strong understanding of controlled research requirements, particularly CUI, DFARS, and CMMC frameworks.
  • Excellent verbal and written communication skills, including the ability to explain regulatory requirements to technical and non-technical audiences.
  • Experience creating, managing, or reviewing compliance documentation such as SSPs, POA&Ms, or risk registers.
  • Proven ability to manage and prioritize multiple projects across a distributed team.
  • Familiarity with GRC platforms or tooling (e.g., IsoraGRC, ServiceNow GRC).

Relevant education and experience may be substituted as appropriate.

Preferred Qualifications

  • Experience working in higher education or academic research settings.
  • Experience with CMMC Level 2 compliance readiness or pre-assessments.
  • Experience managing or mentoring a cybersecurity or compliance team.
  • Certifications such as CISSP, CAP, CISM, CISA, or relevant NIST/CMMC credentials.
  • Familiarity with UT Austin’s information security policies, research infrastructure, or compliance structure.

Salary Range

$155,000 + depending on qualifications

Working Conditions

  • May work around standard office conditions
  • Repetitive use of a keyboard at a workstation
  • Use of manual dexterity
  • This is a remote-eligible opportunity offering flexible work arrangements

Required Materials

  • Resume/CV
  • 3 work references with their contact information; at least one reference should be from a supervisor
  • Letter of interest

Important for applicants who are NOT current university employees or contingent workers: You will be prompted to submit your resume the first time you apply, then you will be provided an option to upload a new Resume for subsequent applications. Any additional Required Materials (letter of interest, references, etc.) will be uploaded in the Application Questions section; you will be able to multi-select additional files. Before submitting your online job application, ensure that ALL Required Materials have been uploaded. Once your job application has been submitted, you cannot make changes.

Important for Current university employees and contingent workers: As a current university employee or contingent worker, you MUST apply within Workday by searching for Find UT Jobs. If you are a current University employee, log-in to Workday, navigate to your Worker Profile, click the Career link in the left hand navigation menu and then update the sections in your Professional Profile before you apply. This information will be pulled in to your application. The application is one page and you will be prompted to upload your resume. In addition, you must respond to the application questions presented to upload any additional Required Materials (letter of interest, references, etc.) that were noted above.

----

Employment Eligibility:

Regular staff who have been employed in their current position for the last six continuous months are eligible for openings being recruited for through University-Wide or Open Recruiting, to include both promotional opportunities and lateral transfers. Staff who are promotion/transfer eligible may apply for positions without supervisor approval.

----

Retirement Plan Eligibility:

The retirement plan for this position is Teacher Retirement System of Texas (TRS), subject to the position being at least 20 hours per week and at least 135 days in length.

----

Background Checks:

A criminal history background check will be required for finalist(s) under consideration for this position.

----

Equal Opportunity Employer:

The University of Texas at Austin, as an equal opportunity/affirmative action employer, complies with all applicable federal and state laws regarding nondiscrimination and affirmative action. The University is committed to a policy of equal opportunity for all persons and does not discriminate on the basis of race, color, national origin, age, marital status, sex, sexual orientation, gender identity, gender expression, disability, religion, or veteran status in employment, educational programs and activities, and admissions.

----

Pay Transparency:

The University of Texas at Austin will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.

----

Employment Eligibility Verification:

If hired, you will be required to complete the federal Employment Eligibility Verification I-9 form. You will be required to present acceptable and original documents to prove your identity and authorization to work in the United States. Documents need to be presented no later than the third day of employment. Failure to do so will result in loss of employment at the university.

----

E-Verify:

The University of Texas at Austin use E-Verify to check the work authorization of all new hires effective May 2015. The university’s company ID number for purposes of E-Verify is 854197. For more information about E-Verify, please see the following:

----

Compliance:

Employees may be required to report violations of law under Title IX and the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery Act). If this position is identified a Campus Security Authority (Clery Act), you will be notified and provided resources for reporting. Responsible employees under Title IX are defined and outlined in HOP-3031

The Clery Act requires all prospective employees be notified of the availability of the Annual Security and Fire Safety report. You may access the most recent report here or obtain a copy at University Compliance Services, 1616 Guadalupe Street, UTA 2.206, Austin, Texas 78701.

The University of Texas at Austin

About The University of Texas at Austin

Industry
Unknown
Company Size
Unknown
Headquarters
Unknown
Year Founded
Unknown
Social Media